MDS Files

MDS is the native project file format for MIDAS. The file extension is .mds. An MDS file stores datasets, models, reports, workspace layouts, and other project state in a single file.

Saving and Exporting

There are two ways to save an MDS file. Saving to the browser is for frequent saves while you work; exporting as a file is for sharing with other users and keeping backups.

Save to Browser

File > Save to Browser (Cmd+S / Ctrl+S) saves the project to the browser's storage (OPFS). Saved projects appear in the launcher's Quick Access section and can be reopened with a click.

Because this uses browser storage, saved projects are only accessible from the same browser and profile. They do not appear in other browsers or on other devices. Clearing browser data will delete saved projects. When saving, MIDAS requests persistent storage from the browser. If the request is granted, the data is excluded from automatic eviction under storage pressure. Whether to grant the request is up to the browser, so depending on browser settings and available storage capacity, the browser may still evict this data automatically. Export important projects as files for safekeeping.

Export as File

File > Export Project... (Cmd+Shift+S / Ctrl+Shift+S) downloads an .mds file. Exported files are always digitally signed. The first time you export, enter a signer name in the dialog to create your signing key.

Exported MDS files can be shared with other users or kept as backups. To open a received MDS file, use Open File on the launcher screen. On the recipient's side, the signer appears as Unknown by default. If you exchange public keys in advance, the file will be recognized as Trusted. See Managing Signing Keys for details.

About Auto-Save

MIDAS does not perform real-time auto-save. To preserve your work, save explicitly using either method above. Exporting only writes out an MDS file and does not update the project saved in the browser. When you close a project or open another project within MIDAS, a confirmation dialog appears if there are changes not saved to the browser. The dialog appears even after you export the changes, unless you have also saved them to the browser. Closing the browser tab shows no confirmation dialog and discards any changes not saved to the browser.

Data Excluded from Saving

Primary Dataset row data (the original datasets imported from CSV or similar sources) is included in the MDS file. Derived Datasets (datasets produced by queries or transformations) are saved as definitions only; their row data is not saved by default. After opening a project, data is recomputed on demand by re-running the stored operation.

This keeps MDS files small. For Derived Datasets with expensive queries, enable Save data with project to save the computed data as well. See Datasets > Saving Computed Data with the Project for details.

File Structure

An MDS file is a zip file. The zip of an exported MDS file contains three JSON files and the Parquet files1 that record the row data of datasets2. The contents of each file are as follows.

FileContents
manifest.jsonA list of the names, sizes, and SHA-256 hash values of metadata.json and each Parquet file, together with the signer name, the signing time, and the provenance
signature.jsonThe digital signature over manifest.json and the signer's public key
metadata.jsonThe project state that is not stored in Parquet files, such as the names and types of dataset columns, the operations of Derived Datasets, the values of excluded rows, models, reports, and workspace layouts
datasets/*.parquetThe row data of one dataset

There is one Parquet file for each dataset that stores row data. The datasets that store row data are of three kinds: Primary Datasets, Derived Datasets with Save data with project enabled that hold computed data, and Ephemeral Datasets held by open tabs. For any other Derived Dataset, MIDAS records only its definition in metadata.json. MIDAS also records in metadata.json which Parquet file holds the row data of which dataset.

The columns in a Parquet file correspond to the column definitions in metadata.json through IDs that MIDAS assigns to each column. MIDAS names the columns in a Parquet file with these IDs rather than with the dataset's column names. MIDAS records the names and types of the columns in metadata.json. When opening an MDS file, MIDAS checks that the number, IDs, and types of the columns and the number of rows in each Parquet file match the definitions in metadata.json, and does not open a file that does not match3.

MIDAS opens only zip files with the same layout that MIDAS writes. MIDAS stores the files in the zip without compression and lists every file other than manifest.json and signature.json in manifest.json4. MIDAS does not open a zip whose files are compressed or a zip to which a file not listed in manifest.json has been added.

Digital Signatures and Provenance

Exported MDS files are always digitally signed. Signatures use ECDSA P-256 via the Web Crypto API. A signature lets you confirm who ultimately created the file (which key signed it) and also detects tampering that occurs after signing. Signatures do not encrypt the file contents; anyone who obtains the MDS file can read its contents.

Saving to the browser (Save to Browser) does not sign anything. Browser storage is a working area that only this browser reads and writes; signatures apply only to exported files that leave the browser.

When opening an MDS file, MIDAS verifies its signature. Files without a signature, and files that fail verification due to tampering or corruption during transfer, cannot be opened. See Managing Signing Keys for how to handle verification failures.

