Skip to content

About

Every TrUAPI, one click away.

Resources

Contributing

Security policy

Stars

1 star

Watchers

1 watching

Forks

Repository files navigation

Host Playground

Warning

The following is a prototype, reference implementation, and proof-of-concept. This open source code is provided for research, experimentation, and developer education only. This code has not been audited, is actively experimental, and may contain bugs, vulnerabilities, or incomplete features. Use at your own risk.

Every TrUAPI, one click away.

Host Playground is code developed and published by Parity that puts a button behind every host API that @parity/product-sdk exposes.

A host API is what a sandboxed Polkadot application calls to reach the wallet around it. Signing, accounts, chain state, notifications, storage. Each one gets a card here, so you can press it and read the real answer instead of writing a throwaway app to find out.

Access

Browser

Network Link
Paseo https://host-playground.paseo.li
Previewnet https://host-playground.testnet.li

These are instances Parity runs for its own testing. They carry no availability commitment. Deploy your own copy for anything you depend on.

Polkadot Desktop and Mobile

Install the Polkadot app, then search for the domain.

Network Domain
Paseo host-playground.paseo
Previewnet host-playground.dot

Development

Node 22 and Corepack, which pins yarn to the version in packageManager.

corepack enable
yarn install --immutable
yarn dev              # Previewnet, the default
yarn dev:paseo        # Paseo

The cards that write to a network need a funded account on that network. The read-only cards work without one.

Local signing host

truapi-host dev starts a signing host on loopback and then runs the dev server with that host already live, so the cards work in a plain browser tab instead of a Host webview:

cargo install --git https://github.com/paritytech/host-rust-core \
  --bin truapi-host --locked truapi-host-cli

truapi-host dev -- yarn dev:paseo

Open http://localhost:3000. In development the root layout loads the bridge snippet the host serves at http://127.0.0.1:9955/bootstrap.js, which installs the message port the SDK talks over. Confirmations are approved automatically, so the host signs whatever a card asks for.

Host and app have to serve the same network, otherwise the chain cards report Host does not serve chain <genesis>. truapi-host dev defaults to Paseo Next v2, which is what yarn dev:paseo builds against. Pair it with Paseo only. Previewnet resets often, and --network previewnet works only while the genesis hashes in NETWORKS match the live chains.

Test

yarn typecheck
yarn lint
yarn test:e2e         # Playwright against a mock Host

The E2E suite drives the real cards through @parity/host-api-test-sdk, so it runs without a Host of its own.

Deployment

Deploy your own copy with bulletin-deploy, published on npm. It uploads the static export and publishes the dotNS records that make it resolvable in a Polkadot host.

yarn build
npm install -g bulletin-deploy
export MNEMONIC="$(cat ~/.config/host-playground/deploy-seed)"
bulletin-deploy --env paseo-next-v2 apps/app/out your-name.paseo

Read the seed from a file rather than typing it inline. An inline assignment lands in shell history and is readable from the process environment.

bulletin-deploy.config.ts is the product manifest. The domain there has to match the domain argument exactly, suffix included.

In this repository, pushing to main deploys to Previewnet and Paseo through GitHub Actions, and every pull request gets its own preview domain posted back as a comment.

Security

Warning

The following is a prototype, reference implementation, and proof-of-concept. This open source code is provided for research, experimentation, and developer education only. This code has not been audited, is actively experimental, and may contain bugs, vulnerabilities, or incomplete features. Use at your own risk.

This repository has not received a security audit. Treat it as a reference for how the host APIs behave, not as a hardened build to depend on.

Before deploying this for real use cases, you are responsible for:

  • Reviewing the code yourself. We publish a reference, not a production build.
  • Checking that the dependencies are current and free of known vulnerabilities.
  • Securing your own fork or deployment environment, including keys, secrets, and network configuration.
  • Tracking the latest commits for security fixes. Older releases are not backported.

SECURITY.md covers what to report, what is out of scope, and how to reach us. For the Parity disclosure process and Bug Bounty programme, see https://parity.io/bug-bounty.

Contribute

CONTRIBUTING.md covers documentation and test style. AGENTS.md maps the repo, one line per directory, and lists the gotchas worth knowing before a first change. New cards go in apps/app/lib/tests/, one file per category.

License

Apache-2.0. See LICENSE.

Copyright 2026 Parity Technologies.

Happy Building! 💻💻

About

Every TrUAPI, one click away.

Resources

Contributing

Security policy

Stars

1 star

Watchers

1 watching

Forks

Contributors

Languages