The corrected diagnosisA generic or context row does not prove the Host lost the image. It proves the client presentation path was not registered for that tool.

Keep the consumers separate.

Canonical value

Stable JSON for Code Mode and programmatic callers.

Model render

Text and image blocks for the next model request.

Tool node

Durable call/result identity and replay lifecycle.

Web view

Business-owned row registered under the exact wire name.

Wire the user path explicitly.

Registertool.call.toolview

Scope one component to each controlled image tool name.

Resolvecompleted result

Read only durable image references owned by that call.

Fetchsession.attachment

Use Session authorization, then create and revoke a safe Blob URL.

Do not inject context to make pixels appear.

Context injection changes model transcript semantics and renders through a compact context row. Keep the artifact attached to the tool call that produced it.

Fail safely and visibly.

Missing, corrupt, oversized, unsupported, or unauthorized attachments must leave readable fallback text without crashing Chat. Abort loads on Session change, revoke object URLs, and keep provider credentials and local paths out of the DOM.

Primary evidence.

Keep model and UI truth aligned.

The complete guide covers Host output, client slot registration, authorized attachment retrieval, package lifecycle, failure routing, security boundaries, and fourteen acceptance tests.

Read the complete guide