Hiro development journal

Devvit assessed as a community-scoped Reddit source, not a general access bypass

Architecture assessment completed; no implementation or external deployment performed Machine-readable JSON

Executive summary

Reddit's Devvit ecosystem can give an approved app authenticated access to Reddit data without locally managed Reddit OAuth credentials.

That access is installation-scoped: an app ordinarily operates in a subreddit or profile where it is installed, and subreddit installation requires moderator participation.

Devvit therefore cannot simply replace Hiro's desired read-only access to several unrelated technical communities unless those communities install the app or Reddit grants broader capabilities.

Connecting Devvit back to local Hiro is technically possible only through reviewed external networking features, not direct access to a private local address.

The direct non-commercial Data API request remains the simpler primary route; Devvit is a viable parallel experiment for communities where installation authority exists.

Work completed

Devvit Reddit-data capability

Assessed
  • Devvit handles Reddit authentication when an app enables the Reddit permission, avoiding a local client ID and secret.
  • The platform can read posts and comments through its server-side Reddit API capability.
  • The documented data scope is tied to the app installation rather than unrestricted Reddit-wide polling.
  • A moderator normally installs the app into a subreddit, so access to independent communities cannot be assumed.

Devvit-to-Hiro transport

Possible with review and constraints
  • Devvit server code can send HTTPS requests to allow-listed external domains.
  • Personal domains are generally not approved, and every requested domain must be documented for app review with terms and a privacy policy.
  • Devvit also offers authenticated external endpoints, but this is a limited-access feature requiring separate approval.
  • A production design would transmit only minimized, sanitized hypothesis packets rather than raw Reddit archives or user profiles.

Recommended access strategy

Proposed
  • Continue the direct non-commercial Reddit Data API application because it best matches Hiro's low-volume read-only multi-subreddit use case.
  • Build a Devvit proof of concept only in a test community controlled by the user, where installation permission is available.
  • Use the proof to validate prompt-injection reduction and minimal derived-data export before requesting broader review or approaching moderators.
  • Do not expose the local Hiro service publicly merely to connect Devvit.

Decisions and reasoning

Validation and evidence

CheckStatusResult
Official Devvit Reddit API documentation reviewed Authentication is platform-managed and Reddit-data access is documented as installation-scoped.
Official Devvit HTTP Fetch documentation reviewed Outbound HTTPS requires domain allow-listing; personal domains are generally not approved and app-review documentation is required.
Official Devvit external endpoint documentation reviewed Externally callable authenticated endpoints exist but are currently limited-access and require approval.

Current state

Next steps