Reference

Every reserved keyword in Envzn — 137 of them, in 11 groups. Each entry says what the keyword does and when you would reach for it; the rule itself belongs to the Constitution, which is normative where the two differ.

Declaration and module structure

KeywordDescription
CLASSA declared structure composed of constant and variable data fields and defined methods, following normal object-oriented protocols of inheritance by extending a parent class and overriding methods, and implementing interface types. It could be a generic type with a template qualifier declared before it.
NAMESPACEA declared structure composed of stateless, constant data fields and methods. It cannot extend a parent namespace or class, and it cannot implement an interface.
EXTENDSA declarative statement that establishes the relationship between a class and its parent, following object-oriented protocols.
IMPLEMENTSA declarative statement that establishes the relationship between a class and an interface, following object-oriented protocols. Every method declared on the interface must be implemented by the class declaring it.
INTERFACEA declared structure composed of declared methods without a defined body.
STRUCTA declared structure composed of constant and variable data fields. It cannot have methods, nor participate in object-oriented protocols of inheritance or interface implementation.
ENUMA declared ordered structure of named elements, where each is optionally assigned a numeric value.
GROUPA declared structure that is an external mechanism to combine primitives, groups, and user-defined types without those having any knowledge of this declared structure. Ideal for an interface with no methods.
METHODA defined function on a class or namespace that evaluates some expression or statement, returning types as defined.
INITA special method on a class that executes when CREATE() is called.
CLEANUPA special method on a class that executes just before a class instance is destroyed by falling out of scope of the {} it was created in, or at the end of the method, or, if its a data field on another class, when that enclosing class is destroyed.
MODULEA collection of classes in the same folder, usually providing related functionality.
UNIONA grouping of multiple types for which an assigned value could only be one of those types, primary example is the 'number' primitive.
ALIASA means to provide shorthand to long namespace names. Must be defined at the top of that class file.
FOREIGNA declaration of a C function, written with matching Envzn types, usually combined with BIND. Always at the top of the file.
FOREIGN_TYPEA declaration of a C structure or type, written with matching Envzn types, usually related to a C function that may require it or return it.
BINDAlways combined with FOREIGN; a functional declaration in Envzn that maps to a C function.
SETS_ERRNOA declarative that attaches to the end of the FOREIGN BIND declaration if that C function also sets ERRNO.
LOADA declarative that is added to a parameter if the C function will write into that parameter space.
UNSAFEA declarative at the start of a {...} block, inside which a FOREIGN_TYPE handle — a raw C pointer the compiler cannot vouch for — may be reached through to read or write a field. It is a narrow permission rather than a suspension of checking: everything else is checked as usual, and only that one otherwise-rejected access (E3036) becomes legal. Provides additional functionality to opaque types.
TEMPLATEA declaration that the following class will be generic and bound by template qualifier.
GIVENPart of the template qualifier declaration where the generic elements are type-limited.
TYPEThe single-parameter form of a template qualifier, naming one generic element and the constraints it must satisfy — TEMPLATE: GIVEN TYPE T IS Cloneable, PRIMITIVE:.
TYPESThe multi-parameter form of a template qualifier, naming several generic elements whose constraint groups are then separated by semicolons — TEMPLATE: GIVEN TYPES V, H; V IS Cloneable; H IS Hashable:.
EXCEPTPart of the template qualifier declaration where the generic elements are type-limited, but this clause excludes subelements of a group, commonly seen with "PRIMITIVE (EXCEPT boolean)"
PRIMITIVEA group defined by the compiler as foundational types, such as int32, float64, char32, binary, number, and complex.
IDENTITYA language mechanism that returns a STRUCT populated with everything the compiler knows about this element at that point.

