The server projects account identity and presence per recipient. A client that does not negotiate these capabilities continues to receive ordinary IRC lines; a capable client receives the additional fields and tags defined by IRCv3. There is one live event and one authorization decision, not separate modern and legacy chat paths.
| Capability | Negotiated presentation |
|---|---|
account-tag |
Authenticated live user commands and retained message replay carry account=<name>. Anonymous commands have no account tag. |
extended-join |
JOIN includes the account name (or *) and real name. |
away-notify |
Shared-channel peers receive later AWAY changes, and an away user joining a channel is announced after their JOIN. The user does not receive their own notification. |
userhost-in-names |
353 entries include nick!~user@anon.invalid. |
multi-prefix |
Every applicable status prefix is presented. Roles are hierarchical here, so an account currently has at most one applicable @ or + prefix. |
account-notify is intentionally not advertised. Authentication is fixed
before registration and Telex does not allow a registered connection to switch
accounts. Advertising a transition capability that cannot produce an
ACCOUNT message made the compatibility surface less honest. Revisit it only
with a separately reviewed post-registration identity-transition model.
multi-prefix remains advertised because the current hierarchical role model
truthfully returns every applicable prefix, even though that is presently at
most one @ or +. Its presentation should be reviewed if accounts can ever
hold simultaneous non-hierarchical channel statuses.
Account tags are composed with msgid, time, and batch tags rather than
creating a second tag section. They cover channel and direct messages plus
user-originated JOIN, PART, QUIT, NICK, TOPIC, MODE, INVITE,
KICK, and AWAY state. Account-backed history resolves the durable principal
back to its account display name; the stored nickname and username snapshot
still preserves the prefix recipients originally saw.
Server-originated state and notices do not borrow the triggering user's account tag. They retain labeled-response correlation where applicable without being misrepresented as commands sent by that account.
The privacy boundary is unchanged. User and host presentation never includes a
socket address or reverse DNS name: even userhost-in-names exposes only the
synthetic anon.invalid host. Account names are already visible through SASL,
extended joins, account tags, and numeric 330 to clients that opt into or query
those standard surfaces. Device IDs are never projected.
The account extban discovery tokens are EXTBAN=$,a and ACCOUNTEXTBAN=a.
Ban masks use canonical $a:account names, while account tags and extended
joins preserve the provisioned display case.