Compatibility

Legend: 🟢 compatible, 🟡 compatible with gaps, 🔴 missing, ⚪ outside the ActivityPub and Mastodon API compatibility targets.

ActivityPub and Federation

Discovery

Support Area Notes

🟢

WebFinger

🟢

/.well-known/nodeinfo

🟡

/nodeinfo/2.0, /nodeinfo/2.1

Counts are placeholders.

Actors and Objects

Support Area Notes

🟢

Actor document

Local actors advertise the instance-wide shared inbox and explicit FEP-5feb search-indexing consent. Remote Person, Service, Application, and Group actors are accepted and projected through Mastodon-compatible bot, group, and indexable account fields.

🟡

Outbox

Mastodon-compatible cursor pages expose requester-visible Create and Announce activities. Other published activity types are not archived.

🟢

Status object pages

🟢

ActivityStreams polls

Local and cached-remote Question objects support oneOf/anyOf, aggregate tallies, expiration/closure, tally Update delivery, and Mastodon-compatible Create(Note) votes.

🟢

Featured posts

🟢

Actor keys

FEP-521a RSA and Ed25519 Multikey methods are discovered, cached, and published alongside the legacy ActivityStreams RSA publicKey. Active keys rotate automatically with a bounded overlap.

🟢

FEP-8967 link previews

Inbound Notes prefer the first valid Link.href attachment and fall back to scanning linked content. Outbound Notes include the locally selected preview URL as a Link while retaining media Document attachments. Preview metadata is always fetched through Roosty’s SSRF-safe pipeline.

Inbox and Delivery

Support Area Notes

🟡

Inbox integrity

Transient ID-less activities are unsupported. Every POST remains HTTP-signed. A request signed by the declared activity actor is accepted through HTTP authentication; a distinct forwarding signer must carry a valid top-level FEP-8b32 eddsa-jcs-2022 proof controlled by that actor. Proof sets, chains, and mldsa44-jcs-2024 are not supported.

🟢

Signed HTTP requests

Legacy Cavage RSA signatures and Mastodon-compatible RFC 9421 rsa-v1_5-sha256 and ed25519 signatures are accepted. Body-bearing RFC requests require a signed, verified RFC 9530 Content-Digest; signed GET requests do not require one. FEP-8b32 eddsa-jcs-2022 proofs use the actor’s FEP-521a Ed25519 assertion method.

🟢

Outbound delivery

ActivityPub POST delivery uses legacy Cavage RSA first and retries the identical target and body once with RFC 9421 RSA after HTTP 400 or 401. Other responses and network errors do not switch signature formats. Newly queued local activities are proved once with the active Ed25519 key before durable fan-out, so recipients and retries receive identical JSON. Existing unsigned queued jobs remain deliverable. Proofs are also emitted for private and direct activities: recipients can transfer those proofs to third parties as evidence of authenticity, so audience addressing remains an access-control signal rather than cryptographic confidentiality. Identical broadly addressed activities are queued once per advertised shared inbox; direct and actor-specific activities keep using personal inboxes.

🟢

Remote fetch/cache

Cold avatar, header, attachment, and attachment-preview proxy requests wait for one coordinated durable fetch and return usable media immediately when the origin succeeds. Stale cached media is served while refreshing. Reciprocal-alias-verified account moves transfer accepted local followers and list memberships through bounded, retryable Follow/Undo jobs.

Moderation and Safety

Support Area Notes

🟢

Domain policy

Mastodon-compatible database-backed noop, silence, and suspend rules cover exact domains and subdomains. Optional media/report rejection and comments are persisted.

🟢

SSRF protections

🟢

Federation moderation

Account and domain suspension is local server policy. Suspending a local actor emits the standard ActivityPub actor Delete; ActivityPub defines no inverse unsuspend activity.

🟢

Federated reports

Signed ActivityPub Flag activities are delivered for forwarded remote reports and accepted idempotently for local targets. Domain reject_reports policy drops inbound reports.