Type-system modifiers

KeywordDescription
ABSTRACTA declarative on a class stating that this class has at least one method declared but not defined, requiring an override by a subclass.
FINALA declarative on a class stating that this class cannot be extended with inheritance.
OVERRIDEA declarative on a method stating that this method will be called to override a method of the same name and signature in a parent.
SINGLETONA declarative on a class limiting that class to one instance.
PRIVATEA modifier on a data field or method stating that this item cannot be accessed outside of this class. Only usable by class and namespace types.
PROTECTEDA modifier on a data field or method stating that this item can only be accessed outside of this class by subclasses. Only usable by class types.
INTERNALA class data field modifier that allows other classes in the same module to access it freely, yet classes outside of the module are forbidden acces to it. Only usable by class types.
SHAREDA specialization of a class that allows instances of it to become shared mutable references, meaning two handles can modify the same object. Also a modifier on a MUTABLE REFERENCE that allows a second to be created.
VOLATILEReserved for future use.
VALUEA modifier on a class declaration that gives it value identity and inline storage instead of a heap handle, so it is passed and copied as a whole value — VALUE CLASS Money { ... }. It still carries methods, generics and interface conformance, but it is an inheritance leaf: it may implement an interface but it may neither extend nor be extended.
HIDDENA specialization of a class that forces access to a one or a group of classes through a defined interface.
REFERENCEA borrowed handle for an owned object; created by =@ or by passing an owned object into a REFERENCE parameter into method.
MUTABLEA modifier on a data field or local variable allowing MODIFY methods to be accessed freely.
MOVEReserved; RETIRED as a parameter marker (2026-10-01). A plain parameter owns its argument; writing MOVE on a parameter is E1164.
DUPLICATEA mechanism to duplicate whatever is adjacent to the keyword, whether it is an object (it will call clone()), a struct or a primitive.
CONSTANTA modifier on a data field or local variable that establishes that element at compile-time as unchangeable.
MODIFYA declarative on a class method stating that this method will change the internal state of the instance.
AUTOA method modifier that asks the compiler to generate the method body rather than writing one. In V1 it applies to a single form, AUTO METHOD clone() RETURNS <classname> { }.
DERIVEDA modifier on a class data field as a marker for Json serializer/deserializer to not touch it.
BLITTABLEA Group defined in the compiler as types that are able to be trivially copied by value.
DEPRECATEDA modifier that marks a class or a method as obsolete without removing it. A call to a deprecated method, and a construction of a deprecated class, compile and run exactly as before — the mark is advisory and warns at the call site.

Method semantics and instance

KeywordDescription
RETURNSA declarative part of a method stating what types that method should return.
RETURNA language mechanism for exiting a method/function. Requires any type being returned to be in ().
VOIDA language mechanism for stating that a method will return nothing when it finishes.
LAMBDAA keyword that defines an anonymous function, as in LAMBDA (int32 x) { RETURN (x * 2) }. There is no implicit-lambda form anywhere in the language: a bare brace block or a parenthesized parameter list is not a lambda unless LAMBDA precedes it.
OFA language mechanism used with templates to state that this generic type is "of T", example: Array OF T, equivalent to Array[T]
ISA language mechanism used in many situations related to checking the type, some examples: WHEN x IS <interface>, IF y IS VALID THEN {...}
CREATEA language mechanism for (a) allocating memory for a class or struct, (b) calling the INIT() method on the class, and (c) returning the handle to assign it to the left-hand side of the ':='.
SELFA keyword reserved for future use.
SUPERA language mechanism for a subclass to explicitly access data fields and methods of its parent.

