@reticlehq/core is the shared wire contract at the bottom of Reticle’s dependency graph. Every message that crosses a boundary, browser to bridge, bridge to agent, is defined here as a named constant plus a zod schema. You almost certainly do not need to install it: it arrives with whatever Reticle package you did install, and you only reach for it directly if you are building your own integration against the wire format.
Apache 2.0. Depends on zod and on open-verification, the protocol whose vocabulary the contract is written in.
Why it exists
Without one shared definition the browser and the server drift. One side renames a field, the other keeps reading the old one, and the failure is silent: a verdict that quietly stops carrying its evidence. Core makes that a type error instead. The narrow dependency list is the point.open-verification itself depends on zod alone, so the graph stays acyclic: everything can depend on core, and nothing core does can drag a filesystem call into the browser bundle. This page said “depends on zod and nothing else” until v3 extracted the protocol and nobody updated the sentence.
Do you install it?
No. It arrives as a dependency of@reticlehq/browser, @reticlehq/react, @reticlehq/server, @reticlehq/vite-plugin or @reticlehq/electron. Install it directly only if you are building your own integration against the wire format.
Exports map
What the barrel exports
src/index.ts is a pure barrel: a stack of export * re-exports plus one named export. Grouped by what they are for, and not exhaustive:
Wire constants
RETICLE_DEFAULT_PORT (4400), RETICLE_WS_PATH (/reticle), MCP_SSE_PATH, MCP_MESSAGE_PATH, STATUS_PATH, RETICLE_PROTOCOL_VERSION (1), RETICLE_URL_PARAM, LOOPBACK_HOST (127.0.0.1), TRANSPORT_LIMITS, REDACTED_VALUE, RING_BUFFER_DEFAULTS, DEFAULT_ASSERT_TIMEOUT_MS (4000), VISUAL_PIXEL_THRESHOLD (0.1), SCROLL_FIND_DEFAULTS, CRAWL_DEFAULTS.
Environment and directories
ReticleEnv names every environment variable Reticle reads: RETICLE_TOKEN, RETICLE_HOST, RETICLE_ALLOWED_ORIGINS, RETICLE_PORT, RETICLE_STATE_DIR, RETICLE_CDP_URL, RETICLE_MAX_CONTEXTS, RETICLE_MAX_MESSAGES_PER_SECOND and the rest. ReticleDir names the paths under .reticle/.
Enum-like frozen objects
EventType, ActionType, ElementState, QueryBy, MessageKind, ReticleCommand, PhenomenonType, SettleReason, ComponentStateReason, InputMode, InputModeReason, ActionWarning, DriveErrorCode, TruncationChannel, EventAttribution, PerfMetric, PresenterMode, SnapshotMode, VisualReason, CONSOLE_LEVELS, Verified.
ComponentStateResult is an interface, not one of these: it is a type-only export, so importing it as a value fails with 'ComponentStateResult' only refers to a type, but is being used as a value here.
Zod schemas
ReticleMessageSchema (a discriminated union on kind) and its members HelloMessageSchema, CommandMessageSchema, CommandResultSchema, EventMessageSchema, plus ReticleEventSchema. Flows are FlowStepSchema, FlowExpectSchema, FlowAnchorSchema, FlowFileSchema, RecordedFlowSchema. CI runs are ReticleVerificationRunSchema, RunVerdictSchema, RunFlowResultSchema, RunCheckSchema, RunRiskSchema, RepairPacketSchema, VerificationEvidenceSchema. Telemetry is TelemetryEventSchema, SessionSummarySchema, ProjectProfileSchema, FeedbackSchema, IdentitySchema.
Kernel functions
Pure, isomorphic, and safe on both sides of the wire:The desktop contract
The JSON schemas
Seven files, generated at build from the zod definitions:reticle-message.json, reticle-event.json, hello-message.json, command-message.json, command-result.json, event-message.json, event-type.json.
How the pieces fit
Where the contract sits between the SDK, the bridge, and the agent.