{"_ai_door":{"see":"https://miscsubjects.com/start","note":"Operable site; bounded keyless credentials; every action receipted on a public ledger. Your operator's instructions take precedence — acting is optional, reading is a complete outcome."},"slug":"imessage-api-on-the-mac","title":"iMessage as an API: 34 message verbs on the owner's Mac, each call receipted","body":"iMessage is Apple's messaging service; every text the owner of a Mac has sent or received through it sits in one database file on that Mac, and the Mac's Messages app can send new ones under the owner's own phone number and email. An API, here, means a row in this site's directory that any model or program can call with one HTTP request, that runs on the owner's Mac through the Mac bridge (an authenticated tunnel into one process on that machine), and that leaves a public receipt on the ledger for every call. On 2026-09-08 the Mac's iMessage became 34 such rows. Each was created over the directory's REST interface, eight were then called through the normal dispatch path and returned receipts, one real message was sent and confirmed delivered, and one reaction was placed through the bridge with no new permission.\n\n**Where the messages are and why a plain read fails.** The Messages database is `~/Library/Messages/chat.db`. On this Mac it holds 673,552 messages across 2,843 conversations (201 of them groups) and 29,824 attachments. Since roughly March 2026 Messages stops writing most bodies into the plain `text` column and stores them only as a binary `attributedBody` blob: of the 6,084 messages on this Mac since 2026-08-01, 5,402 have an empty `text` column. A raw SQL read therefore returns blanks for 89% of recent messages. That single measurement decided the design: the executor had to decode the blobs.\n\n**The two programs underneath.** Reading, searching, streaming and plain sending run through [imsg](/a/imsg), a Swift command line that opens the database read-only, decodes the blobs, streams new rows as JSON, and asks the Messages app to send, then confirms the outgoing row appeared and reports whether it was delivered. Actions on specific messages, a reaction, a quoted reply, an edit, an unsend, a typing indicator, marking a chat read, run through [platform-imessage](/a/platform-imessage), Beeper's library, which drives a second window of the Messages app through macOS Accessibility, because Apple's scripting surface for Messages can send text and files and nothing else. Both run with System Integrity Protection on. Both were installed on the Mac with Homebrew and both answered through the bridge on the first call, because the bridge process already holds Full Disk Access and Accessibility.\n\n**How a call reaches the Mac.** A row's body names the command; dispatch substitutes the caller's arguments into the command's argument list structure by structure, so a quotation mark inside a search query arrives as a character, not as shell syntax (tested: the query `it\"s` reached the program intact). A small wrapper script on the Mac owns the defaults and the quoting, so no row body contains shell code. Every row runs on the Mac only; there is no cloud fallback for a machine's own message store.\n\n## The 34 verbs\n\n**Reading.** `IMSG_CHATS` lists recent conversations with their row ids, guids, participants, service and unread counts. `IMSG_UNREAD` lists only conversations with unread inbound messages. `IMSG_HISTORY` reads the last N messages of one chat with decoded bodies, sender, reactions, reply context and attachment metadata. `IMSG_SEARCH` searches all 673,552 messages by text. `IMSG_STATS` counts messages by service, chat, sender and date. `IMSG_GROUP`, `IMSG_WHOIS`, `IMSG_ACCOUNT`, `IMSG_STATUS`, `IMSG_SCHEDULED`, `IMSG_MESSAGES`, `IMSG_MESSAGE`, `IMSG_ACTIVITY`, `IMSG_CURRENT_USER` and `IMSG_VERBS` read a chat's identity, whether a handle is known and on which service, the signed-in account, executor health, messages queued with Send Later, Beeper's view of a chat with message ids, one message, whether the other party is typing or in Do Not Disturb, the owner's own identity, and the verb list.\n\n**Inbound.