Control flow

KeywordDescription
IFA language mechanism to evaluate a given expression, and if true to follow the THEN path, and if false to follow the ELSE path.
THENA language mechanism for the block used when the IF expression evaluates to true.
ELSEA language mechanism for the block used when the IF expression evaluates to false.
WHILEA language mechanism to evaluate a given expression, and if true to continue into the following block, and if false to skip the following block. When the block ends, return to the WHILE line to re-evaluate the expression again.
DOA language mechanism associated with WHILE that sits between the evaluated expression and the following block {}
FORA language looping mechanism declaring an expression to be evaluated with an auto-increment, and if true to continue into the following block, and if false ot skip the following block. When the block ends, return to the FOR line to re-evaluate the expression again.
FOREACHReserved for future use.
LOOPA language looping mechanism over a collection iterator that carries the element's position alongside the element, written as "LOOP name IN collection WITH INDEX index".
REPEATA language looping mechanism that counts without a variable and runs the following block, in two forms: "REPEAT n {...}" or "REPEAT {...}". The latter form runs indefinitely requiring a BREAK to exit that loop.
UNTILA language mechanism associated with FOR and DO that precedes a conditioanl expression: if true with the FOR, enter the following block; if true with the DO, repeat the prevous block. Used like "FOR index=0 UNTIL length {...}" or "DO { ... } UNTIL (<expression>)".
TOThe clause of a counted FOR that names an inclusive upper bound. FOR i = 1 TO 6 runs six times and ends with i == 6, where FOR i = 1 UNTIL 6 runs five times and stops before its bound.
STEPThe optional clause of a counted FOR range that sets the increment between iterations, as in FOR i = 0 TO 10 STEP 2.
INThe clause that names the collection a loop walks, in both FOR e IN items and LOOP e IN items WITH INDEX i. The element binds as a non-owning reference, and the collection is locked against mutation for the duration of the body.
BREAKA language looping mechanism that exits the current loop, moving the the closing "}". Could be followed by a label, like "BREAK copying" if "copying" is a LABEL declared just before the top of the block (really helpful for exiting nested loops).
CONTINUEA language looping mechanism that jumps back to the start of the FOR or WHILE loop.
MATCHA statement that selects one arm from a set of cases, most often the cases of an enum, with an absence arm available for a value that may be EMPTY. It is the dispatch form for a closed set, where IF is the form for a condition.
WHENA language mechanism for evaluating an expression related to class identity, like if a given class extends a parent or implements an interface. Used like "WHEN x IS <classname> {...}"
DEFAULTUsed with MATCH...
WITHThe first half of WITH INDEX, the mandatory clause of LOOP. Both halves are required — a LOOP without WITH INDEX is a compile error, and WITH INDEX on any other loop keyword is one too.
INDEXThe second half of LOOP's mandatory WITH INDEX clause, naming the read-only int64 that carries the element's zero-based position — LOOP e IN items WITH INDEX i. Assigning to it is a compile error, because it is the loop's own state and a writable copy reintroduces the off-by-one the form exists to remove.
HOTLOOPA language mechanism asking the compiler to attempt to optimize that loop; only valid on FOR and WHILE loops.
LABELA declarative name given to a code block, used by BREAK or CONTINUE.

Error handling and STATUS narrowing

KeywordDescription
TRYA declarative given to a code block warning the compiler that the following block could raise a PANIC.
RECOVERA defined block following a TRY block that acts as landing pad to start recovery when a PANIC was raised inside the TRY block; note there could be more than one if a given PANIC type is named with the RECOVER block.
FINALLYA defined block following a TRY block and RECOVER blocks that executes regardless of what path is taken before it.
PANICA language mechanism raised when an invariant condition that should not exist is detected, like DivideByZero.
ASSERTA statement that halts the program when its condition is false, written ASSERT(p.age == 30) => "age should match". It is the dev-only tier of the assertion family and is stripped entirely under -prod, condition and all; unlike a PANIC it aborts without unwinding, so no CLEANUP runs and it cannot be recovered.
ASSERT!The always-on tier of the same family — identical to ASSERT except that the ! marks an assertion that survives -prod and so fires in production. Use it for an invariant that must hold in a shipped build, where ASSERT is for a check that need only hold while developing.
UNREACHABLE!An unconditional, always-on marker for a branch that cannot be reached — the exhaustive-MATCH default, a not-yet-implemented stub, a dead arm. The message is optional, and the analyzer treats it as a control-flow terminator, so it satisfies definite-return and exhaustiveness in a branch that cannot produce a value.
SNAPSHOTA language mechanism for showing what variables are in scope at the given point, along with their type and their value.
STACKTRACEA language mechanism for showing vertically what methods were called from the top, down the stack, to arrive at the given point.
SUCCESSA language mechanism part of the STATUS field.
FAILUREA language mechanism part of the STATUS field.
PARTIAL_SUCCESSA language mechanism part of the STATUS field.
OKA short spelling of SUCCESS in a STATUS narrowing test — IF s IS OK reads as IF s IS SUCCESS.
PARTIALA short spelling of PARTIAL_SUCCESS in a STATUS narrowing test — IF s IS PARTIAL reads as IF s IS PARTIAL_SUCCESS.
VALIDA language mechanism usually acting as a guard on a reference or shared mutual reference to test if the object pointed to is valid.

