Core 0.2 · normative: the part of the standard an implementation must follow to be called conformant, under review

Robots are learning to move. Nobody had written down how to cook.

A free, open rulebook that lets any kitchen device check a recipe step by step before it cooks — and refuses the steps it cannot do safely. Try it below.

  1. What to make. Recipes as steps a machine can plan.
  2. When it's done. Temperatures, food-state cues and times it can measure.
  3. What must never happen. Safety limits the device enforces itself.

Live now

Our MCP server is live. Use it in your AI app today.

Claude Code, Devin, Cursor, Windsurf, Codex, Copilot and any other app that can run an MCP server: a small program that gives an AI agent read-only access to Cookwala tools and data can now search the Cookwala recipes, dry-run: a check of every step of a recipe against what a device can do and sense, before anything heats up a recipe against a device and check safe temperature bands. It is read-only and can never start cooking. No account, no server to run.

claude mcp add cookwala -- npx -y @cookwala/mcp

Needs Node 20 or later. The same package, @cookwala/mcp, works in any MCP-capable app. Listed in the official MCP Registry as ai.cookwala/cookwala.

Can this device cook this recipe?

Before anything heats up, a Cookwala device checks every step and refuses rather than guesses. Pick a recipe, pick or build a device, and watch the answer change. This runs the same rules as cookwala dryrun (a practice check of the recipe against a device, before any heat), entirely in your browser.

3 Human presence

Step 1: Pick a preset device above. Step 2: Or build your own below. Most recipes need a human actively supervising; fewer work with no human.

Build your own device
Loading the recipe and the operation vocabulary…
StepOperationSafe bandWhoChecked by

Bands come from the operation vocabulary. "Estimate" is a logged model estimate; "time" is nominal time only. A step that nothing can check is refused. Deep frying has one rung: no oil thermometer, no deep frying.

Try cookwala dryrun your-recipe.yaml --device device.yaml to run the same rules locally, entirely offline. CLI docs · Using Cookwala from your agent

It started with a family cookbook

Cookwala began with a family archive of Egyptian home cooking, the recipes of Dr. Fatma Alkawokgy (1943 to 2026), published at fifi.cooking in … languages. They were written for people. "Fry until golden." "Add water to cover." "Let it simmer until it is ready." Anyone who grew up in that kitchen knows exactly what those lines mean. A machine does not, and neither does a stranger. When one of those dishes was described so that an oven, a robot or a food bank could check it before cooking, it turned out that nobody had written down what "simmer" is, when chicken is safe, or when a step must be refused. Cookwala is the attempt to write that down, in the open, so that the dishes outlive the machines and the machines refuse rather than guess.

— the founder

Find your path

Within a minute: why Cookwala matters to you, and one thing you can do today.

Why now

Home robots are shipping and kitchen robots are taking orders. Each maker writes its own closed recipes, mostly from a few cuisines, and decides alone what "simmer" or "done" means.

Unsafe food causes about 600 million illnesses a year measured · WHO. About 14 % of food is lost before it reaches a shop measured · FAO, while about 733 million people faced hunger in 2023 measured · SOFI 2024.

Cookwala is the shared, open layer: one way to describe a recipe that a person, a food bank, an oven or a humanoid can read, check and cook safely, in every cuisine, with the cook's name on it. Why this, why now · Impact, with sources

Three goals — help end hunger, make people healthier, put robots to work for people — each told with its measured problem, what exists now, and what we will never claim: How this helps →

Now, next, later

Now

  • Core 0.2 standard and schemas
  • Dry run, validator, 140 conformance vectors: a public test with an input and the expected output that an implementation must reproduce (the public test cases the standard is checked against), conformance reports
  • Python package and CLI, TypeScript types, MCP server, reference hub, ROS 2: Robot Operating System 2, the middleware most robots use to move and communicate interfaces
  • 9 example recipes at V1 and 2,430 recipes imported from fifi.cooking at V0, with names in 30 languages and text in Arabic and English: the recipe index
  • SDK clients in 13 languages and 101 executed scenarios: SDK and scenarios
  • Humanitarian Profile: the add-on that defines food-rescue documents: offer, claim, handover, distribution, impact 0.2 with an SMS grammar: the exact text-message format a basic phone uses to offer, claim and hand over food and four worked flows
  • Household Context Profile: only derived constraints travel
  • Four simulators, illustrative

Next

  • Professional review of envelopes: the physical band an operation must stay in, for example simmering is water at 85 to 96 °C and rule packs: a reviewable list of food-safety and nutrition rules a program chooses to apply, derived from published guidance
  • A food-bank pilot (not yet funded)
  • Agent-safety results per model
  • Packaged SDKs; a registry service
  • A first device maker against the reference hub
  • Core 0.3; a steering committee

Later

  • A real device cooking a Cookwala recipe, unedited
  • Certification with an independent certifier
  • A neutral foundation for the standard
  • A contributor network that teaches robots every cuisine, with credit
  • Supply signals, after competition-law review

Every planned item has a gate: the one thing that has to happen first. If you can open one (a reviewer, a device, a food bank, funding), say so in GitHub Discussions; a direct address will follow from the founder.

The roadmap with a status on every item · what we got wrong so far

What exists today

Counted from the repository at each build. Nothing here is a projection unless it says so.

measured32cooking operations with a physical definition
measured140conformance test vectors
measured14default on-device safety limits
measured10agent-safety test cases
measured43food-safety and nutrition rules for food banks
measured24JSON schemas
measured2,439recipes published in the index
measured139household and device facet types with privacy rules
planned2,430V0 recipes awaiting conversion to V1

Counted at build from commit 8b23d9dce3cc on 2026-10-10. Core 0.2.0.

Safe by design, verifiable by anyone

Safety is enforced on the device, not in the cloud. No recipe, agent, message or extension can raise a device's limits, and a local stop works without a network. AI agents act only under a signed mandate: a signed permission from a person that says what an AI agent may do for them, with limits and an expiry and treat every text field as data, never as instructions.

Every recipe and record can be hashed and signed, keys can be revoked, and event logs carry witnessed checkpoints: a signed summary of an event log that witnesses counter-sign, so a later rewrite can be detected. The tests that prove it are public: 140 vectors.

Read Core 0.2 · Trust · Critiques we published

A recipe step
deep fry the vermicelli
Its safe band
oil at 160 to 190 °C, never unattended
The sensor check
does this device have an oil thermometer?
Yes: accept
cook inside the band and log every reading
No: refuse
no thermometer, no deep frying; nothing heats up
One step of a dry run: the step, its safe band from the operation vocabulary, the sensor the device must have, and the two possible answers. The same check runs for every step before anything heats up.

Where it started: fifi.cooking

Cookwala began as one family's Egyptian recipe archive on fifi.cooking, and fifi.cooking is still its first source of recipes. It is open source too: a static website built with React, TypeScript, Vite and Tailwind CSS, published with GitHub Actions and GitHub Pages, plus native apps for Android, iPhone and iPad, Apple TV, Fire TV and Samsung TV that read the same open JSON files.

Open, and joinable today

Royalty-free. Apache-2.0 code, CC BY 4.0 specification, CC0 vocabularies. No API keys. Model-agnostic and device-agnostic. Governed in public today, with a steering committee once there is a second independent implementation, and a neutral foundation later.

For developers and AI readers