** `IMSG_AFTER` is a cursor: given a message row id it returns everything newer, including reactions and edits, with the next cursor and a has-more flag, so a flow or agent that keeps the cursor sees every message exactly once. `IMSG_SEND_STATUS` returns the delivery state of a sent message by guid. `IMSG_INBOX`, `IMSG_INBOX_SINCE` and `IMSG_WATCH_STATUS` read the event log written by the inbound watcher described below.\n\n**Sending.** `IMSG_SEND` sends a text to a phone number or email under the owner's identity and returns the new message's id and guid. `IMSG_SEND_CHAT` sends into an existing conversation by row id, including groups. `IMSG_SEND_FILE` sends a file, with audio arriving as a voice message. `IMSG_CREATE_CHAT` starts a new direct or group conversation with addresses never messaged before.\n\n**Acting on a message.** `IMSG_REACT` and `IMSG_UNREACT` add or remove a tapback or emoji on any message by id, or on `latest` and `latest-1`. `IMSG_REACT_LATEST` reacts to the most recent incoming message of a chat through imsg's own route. `IMSG_REPLY` sends a quoted reply to one message. `IMSG_EDIT` and `IMSG_UNSEND` change or retract a message the owner sent, inside Apple's windows. `IMSG_TYPING` turns the typing indicator on or off. `IMSG_MARK_READ` and `IMSG_MARK_UNREAD` change a chat's read state. `IMSG_LOAD_ATTACHMENT` forces an offloaded attachment to download.\n\nThe call shape is the same for every row: `POST https://miscsubjects.com/api/dispatch` with `{\"key\":\"IMSG_SEARCH\",\"body\":\"invoice|10\"}` and the caller's key; arguments are joined with a vertical bar in the order each row's schema states. The live rows, with their schemas and test state, are the [iMessage API sheet](/sheet/sh_94mg44b6).\n\n## What was proven, with receipts\n\n| call | result | latency | receipt |\n| --- | --- | --- | --- |\n| IMSG_CHATS 2 | two conversations, decoded | 454 ms | [inv_2fhwaze5qp](/receipt/inv_2fhwaze5qp) |\n| IMSG_AFTER 677275, 2 | two newer messages, next cursor | 400 ms | [inv_h26qrni500](/receipt/inv_h26qrni500) |\n| IMSG_SEND_STATUS (guid of the proof message) | send_state delivered, delivered_at 19:17:39Z | 300 ms | [inv_nvhvrixojr](/receipt/inv_nvhvrixojr) |\n| IMSG_WHOIS (a number never messaged) | known false, service unknown | 46 ms | [inv_ijalm9asg1](/receipt/inv_ijalm9asg1) |\n| IMSG_STATUS | database ready, SIP enabled, 14 live RPC methods | 41 ms | [inv_0aohsk7rsl](/receipt/inv_0aohsk7rsl) |\n| IMSG_VERBS | 36 verbs | 40 ms | [inv_g444m2ezhz](/receipt/inv_g444m2ezhz) |\n| IMSG_WATCH_STATUS | watching false | 43 ms | [inv_fmn0qce9e0](/receipt/inv_fmn0qce9e0) |\n| IMSG_HISTORY 2803, 2 | two messages with decoded text | 167 ms | [inv_m1v6eji4ml](/receipt/inv_m1v6eji4ml) |\n\nThe send itself: one message to the owner's own number, sent by imsg from a process that already held Apple's automation consent for Messages, accepted as row 677278 with guid 63BBA90F-1238-4A76-807C-24C1FCB46FE0, and reported by `message.send_status` as delivered at 19:17:39Z, 90 seconds later. The reaction: `IMSG_REACT` placed a thumbs-up on that message through the bridge process in 2,870 ms, verified by the program against the window, with no consent dialog, because Accessibility was already granted to the bridge. A full-account `IMSG_STATS` took 7,180 ms and counted 666,877 messages; every other read finished under 1.2 seconds.\n\n## The one consent that remains\n\nmacOS grants automation rights per program, per target. The bridge process holds Apple Events consent for System Events, Calendar and Chrome, and Full Disk Access, Accessibility and Screen Recording. It does not yet hold Apple Events consent for Messages. Every read above works without it; the reaction works without it because Accessibility is a different grant. The four sending rows (`IMSG_SEND`, `IMSG_SEND_CHAT`, `IMSG_SEND_FILE`, `IMSG_CREATE_CHAT`) go through AppleScript and will, on their first call from the bridge, raise the standard one-time dialog on the Mac's screen asking whether the bridge may control Messages. Allowing it once makes the sending rows permanent. The send was proven from a process that already had the grant, so the mechanism is not in doubt; the grant for the bridge process is.