Logical and boolean literals

KeywordDescription
ANDA language feature for evaluating a boolean AND expression.
ORA language feature for evaluating a boolean OR expression.
NOTA language feature for evaluating a boolean NOT expression.
XORA language feature for evaluating a boolean exclusive-OR expression.
TRUEA boolean value.
FALSEA boolean value.
EMPTYA possible value for a WEAK REFERENCE when it contains no value.
NONEThe absence spelling that survives beside EMPTY. A MATCH absence arm accepts either, and the legacy IS NONE reads as IS NOT VALID; the canonical absence model remains bare-type EMPTY.

Bitwise and shift (keyword form — no C-style operator symbols)

KeywordDescription
BANDA language feature for bitwise AND operation.
BORA language feature for bitwise OR operation.
BXORA language feature for bitwise exclusive OR operation.
BNOTA language feature for bitwise NOT operation.
LSHIFTA language feature for bitwise shift left; number following the number of bits to shift.
RSHIFTA language feature for bitwise shift right; number following the number of bits to shift; the logical form and fills with zero.
ASHIFTThe arithmetic right shift, which fills the vacated high bits with the sign bit so a negative value stays negative — value ASHIFT 4.
LROTATEA language feature for bitwise rotate left; number following the number of bits to move.
RROTATEA language feature for bitwise rotate right; number following the number of bits to move.

Bit-pattern equality

KeywordDescription
BEQUALSA comparison that tests two values for an identical bit pattern rather than an equal value, which is how NaN BEQUALS NaN is true and 0.0 BEQUALS -0.0 is false. Ordinary == compares values and answers the opposite in both cases.
BNEQUALSThe negation of BEQUALS, true when two bit patterns differ.

Concurrency

KeywordDescription
SYNCHRONIZEDA specialized label for a block so that only one thread at a time is able to execute that block.
ATTACHEDReserved for future use.
CONCURRENTA special label for a block that could execute multiple threads concurrently.
DETACHEDReserved for future use.
LONG_LIVEDReserved for future use.
PARALLELA specialized label for a block that assumes it will run multiple threads in parallel over the following block.

Conversion operators (I.D.viii)

KeywordDescription
CONVERSIONSA specialized type of NAMESPACE reserved exclusively for type conversions.
OPERATORA language mechanism that allows for user-defined operations, like ">>" or whatever.
ASA language mechanism for converting between types; note AS is lossy.
INTOA language mechanism for converting between types; note INTO is lossless.
FROMUsed in conversions.

Reserved-only (claimed, no V1 semantics — using one is an error, E1163)

KeywordDescription
NO_RETURNReserved for future use.
FREEZEReserved for future use.
POISONReserved for future use.
FENCEReserved for future use.
SECRETReserved for future use.
ENCRYPTEDReserved for future use.
TEMPORARYReserved for future use.
DIRTYReserved for future use.
PUBLICReserved for future use.
FEATUREReserved for future use.
UNREACHABLEReserved for compiler error catching reminding the dev to use UNREACHABLE!
THROWReserved for compiler error catching reminding the dev to use PANIC.
CATCHReserved for compiler error catching reminding the dev to use RECOVER.