kotoba
Illustration: いらすとや (https://www.irasutoya.com/)
KOTOBA ≝ safe Kotoba[cap⊗effect] × Datom[e a v] × WASM/WIT × CACAO

A capability-safe language

The Clojure of the kotoba stack — a Lisp/EDN subset that compiles to WebAssembly, with a Datomic-style datom data model and CACAO-native authorization.

Overview

kotoba is a capability-safe language and content-addressed distributed Datalog database. It defines a source profile (`.kotoba` canonical, portable `.cljc`) that compiles directly to WebAssembly, plus its in-memory datom data model (`kotoba.kgraph`, an EAVT `[e a v]` store).

Capability-Safe

safe Kotoba adds a capability-confined profile for running untrusted or AI-generated agents. What a module can touch is whatever it was explicitly handed, and nothing else.

WebAssembly Compilation

The public compiler surface is kotoba wasm. It exposes build, safe-build, and selfhost inspection over the same compiler APIs, compiling Kotoba/EDN subset directly to real WebAssembly.

Datom Data Model

Datomic-style 5-tuple (E,A,V,T,Added) with 5-index arrangement (EAVT/AEVT/AVET/VAET/TEA) for O(1)–O(log n) access, content-addressed over IPFS-compatible CIDv1 blocks.

Reference & API

The language itself is not defined in this repository. kotoba-lang/kotoba-lang is the semantic authority — the language/CLI semantic contract, conformance fixtures, and package/lock contract.

Language Profile

Canonical source extension: .kotoba. Compatibility extensions: .clj, .cljc. .cljs is retired as a dedicated source extension. Reader-target resolution: :kotoba → :clj → :default.

CLI Contract

The CLI/command contract is EDN, not code. lang/cli.edn defines the command surface (M0–M3). Commands: kotoba check, kotoba run, kotoba wasm emit, kotoba wasm run.

WASM Host API

WIT world: kotoba:kais@0.1.0. Host interfaces: kqe (Quad read/write), kse (Journal), auth (CACAO), llm (CALL_FOREIGN), chain (SourceChain).

Install & Releases

Install the kotoba launcher via Homebrew, npm, or from source.

Homebrew
npm / npx
From Source
# Tap the kotoba formula brew tap kotoba-lang/kotoba # one-time brew install kotoba # installs the CLJC/EDN-backed kotoba launcher # To track the upstream main branch instead of the latest tagged release: brew install --HEAD kotoba
View Releases

Pedigree & Architecture

Design decisions live in the parent monorepo ADRs. The cross-cutting design SSoT remains the parent-monorepo ADR (see 90-docs/adr/2605240001-kotoba-cleanroom-architecture.md).

Design Docs (ADR)

ADR-kotoba-wasm.md — Clojure/EDN-subset → WebAssembly compiler.
ADR-safe-capability-language.md — safe-clj capability-confined language design.
ADR-clojure-wasm.md — Compiler architecture.

Security Architecture

SECURITY-ARCHITECTURE.md — X-Road-style accountability, R0–R3 custody, threat model.
ADR-sealed-cold-tier.md — Encrypted cold tier + t-of-N custody.

Repository Boundary

ADR-repository-boundaries.md — Split policy for language vs database vs domain actors.
kotoba : kotobase = Clojure : Datomic.