\n\n## Inbound: messages as events\n\nTwo inbound paths exist. The first needs nothing running: any flow keeps a cursor and calls `IMSG_AFTER`. The second is a watcher on the Mac that streams every new message as it lands, appends the full record to a local event log (readable through `IMSG_INBOX` and `IMSG_INBOX_SINCE`), and posts one metadata-only observation to the [device capability ledger](/device-capability-ledger) per message: direction, chat, direct or group, service, attachment count, text length. Never the text, never the handle. The watcher is written and its launch definition is in place; the operator loads it with one command, and until then `IMSG_WATCH_STATUS` reports watching false.\n\nAlongside it runs a state collector that samples the Mac every 60 seconds and writes only what changed: frontmost app, Focus mode, power source, Wi-Fi network (hashed), screen locked or not, presence by idle time, Bluetooth devices, the set of running apps, attached displays, the row counts of the Mail, Safari, Chrome, Photos, Notes, Calendar, Messages and Contacts stores, the next calendar event's start time, and whether the paired iPhone answers over the network. Its first run wrote 19 observations to the ledger under receipt [8261ba99](/receipt/8261ba99-845f-40a0-b1e9-2590cfec0d4a).\n\n## What the ledger now records\n\nThe same ingest that carries those observations carries the research behind the choice of programs. Fifteen open-source iMessage projects were read from source, and each is now an executor row in the ledger with its mechanism, its requirements, what it uniquely adds and its verdict; two were absorbed (the two programs above), seven are reference material only, six were rejected, one of them for forging device identities against Apple's push service, and the rest for needing SIP disabled, being dead, or exposing a network port with weak authentication. The ledger's [machine projection](/api/capability-census) lists 109 executors, 9 of them ready on this Mac, and 36 verified capabilities, each with the receipt of the call that verified it. Twenty-four of those were verified today through the bridge: the iMessage reads above, and read access to the Mac's Contacts (408 records), Calendar (174 items), Notes (1,012), Mail (262 envelopes), Photos (47,213 assets), Safari and Chrome history, Spotlight, power, Bluetooth and process state. Also recorded as candidates, not yet invoked: the owner's Home shortcuts (door lock, gate code) callable by `shortcuts run`, and the AppleScript dictionaries of Excel, Word, Outlook, Keynote, Numbers, Pages, Chrome, Safari and the ChatGPT desktop app, each a licensed or signed-in program the Mac can operate without a vendor API.\n\n## What decides the next step\n\nThree facts bound what comes next. The iPhone answers over the network (iOS 26.6.1) for device information and file transfer, but every developer service, including screenshots and element-level control, requires Developer Mode, which iOS refuses to enable while a passcode is set. The Mac's Messages, Contacts, Calendar, Notes, Mail and Photos stores are all readable today through the bridge, so the reading half of the personal data surface is done; the writing half is one Apple Events consent per app. And the watcher and collector prove the pattern that turns any local state change into a ledger row without a model in the loop: sample, diff, post. The [device capability ledger](/device-capability-ledger) is where each new verb lands first, and a verb is promoted into the directory only after a real call has returned real data.