Technical Specification · Version 1.0

`.otmp` & 1tap:// Protocol Specification

The static, offline-first spatial package format and custom URI scheme that power zero-API micro-anchor navigation across the 1TapMap platform.

Specification

1. Overview

Protocol Name
1TapMap Package (.otmp) & 1tap:// URI Scheme
Version
1.0
MIME Type
application/vnd.1tapmap.otmp (alias: application/x-otmp)
Change Controller
1TapMap Platform Architecture Team (1tapmap.com)
Status
Stable — production deployment on 1tapmap.com

A lightweight, static, offline-first spatial data specification and URI protocol designed to execute zero-API micro-anchor navigation on mobile and web clients. Packages carry pre-configured decimal coordinates and venue metadata; no map SDK, API key, or network signal is required to execute a navigation handoff.

Format

2. File Extension Specification (.otmp)

Extension
.otmp
Encoding
Plain UTF-8 JSON
Root Object
OtmpPass
Execution Model
Parsed locally by the 1TapMap PWA Service Worker
Remote API Calls
None (zero-API)

An .otmp file is plain UTF-8 JSON. It is parsed locally by the 1TapMap PWA Service Worker without any remote API calls. The PWA registers as a system-level file handler for the .otmp extension so that opening a pass from a device launches execution immediately.

2.1 Schema

format
string — must equal "otmp"
version
integer — package format version (currently 1)
id
string — unique pass identifier
title
string — human-readable pass title
org
string — issuing organization
subtitle
string (optional) — descriptive subtitle
anchors
array — one or more OtmpAnchor objects

2.2 Anchor Object

id
string — stable anchor identifier (e.g. vip-lot)
label
string — display name shown on the 1-Tap button
note
string (optional) — arrival instructions / door note
lat
number — WGS-84 decimal latitude
lng
number — WGS-84 decimal longitude

2.3 Example Payload

sample.otmp

{
  "format": "otmp",
  "version": 1,
  "id": "ucf-mbb-official-visit",
  "title": "Official Visit Pass",
  "org": "UCF Men's Basketball",
  "subtitle": "Recruit + family — game day micro-anchors",
  "anchors": [
    {
      "id": "vip-lot",
      "label": "VIP Recruits Parking Lot",
      "note": "Lot B7 · attendant gate, show pass on phone",
      "lat": 28.6089,
      "lng": -81.1934
    },
    {
      "id": "arena-players-gate",
      "label": "Addition Financial Arena (Players Gate)",
      "note": "Players Gate — southwest tunnel door, not main box office",
      "lat": 28.6072,
      "lng": -81.1966
    }
  ]
}

Protocol

3. URI Scheme Specification (1tap://)

The 1tap:// custom URI scheme executes a hardware-level handoff, triggering native OS navigation (maps:// on iOS, geo: on Android) to exact sub-meter coordinates — bypassing browser rendering entirely.

3.1 Syntax

ABNF syntax

1tap://[action]?lat=[decimal]&lon=[decimal]&anchor=[name]&label=[display]&note=[arrival]
action
string — execution action (default: route)
lat
decimal — WGS-84 latitude (required)
lon
decimal — WGS-84 longitude (required; alias: lng)
anchor
string — stable anchor identifier (default: anchor)
label
string (optional) — display name for the destination
note
string (optional) — arrival / door instructions

3.2 Browser Registration

Browsers register custom protocols via the web+ prefix. The 1TapMap PWA registers itself as the handler for web+1tap, routing execution through the /open handoff endpoint.

3.3 Example

1tap:// URI

1tap://route?lat=28.6072&lon=-81.1966&anchor=arena_players_gate&label=Players%20Gate&note=southwest%20tunnel

Execution

4. Native OS Handoff

On execution, the parsed coordinates are handed off to the platform's native navigation app. The handoff target is selected by user-agent — no map SDK or paid API is invoked.

iOS

maps://
maps://?daddr=28.6072,-81.1966&q=Players%20Gate&dirflg=d

Android

geo:
geo:28.6072,-81.1966?q=28.6072,-81.1966(Players%20Gate)

Web fallback

https://
https://www.google.com/maps/dir/?api=1&destination=28.6072,-81.1966

Security

5. Security & Data Integrity

  • Non-executable payloads. .otmp files are static JSON data. They are never evaluated as code or executed as scripts.
  • HTTPS transport. Packages and URI handoffs are transported exclusively over HTTPS, protecting coordinates and metadata in transit.
  • Client-side schema validation. Payloads are validated locally against the schema before any navigation handoff is triggered. Malformed or invalid packages are rejected without execution.
  • No remote API calls. The zero-API architecture means no third-party map credentials are transmitted, stored, or exposed — eliminating credential leakage as an attack surface.
  • Offline execution. Passes are cached in local browser memory via the Service Worker and execute identically with zero network signal.

Registry

6. Registration Considerations

Media Type
application/vnd.1tapmap.otmp
File Extension
.otmp
URI Scheme
1tap (browser form: web+1tap)
Intended Usage
Offline-first micro-anchor navigation
Restrictions
Non-executable static JSON; no code execution
Change Controller
1TapMap Platform Architecture Team
Specification Document
This page (1tapmap.com/spec)
Back to Secure Pass