SIGN IN SIGN UP

chore(release): prepare DomainKit (#108)

## Summary

All bumped packages.

| Package | From | To |
| --- | --- | --- |
| `domainkit` | `0.9.1` | `0.10.0` |
| `@domainkit/react` | `0.9.1` | `0.10.0` |
| `@domainkit/capsuledb` | `0.9.1` | `0.10.0` |

## Changelogs
### `domainkit-discover-zone-host.md`

<details>
<summary>Show Bumped Packages (1)</summary>

| Package | Bump |
| --- | --- |
| `npm:domainkit` | patch |

</details>

#### Discovery names the provider that hosts the zone

`Provider.Definition.nameservers` declares the hostname suffixes a
provider's nameservers end in (Cloudflare `ns.cloudflare.com`, Vercel
`vercel-dns.com`), and `Connect.discover` answers `NotFound` with `host:
{ provider }` naming the one registered provider whose suffixes cover
every authoritative nameserver, or `null`. The discovery route and
`Transport` carry the field, and `Testing.provider` accepts
`nameserverSuffixes`.
### `domainkit-rejected-token-reason.md`

<details>
<summary>Show Bumped Packages (1)</summary>

| Package | Bump |
| --- | --- |
| `npm:domainkit` | patch |

</details>

#### A rejected token reads as Unauthenticated

Cloudflare's HTTP 400 answers with code 6003 or 6111 (a malformed bearer
token) and a 403 from its token verify endpoint fail
`Reason.Unauthenticated` with Cloudflare's own message, as 401 does;
Vercel's 403 `forbidden` on token verification does the same, while a
403 from zone listing stays `Forbidden`. The server answers 401, and
`Testing.conformance.provider` gains a `rejected-token` case that
authenticates empty secrets (or the `rejectedToken` values you pass) and
expects `Unauthenticated`.
### `react-first-party-connect.md`

<details>
<summary>Show Bumped Packages (1)</summary>

| Package | Bump |
| --- | --- |
| `npm:@domainkit/react` | minor |

</details>

#### A first-party connect experience

`Outcome` is a compound part: media, title, description, and the action,
as a card or on one line.
Every flow's `X.Outcome` binds its controller to it, and a host
recomposes it with its own parts
while the words stay in the catalog. `Messages.Catalog` returns a `{
title, description }` pair per
`DomainKit.Error` reason, and `Messages.outcome` reads it.

A failed connect keeps its context. `Connect.State.Failure` carries the
snapshot, the discovery, and
the provider and method that were in flight, so the dialog keeps its
description, its provider
forms, and the values already typed, and answers beside the method that
failed.

A rejected token answers under the field it is about: the input carries
`aria-invalid`, the outcome
renders in `field-error`, and its title names the provider the customer
acted on.

The disconnected state names the provider that serves the domain.
`Connect.Prompt` renders the
provider's mark, its name, and "Owns DNS for this domain." beside a
`Connect` trigger, and the
dialog behind it is titled after that provider and shows its methods
alone, with the rest behind
"Use a different provider". With no host the flow offers nothing unless
it is given
`connect="always"`. Token fields take shadcn's `Field` anatomy, method
buttons carry the verb, and
the fields a provider does not need sit behind "Need an account id?".

## Publish

The following packages will be published if merged:

| Package | Version | Registry |
| --- | --- | --- |
| `domainkit` | `0.10.0` | `npm` |
| `@domainkit/react` | `0.10.0` | `npm` |
| `@domainkit/capsuledb` | `0.10.0` | `npm` |

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Saatvik Arya <saatvik@aryalabs.ai>
G
github-actions[bot] committed
703f2601a9b4ef2ec91598c550d81414f96d3e38
Parent: 3fd5bd0
Committed by GitHub <noreply@github.com> on 9/4/2026, 8:58:28 AM