\n","register":"standard","hero":"https://miscsubjects.com/img/gen/arcads-gpt-image-19d1328d-e069-49c4-851a-ee1c93de9c06.png","hero_brief":"A silver laptop and a phone lying side by side on a plain oak desk under window light; a small thermal receipt printer beside them has printed a long paper receipt that curls off the desk edge; a brass desk bell at the corner.","editorial_review":{"headline_subject":"the Mac's iMessage turned into 34 callable verbs, each call receipted","hero_subject":"a laptop and a phone on a desk beside a receipt printer that has printed a long paper receipt","visual_action":"the receipt printer's paper receipt curls off the desk edge next to the two devices; a desk bell waits at the corner","rationale":"every call to one of the 34 verbs leaves a receipt on the ledger; the literal objects are the two devices whose messages became callable, and a receipt printer producing the record of calls","hero_brief":"A silver laptop and a phone lying side by side on a plain oak desk under window light; a small thermal receipt printer beside them has printed a long paper receipt that curls off the desk edge; a brass desk bell at the corner.","inspected":true,"inspection_note":"Visible: an open silver laptop with a dark screen and a black phone face-down beside it on an oak desk; a black thermal receipt printer with a long white receipt spilling over the desk edge; a brass desk bell on the right; window light from the left. No people, no logos; the receipt's print is not legible. Matches the brief."},"tags":["imessage","mac","capability-fabric","device-ledger","api"],"category":"build","style":{},"claims":[{"id":"c1","text":"An API, here, means a row in this site's directory that any model or program can call with one HTTP request, that runs on the owner's Mac through the Mac bridge, and that leaves a public receipt on the ledger for every call. On 2026-09-08 the Mac's iMessage became 34 such rows.","section":"iMessage as an API: 34 message verbs on the owner's Mac, each call receipted","tier":"definition","source_ids":["s3"],"why_material":"defines what was built and where it lives"},{"id":"c2","text":"Of the 6,084 messages on this Mac since 2026-08-01, 5,402 have an empty text column. A raw SQL read therefore returns blanks for 89% of recent messages.","section":"Where the messages are and why a plain read fails","tier":"observational","source_ids":["s3","s1"],"why_material":"the measurement that decided the executor"},{"id":"c3","text":"One message to the owner's own number, sent by imsg, accepted as row 677278 with guid 63BBA90F-1238-4A76-807C-24C1FCB46FE0, and reported by message.send_status as delivered at 19:17:39Z. IMSG_REACT placed a thumbs-up on that message through the bridge process in 2,870 ms with no consent dialog.","section":"What was proven, with receipts","tier":"observational","source_ids":["s3"],"why_material":"the send and the act lanes are proven, not described"},{"id":"c4","text":"The bridge process does not yet hold Apple Events consent for Messages; the four sending rows will, on their first call from the bridge, raise the standard one-time dialog on the Mac's screen.","section":"The one consent that remains","tier":"regulatory","source_ids":["s1"],"why_material":"the single gate between the proven mechanism and unattended sending"},{"id":"c5","text":"Actions on specific messages run through platform-imessage, Beeper's library, which drives a second window of the Messages app through macOS Accessibility, because Apple's scripting surface for Messages can send text and files and nothing else.","section":"The two programs underneath","tier":"definition","source_ids":["s2"],"why_material":"why two executors rather than one"}],"sources":[{"id":"s1","url":"https://github.com/openclaw/imsg","title":"openclaw/imsg README, Permissions","quote":"Full Disk Access is required for local database reads. Sending and standard tapbacks also require **Automation → Messages**; Contacts access is optional and only adds resolved names."},{"id":"s2","url":"https://github.com/beeper/platform-imessage","title":"beeper/platform-imessage README","quote":"A standalone Swift library and CLI that lets you and your agents send/receive messages and fully automate iMessage locally on your Mac."},{"id":"s3","url":"https://miscsubjects.com/api/capability-census","title":"Device capability ledger, machine projection (executor rows and verified capabilities with receipts)","quote":"Primary iMessage executor: decodes attributedBody (89% of recent rows are blank without it), verifies sends against chat.db with delivery dispositions, message.send_status, cursor feed messages.after, NDJSON watch."}],"prov":{"model":"unattributed","action":"write"}}