Mastodon API

Instance and Discovery

Support Area Notes

🟡

/api/v1/instance, /api/v2/instance

Counts and advertised capabilities are minimal. Ordered database-backed rules are included.

🟢

GET /api/v1/instance/rules

Returns the active administrator-configured rules in display order.

⚪

/api/v1/version

Roosty-specific extension.

🟢

Explore and trends

Trending hashtags, statuses, and rich preview-card links are available from shared, transactionally maintained caches. Trending links can be opened through /api/v1/timelines/link. Results are eventually consistent and normally refresh within ROOSTY_TRENDS_REFRESH_INTERVAL. The public profile directory supports active/new ordering, local-only filtering, and offset pagination. Authenticated v1/v2 account suggestions combine bounded friends-of-friends results with global social proof from accepted local followers, with offset pagination and durable per-account dismissals. Global scores use a concurrently refreshed PostgreSQL materialized view and normally refresh daily, configurable through ROOSTY_ACCOUNT_SUGGESTIONS_REFRESH_INTERVAL. Viewer-specific follows, moderation policy, friends-of-friends relationships, and dismissals are enforced when each page is read.

OAuth

Support Area Notes

🟢

POST /api/v1/apps

🟢

GET/POST /oauth/authorize

🟢

POST /oauth/token

Supports authorization-code/PKCE user tokens and client-credentials application tokens.

🟢

POST /oauth/revoke

Accounts and Preferences

Support Area Notes

🟢

GET /api/v1/accounts/verify_credentials

🟡

PATCH /api/v1/accounts/update_credentials

Only profile basics, avatar/header images, and posting defaults are supported.

🟢

GET /auth/edit, POST/PUT/PATCH /auth

🟢

GET /api/v1/preferences

🟢

GET /api/v1/accounts/search

🟢

GET /api/v1/accounts/lookup

🟡

Account metadata

Remote counts reflect only content cached by this instance. Verified handle refreshes retain the stable account ID; conflicting or temporarily unverifiable handles expose invalid_handle: true with a server-unique placeholder acct. Remote actor kinds and FEP-5feb indexability are retained.

🟢

Admin accounts API

Account listing, limit, suspend, unsuspend, and suspended-account deletion are available. Report-linked limit and suspension actions are available. Custom roles are missing.

🟢

Admin domain blocks API

GET, POST, PUT, and DELETE under /api/v1/admin/domain_blocks, including cursor pagination.

🟢

Roosty admin API/UI

🟡

Reports

Client filing and administrator list/detail/update/assignment/resolution APIs are available with cursor pagination. collection_ids[], warnings, and custom moderator roles are not yet supported.

🟡

POST /api/v1/accounts

App-token-authorized open registration creates immediately active accounts. Confirmation email, manual approval, age policy, and CAPTCHA are not yet supported. Durable rolling signup limits are shared across processes and use proxy-safe client identification; the configured approval mode therefore fails closed.

🔴

Local account migration

Roosty accounts cannot yet declare migration aliases or initiate an outbound Move.

🟢

GET /api/v1/accounts/:id

🟢

Account statuses

🟡

Follow graph

Language filters are missing.

🟢

GET /api/v1/follow_requests

🟢

Mutes and blocks

🟢

Lists

Support Area Notes

🟡

GET /api/v2/search

Accounts, hashtags, and authenticated status search are supported. Explicitly indexable public posts are broadly searchable; opted-out posts remain limited to ownership, mentions, and known interactions. Status matching uses case-insensitive literal substrings of at least three characters; anonymous status results remain empty.

🟡

Remote account resolution

Exact handles and authenticated HTTPS actor/profile URL searches are resolved. Status and Collection URL resolution is not yet supported.

Statuses

Support Area Notes

🟢

POST /api/v1/statuses

Supports immediate and scheduled polls with Mastodon’s option and expiry limits.

🟢

Scheduled statuses

🟢

GET /api/v1/statuses/:id

🟢

GET /api/v1/statuses/:id/source

🟢

GET /api/v1/statuses/:id/history

Legacy edits expose only their known current state.

