Cookwala · 2026-10 · draft

The open standard for cooking safely.
People, kitchens and robots.

What to make. When it's done. What must never happen.

Use the arrow keys. 14 slides.

Robots are learning to move. Nobody had written down how to cook.

  • Home and kitchen robots are shipping or taking orders.
  • Each maker writes closed recipes, from a few cuisines, and decides alone what "simmer" and "done" mean.
  • Unsafe food: about 600 million illnesses a year measured · WHO 2015
  • About 14 % of food lost before retail measured · FAO 2019; about 733 million people faced hunger in 2023 measured · SOFI 2024
  • The most intimate dataset in a home is about to be collected by appliances.

Three things a machine can check

  • What to make. Typed steps from a shared vocabulary of 57 operations.
  • When it's done. A temperature, a food-state cue, a time window, and a path when it times out.
  • What must never happen. Safety limits enforced on the device. No recipe, agent, message or operating mode can raise them.

Refuse rather than guess

What to make When it's done What must never happen Dry run before heat 1 · sensor 2 · logged estimate 3 · a person watches no rung: refused accepted:cook inside the envelope log, with consentthe cook's name travels

Every operation has a physical envelope and a sensor ladder. A device climbs the ladder; if it reaches no rung, it refuses before anything heats up.

  • Simmer: water at 85 to 96 °C · deep-fry: oil at 160 to 190 °C
  • Deep frying has one rung: no oil thermometer, no deep frying
  • Sautéing, searing, frying never fall back to time alone; their last rung is a person (so a person who cannot supervise is refused these steps today: an open problem)

Records anyone can check; agents under mandate

  • Hashes over canonical JSON; Ed25519 signatures; keys that can be revoked; selective disclosure
  • Event logs with witnessed checkpoints: a rewrite is detectable; no blockchain required
  • An agent acts only under a signed mandate: scopes, caps, expiry, a confirm-before list
  • Text in a recipe is data, never an instruction

Three loops, one standard

Cook
dry run → execute inside envelopes → log with consent
Rescue
offer → claim → handover → distribute → impact
Find and publish
proven names → exact versions → hashes → recalls
One standard: Core 0.2 and its profiles, open and royalty-free
  • Cook: dry run → execute inside envelopes → log without personal data (Core 0.2, normative)
  • Rescue: offer → claim → handover with a temperature check → distribution → impact with a method (Humanitarian 0.2)
  • Find and publish: proven names, exact versions, hashes, tombstones; organizations by request (Registry)

Food rescue with the phones you have

Store or farm Food bank Handover: temperature checkedAbove 5 °C: refused Kitchen OFFER by SMSCLAIM Meals countedImpact summary, computed

OFFER 36KG YOGURT C 4C UB0511 · CLAIM A7K ALL · HAND A7K 36 T4.6 · DIST 410 MEALS 410 PEOPLE 96KG

  • No personal data: organizations, aggregates, sites; counts under ten suppressed
  • Rule packs derived from public WHO, Codex and Sphere guidance (sources, not partners; none has reviewed them); care rules for children and older adults; reviewable by professionals
  • Four worked flows: a Cairo-style food bank, school meals, a disaster kitchen, a robot kitchen; all four are fictional worked examples
  • A pilot protocol with a baseline, kill criteria and an independent evaluator. No pilot has run.

What a household robot may know

A household's facts 45 types never leave, in any form 81 travel only as a derived constraint 13 by consent, withdrawable Grocer: delivery window, allergen block; never the schedule or the allergy Planner: constraints, never facts; no score of anyone everything erasable within a stated window

The full picture stays home. Only constraints travel.

  • 139 facet types with a privacy class and a travel rule: 45 never leave, 81 only as a derived constraint, 13 by consent
  • A grocer learns "deliver 17:00 to 18:00, label for peanuts", never the schedule or the allergy
  • No behavioural score of anyone; income never inferred; everything erasable

Impact, honestly

  • Measured in the field: nothing. No pilot, no deployment.
  • Modelled: four simulators; robots with the protocol cut waste at every stage, robots alone push waste upstream; rescue reaches a small share of the hungry illustrative
  • Hunger has many causes: poverty, conflict, climate, prices, policy. Cookwala's part is real and partial.
  • Every impact page has "what we don't know yet" and "what went wrong"

What exists today

  • Core 0.2; 24 schemas; 137 public conformance vectors; a signed report format
  • Python package and CLI, TypeScript types, MCP server, reference hub, ROS 2 interfaces, LeRobot and OpenTelemetry exporters
  • Nine recipes at V1 in English and Arabic, and 2,042 recipes imported from fifi.cooking at V0 (described, not machine-verified) with ingredients and steps in Arabic and English and names in 25 languages; four rule packs (drafts); a 139-type facet registry
  • SDK clients in 13 languages and 101 scenarios executed against the reference hub; the site in six languages (English and Arabic by hand; French, Spanish, German and Portuguese by machine, labelled) and core documents machine-translated for those six
  • Four simulators; this deck
  • Users, partners, pilots, revenue: 0

Three goals, three horizons

  • Help end hunger: less waste, safer rescue, programs that compare numbers; later, farms and stores that plan to need
  • Make people healthier: control points a device must meet; rule packs a dietitian can review
  • Put robots to work for people: every cuisine, with credit; people who cannot cook for themselves; human time returned; a labour voice in governance
  • Now: safer devices, food banks, agents that can't be tricked · Next: robots in every cuisine, new roles · Later: cooking as infrastructure

Open and governed in public

  • Royalty-free: Apache-2.0 code, CC BY 4.0 spec, CC0 vocabularies, patent non-assertion pledge
  • RFCs with 30-day comment; safety changes need a named reviewer
  • A steering committee with published numbers and seats for food banks, a low- or middle-income country, labour, privacy, dietetics
  • A neutral foundation for the spec, the name and the mark
  • Critiques published with responses; kill rules written down

Risks, in plain words

  • Adoption: a standard without implementers is a document
  • Correctness: envelopes and rule packs await professional review
  • Safety: a data standard cannot prevent hardware failure or a maker that lies
  • Privacy: constraints can leak by inference; household consent is not one person's
  • Dependence: one founder, one repository, one domain

Join

  • Try: the dry run in your browser, cookwala.ai/playground
  • Build: pip install -e sdk/python · cookwala conformance --report
  • Review: an envelope or a rule pack, two hours
  • Pilot: the concept note, for a first conversation
  • Think: five essays that invite disagreement

cookwala.ai · github.com/amado2k5/cookwala

English Cookwala