Compatibility
Legend: 🟢 compatible, 🟡 compatible with gaps, 🔴 missing, ⚪ outside the ActivityPub and Mastodon API compatibility targets.
ActivityPub and Federation
Discovery
| Support | Area | Notes |
|---|---|---|
🟢 |
WebFinger |
|
🟢 |
|
|
🟡 |
|
Counts are placeholders. |
Actors and Objects
| Support | Area | Notes |
|---|---|---|
🟢 |
Actor document |
Local actors advertise the instance-wide shared inbox and explicit FEP-5feb search-indexing
consent. Remote Person, Service, Application, and Group actors are accepted and projected through
Mastodon-compatible |
🟡 |
Outbox |
Mastodon-compatible cursor pages expose requester-visible |
🟢 |
Status object pages |
|
🟢 |
ActivityStreams polls |
Local and cached-remote |
🟢 |
Featured posts |
|
🟢 |
Actor keys |
FEP-521a RSA and Ed25519 |
🟢 |
FEP-8967 link previews |
Inbound Notes prefer the first valid |
Inbox and Delivery
| Support | Area | Notes |
|---|---|---|
🟡 |
Inbox integrity |
Transient ID-less activities are unsupported. Every POST remains HTTP-signed. A request signed
by the declared activity actor is accepted through HTTP authentication; a distinct forwarding
signer must carry a valid top-level FEP-8b32 |
🟢 |
Signed HTTP requests |
Legacy Cavage RSA signatures and Mastodon-compatible RFC 9421
|
🟢 |
Outbound delivery |
ActivityPub POST delivery uses legacy Cavage RSA first and retries the identical target and body once with RFC 9421 RSA after HTTP 400 or 401. Other responses and network errors do not switch signature formats. Newly queued local activities are proved once with the active Ed25519 key before durable fan-out, so recipients and retries receive identical JSON. Existing unsigned queued jobs remain deliverable. Proofs are also emitted for private and direct activities: recipients can transfer those proofs to third parties as evidence of authenticity, so audience addressing remains an access-control signal rather than cryptographic confidentiality. Identical broadly addressed activities are queued once per advertised shared inbox; direct and actor-specific activities keep using personal inboxes. |
🟢 |
Remote fetch/cache |
Cold avatar, header, attachment, and attachment-preview proxy requests wait for one coordinated durable fetch and return usable media immediately when the origin succeeds. Stale cached media is served while refreshing. Reciprocal-alias-verified account moves transfer accepted local followers and list memberships through bounded, retryable Follow/Undo jobs. |
Moderation and Safety
| Support | Area | Notes |
|---|---|---|
🟢 |
Domain policy |
Mastodon-compatible database-backed |
🟢 |
SSRF protections |
|
🟢 |
Federation moderation |
Account and domain suspension is local server policy. Suspending a local actor emits the standard
ActivityPub actor |
🟢 |
Federated reports |
Signed ActivityPub |
Mastodon API
Instance and Discovery
| Support | Area | Notes |
|---|---|---|
🟡 |
|
Counts and advertised capabilities are minimal. Ordered database-backed rules are included. |
🟢 |
|
Returns the active administrator-configured rules in display order. |
⚪ |
|
Roosty-specific extension. |
🟢 |
Explore and trends |
Trending hashtags, statuses, and rich preview-card links are available from shared,
transactionally maintained caches. Trending links can be opened through
|
OAuth
| Support | Area | Notes |
|---|---|---|
🟢 |
|
|
🟢 |
|
|
🟢 |
|
Supports authorization-code/PKCE user tokens and client-credentials application tokens. |
🟢 |
|
Accounts and Preferences
| Support | Area | Notes |
|---|---|---|
🟢 |
|
|
🟡 |
|
Only profile basics, avatar/header images, and posting defaults are supported. |
🟢 |
|
|
🟢 |
|
|
🟢 |
|
|
🟢 |
|
|
🟡 |
Account metadata |
Remote counts reflect only content cached by this instance. Verified handle refreshes retain the
stable account ID; conflicting or temporarily unverifiable handles expose |
🟢 |
Admin accounts API |
Account listing, limit, suspend, unsuspend, and suspended-account deletion are available. Report-linked limit and suspension actions are available. Custom roles are missing. |
🟢 |
Admin domain blocks API |
|
🟢 |
Roosty admin API/UI |
|
🟡 |
Reports |