🟢

GET /api/v1/statuses/:id/context

🟢

PUT /api/v1/statuses/:id

Poll option/multiple changes reset votes; expiry-only changes retain them.

🟢

Polls

GET /api/v1/polls/:id and POST /api/v1/polls/:id/votes enforce status visibility, single-vote semantics, hidden totals, and write:statuses scope.

🟢

DELETE /api/v1/statuses/:id

🟡

Status pins

Private posts cannot be pinned.

🟢

Replies

🟢

Mentions

🟢

Hashtags

Includes authenticated following and featuring metadata, tag follow controls, and Mastodon 4.4 name-based feature/unfeature controls. Legacy featured-tag management remains available.

🟡

Status links

Explicit HTTP(S) URLs are safely linkified and rich preview cards are cached and exposed. Bare domains without a URL scheme remain plain text.

🟢

Conversations

🟢

Visibility semantics

🟢

GET /api/v1/favourites

🟢

Favourites

🟢

GET /api/v1/statuses/:id/favourited_by

Cached-remote statuses expose interactions known to this instance.

🟢

GET /api/v1/bookmarks

🟢

Boosts

🟢

GET /api/v1/statuses/:id/reblogged_by

Cached-remote statuses expose interactions known to this instance.

🟢

Quote posts

🟢

Bookmarks

Timelines

Support Area Notes

🟢

GET /api/v1/timelines/home

🟢

GET /api/v1/timelines/public

🟢

GET /api/v1/timelines/tag/:tag

🟢

GET /api/v1/timelines/list/:list_id

🟢

Cursor pagination

Notifications and Markers

Support Area Notes

🟢

GET /api/v1/notifications

Includes poll-completion and administrator report notifications.

🟢

Notification policies and requests

🟢

/api/v2/notifications

🟢

GET/POST /api/v1/markers

🟢

Persisted notifications

🟢

Notification read state

Tags, Push, and Media

Support Area Notes

🟢

GET /api/v1/tags/:name

Authenticated responses include followed and featured-tag state.

🟢

GET /api/v1/followed_tags

🟢

Featured hashtags

🟢

POST /api/v1/tags/:name/follow, POST /api/v1/tags/:name/unfollow

🟢

/api/v1/push/subscription

Includes poll and admin.report alert switches.

🟢

Push delivery

🟡

Media upload

Video and audio uploads are missing.

🟡

Custom emojis

Local emoji administration and outbound emoji federation are missing.

Streaming

Support Area Notes

🟢

GET /api/v1/streaming

Supports multiple Roosty processes through PostgreSQL-backed fan-out.

🟢

GET /api/v1/streaming/direct

🟢

GET /api/v1/streaming/health

🟢

Public status events

🟢

status.update events

🟡

Subscribe controls

Hashtag and list subscriptions, including their required parameters, are unsupported.

🟢

notification events

Poll completion and admin.report use the normal notification stream.

🟡

delete events

Limited to local status deletes and removed boost timeline entries.

🟢

Multi-process fan-out

First-party Web UI

Support Area Notes

🟢

Welcome and about pages

🟢

Metadata

🟢

Authentication

🟢

Profile and status pages

Local profile tabs and bounded status threads are server rendered, session-aware, and UUID-cursor paginated. Eligible public documents expose ProfilePage and SocialMediaPosting JSON-LD plus bounded sitemap discovery; sensitive posts are excluded from structured data and sitemaps. ActivityPub actor and Note endpoints remain JSON-only.

Federation

Support Area Notes

🟢

Local ActivityPub identity

🟢

Remote discovery and profile projections

🟢

Outbound status lifecycle

🟢

Inbound status lifecycle

🟢

Follow graph federation

🟢

Remote timeline fan-out

🟢

Remote replies, mentions, favourites, and boosts

🟢

Featured content federation

🟢

Remote conversations and moderation

Mixed conversations, bilateral moderation, and verified inbound account migration are supported.