Valid base64 does not prove a supported formatCompare the decoded digest and data-URI MIME independently before repairing the wrong layer.
Give each capability one owner.
Storage validates identity, bytes, dimensions, and four accepted local formats.
Declare route media types, create a bounded rendition, or refuse locally before egress.
Build a policy-owned rendition.
original
→immutabledecode
→boundednormalize
→explicitencode
→supportedvalidate
digestNever fall back after conversion failure.
Choose first-frame, all-frame, or reject. Do not silently erase motion.
Bound pixels, frames, bytes, memory, time, concurrency, and cleanup.
Cache by source digest plus the complete rendition policy and encoder version.
Six proof gates.
- 01Known-good PNG proves endpoint, model, and API dialect.
- 02Provider media types are explicit and versioned.
- 03Original attachment bytes and identity remain immutable.
- 04Rendition MIME matches validated target magic bytes.
- 05Unsupported media fails locally before provider egress.
- 06Replay links the original and observable rendition policy.
Primary evidence.
Preserve evidence, adapt the wire.
The canonical guide maps six failure layers, capability metadata, safe rendition architecture, animation and decoder policy, a provider matrix, and sixteen release gates.
Read the complete guide