Client filing and administrator list/detail/update/assignment/resolution APIs are available with
cursor pagination. |
🟡 |
|
App-token-authorized open registration creates immediately active accounts. Confirmation email,
manual approval, age policy, and CAPTCHA are not yet supported. Durable rolling signup limits are
shared across processes and use proxy-safe client identification;
the configured |
🔴 |
Local account migration |
Roosty accounts cannot yet declare migration aliases or initiate an outbound |
🟢 |
|
|
🟢 |
Account statuses |
|
🟡 |
Follow graph |
Language filters are missing. |
🟢 |
|
|
🟢 |
Mutes and blocks |
|
🟢 |
Lists |
Search
| Support | Area | Notes |
|---|---|---|
🟡 |
|
Accounts, hashtags, and authenticated status search are supported. Explicitly indexable public posts are broadly searchable; opted-out posts remain limited to ownership, mentions, and known interactions. Status matching uses case-insensitive literal substrings of at least three characters; anonymous status results remain empty. |
🟡 |
Remote account resolution |
Exact handles and authenticated HTTPS actor/profile URL searches are resolved. Status and Collection URL resolution is not yet supported. |
Statuses
| Support | Area | Notes |
|---|---|---|
🟢 |
|
Supports immediate and scheduled polls with Mastodon’s option and expiry limits. |
🟢 |
Scheduled statuses |
|
🟢 |
|
|
🟢 |
|
|
🟢 |
|
Legacy edits expose only their known current state. |
🟢 |
|
|
🟢 |
|
Poll option/multiple changes reset votes; expiry-only changes retain them. |
🟢 |
Polls |
|
🟢 |
|
|
🟡 |
Status pins |
Private posts cannot be pinned. |
🟢 |
Replies |
|
🟢 |
Mentions |
|
🟢 |
Hashtags |
Includes authenticated |
🟡 |
Status links |
Explicit HTTP(S) URLs are safely linkified and rich preview cards are cached and exposed. Bare domains without a URL scheme remain plain text. |
🟢 |
Conversations |
|
🟢 |
Visibility semantics |
|
🟢 |
|
|
🟢 |
Favourites |
|
🟢 |
|
Cached-remote statuses expose interactions known to this instance. |
🟢 |
|
|
🟢 |
Boosts |
|
🟢 |
|
Cached-remote statuses expose interactions known to this instance. |
🟢 |
Quote posts |
|
🟢 |
Bookmarks |
Timelines
| Support | Area | Notes |
|---|---|---|
🟢 |
|
|
🟢 |
|
|
🟢 |
|
|
🟢 |
|
|
🟢 |
Cursor pagination |
Notifications and Markers
| Support | Area | Notes |
|---|---|---|
🟢 |
|
Includes poll-completion and administrator report notifications. |
🟢 |
Notification policies and requests |
|
🟢 |
|
|
🟢 |
|
|
🟢 |
Persisted notifications |
|
🟢 |
Notification read state |
Tags, Push, and Media
| Support | Area | Notes |
|---|---|---|
🟢 |
|
Authenticated responses include followed and featured-tag state. |
🟢 |
|
|
🟢 |
Featured hashtags |
|
🟢 |
|
|
🟢 |
|
Includes poll and |
🟢 |
Push delivery |
|
🟡 |
Media upload |
Video and audio uploads are missing. |
🟡 |
Custom emojis |
Local emoji administration and outbound emoji federation are missing. |
Streaming
| Support | Area | Notes |
|---|---|---|
🟢 |
|
Supports multiple Roosty processes through PostgreSQL-backed fan-out. |
🟢 |
|
|
🟢 |
|
|
🟢 |
Public status events |
|
🟢 |
|
|
🟡 |
Subscribe controls |
Hashtag and list subscriptions, including their required parameters, are unsupported. |
🟢 |
|
Poll completion and |
🟡 |
|
Limited to local status deletes and removed boost timeline entries. |
🟢 |
Multi-process fan-out |
First-party Web UI
| Support | Area | Notes |
|---|---|---|
🟢 |
Welcome and about pages |
|
🟢 |
Metadata |
|
🟢 |
Authentication |
|
🟢 |
Profile and status pages |
Local profile tabs and bounded status threads are server rendered, session-aware, and
UUID-cursor paginated. Eligible public documents expose |
Federation
| Support | Area | Notes |
|---|---|---|
🟢 |
Local ActivityPub identity |
|
🟢 |
Remote discovery and profile projections |
|
🟢 |
Outbound status lifecycle |
|
🟢 |
Inbound status lifecycle |
|
🟢 |
Follow graph federation |
|
🟢 |
Remote timeline fan-out |
|
🟢 |
Remote replies, mentions, favourites, and boosts |
|
🟢 |
Featured content federation |
|
🟢 |
Remote conversations and moderation |
Mixed conversations, bilateral moderation, and verified inbound account migration are supported. |