system.device | A connected device. Carries name, kind, last-active timestamp. | A Devices list. Revocable. |
system.credential | A platform credential — discriminated on kind: api_key (a Marfa client credential), oauth_token (encrypted OAuth provider config for an Integration), or api_token (encrypted bearer for an Integration whose upstream is API-key-authenticated, not OAuth). Carries permissions, last-used time. | A Credentials list. Revocable. |
system.webhook | A webhook subscription. Carries URL, filters, delivery history. | A Webhooks list. Editable. |
system.app | A registered app identity. Required for app.<app-name>.<type> to mean anything. | An Apps list. |
system.connection | An approved relationship between this space and an external authority. Three kinds: app, integration, tenant. See Connections. | A Connections list. Revocable. |
system.profile | The signed-in user’s account profile — username, name, bio, avatar. One per account, served via /profile/me. See Profile. | An account-settings page. |
system.integration | A published manifest describing how a connector talks to an external service. One item per (name, version) pair. See Integrations. | An Integrations list — typically the marketplace surface. |
system.activity | Operator-visible state — sync progress, errors, reauthorisation prompts. Severity-tagged. See Activity. | An Activity feed; the action_required slice surfaces as a Repairs-style inbox. |