The signature covers only manifest.json, but MIDAS also detects tampering with metadata.json and each Parquet file through the hash values recorded in manifest.json. A SHA-256 hash value is computed from the contents of a file, and rewriting the contents changes the value. If the signature on manifest.json is valid, MIDAS computes the hash value of each file listed in manifest.json and compares it with the recorded value. As a result, MIDAS does not open a file in which metadata.json, any Parquet file, or manifest.json with its signer name and provenance was rewritten after signing.

If verification passes, the file's trust level is determined from its provenance — who created it and who edited and re-exported it:

Trust LevelDescription
OfficialSigned by the MIDAS Provider's key
TrustedSigned by your own key or a registered public key
UnknownSigned by an unregistered signer

When you edit someone else's MDS file and re-export it, the exported file carries your signature together with a record of the original creator (the provenance). On the recipient's side, the file's trust level is the lowest trust level among everyone in the provenance. This prevents content from an unknown signer from appearing trusted just because it passed through someone else's signature. If you export a file without saving it to the browser or changing anything after opening it, MIDAS writes out the original file unchanged and keeps its original signature.

By default, an MDS file from an unknown signer opens without a confirmation dialog. This is because loading an MDS file by itself never makes MIDAS communicate with an external server. For the operations that can communicate based on the file's contents, how each is handled, and the setting that asks for confirmation every time you open a file from an Unknown signer, see Managing Signing Keys. The signature badge in the menu bar reads Unknown, and clicking it shows the fingerprint. Decide whether to trust the key only after comparing this fingerprint with the value the signer has published.

For generating and managing signing keys, exporting public keys, and registering others' public keys, see Managing Signing Keys.

Data Locality

All data processing in MIDAS happens entirely within the browser. Project data is never sent to any external server. MIDAS stores data in the browser's local storage areas (OPFS and IndexedDB) and downloads exported MDS files to the user's device without going through any external server5. For details on how each storage is used, see Storage Management.

The signing key is also stored in the browser and never sent to any external server. Clearing browser data destroys the signing key, and MDS files you previously signed will be treated as Unknown. For key backup, see Managing Signing Keys.

Version Compatibility

A newer version of MIDAS opens MDS files from older versions, but it cannot open files exported or projects saved to the browser before the July 2026 signature format update. An MDS file records the version of MIDAS that last saved the project. When you open an older MDS file, MIDAS automatically applies migrations and updates the project's version to the version of MIDAS that opened it. If a dataset cannot be converted to the current format, MIDAS removes it from the project together with the datasets, models, report elements, and tabs that depend on it, and shows what it removed in a warning. The July 2026 update changed the signature format to include provenance, and MIDAS does not read the earlier signature format.

MDS files in the format that preceded the zip format described in File Structure also open in the current version of MIDAS, as long as they were written after the July 2026 signature format update. In the earlier format, MIDAS wrote the whole project as a single JSON document, compressed it with gzip, and signed it. When you save a project opened from a file in the earlier format to the browser, or edit and export it, MIDAS writes it in the zip format. If you export the file without saving it to the browser or changing anything after opening it, MIDAS writes out the original file unchanged, in the earlier format.

Versions of MIDAS from before the zip format cannot open MDS files in the zip format and show the error "Invalid MDS file: missing signature". The same applies to projects saved to the browser: once saved in the zip format, they cannot be opened by those earlier versions. Because MIDAS is a web app, an older version of MIDAS mainly runs when the browser has cached it. When you reload the page, the browser loads the latest version of MIDAS.

Among versions that support the zip format, when the version recorded in a file is newer than the MIDAS that opens it, MIDAS shows a warning and then opens the file. The warning states that some features may not work correctly.

Footnotes

  1. Parquet is a file format that stores tabular data column by column. ↩

  2. A project saved to the browser is also a zip, but because it is not signed, it has no signature.json. MIDAS does not record the signer name, the signing time, or the provenance in its manifest.json, and records the provenance in origin.json instead. The copy that MIDAS places in the browser right after opening an MDS file is the opened file itself. ↩

  3. MIDAS reads and writes Parquet files with DuckDB, a SQL engine that runs inside the browser. If you open an MDS file in the zip format while DuckDB cannot start, MIDAS shows an error without opening the project. Save to Browser and exporting also write Parquet files with DuckDB, so they fail in this state. Exporting an unedited file as the original does not write Parquet files, so it does not fail. Reloading the page makes MIDAS start DuckDB again. ↩

  4. MIDAS compresses the Parquet files that hold row data with Zstandard (zstd), using Parquet's own compression feature. ↩

  5. When MIDAS signs and exports a project, or exports a project stored in browser storage without edits, it first writes the MDS file to OPFS and then downloads it. MIDAS deletes this copy in OPFS when you start the next export in the same tab, or when you open MIDAS after closing that tab. ↩