Skip to main content
@reticlehq/core is the shared wire contract at the bottom of Reticle’s dependency graph. Every message that crosses a boundary, browser to bridge, bridge to agent, is defined here as a named constant plus a zod schema. You almost certainly do not need to install it: it arrives with whatever Reticle package you did install, and you only reach for it directly if you are building your own integration against the wire format. Apache 2.0. Depends on zod and on open-verification, the protocol whose vocabulary the contract is written in.

Why it exists

Without one shared definition the browser and the server drift. One side renames a field, the other keeps reading the old one, and the failure is silent: a verdict that quietly stops carrying its evidence. Core makes that a type error instead. The narrow dependency list is the point. open-verification itself depends on zod alone, so the graph stays acyclic: everything can depend on core, and nothing core does can drag a filesystem call into the browser bundle. This page said “depends on zod and nothing else” until v3 extracted the protocol and nobody updated the sentence.

Do you install it?

No. It arrives as a dependency of @reticlehq/browser, @reticlehq/react, @reticlehq/server, @reticlehq/vite-plugin or @reticlehq/electron. Install it directly only if you are building your own integration against the wire format.

Exports map

There is no @reticlehq/core/vite subpath. It was documented in an old README and never existed in the exports map. The Vite plugin is @reticlehq/vite-plugin.

What the barrel exports

src/index.ts is a pure barrel: a stack of export * re-exports plus one named export. Grouped by what they are for, and not exhaustive:

Wire constants

RETICLE_DEFAULT_PORT (4400), RETICLE_WS_PATH (/reticle), MCP_SSE_PATH, MCP_MESSAGE_PATH, STATUS_PATH, RETICLE_PROTOCOL_VERSION (1), RETICLE_URL_PARAM, LOOPBACK_HOST (127.0.0.1), TRANSPORT_LIMITS, REDACTED_VALUE, RING_BUFFER_DEFAULTS, DEFAULT_ASSERT_TIMEOUT_MS (4000), VISUAL_PIXEL_THRESHOLD (0.1), SCROLL_FIND_DEFAULTS, CRAWL_DEFAULTS.

Environment and directories

ReticleEnv names every environment variable Reticle reads: RETICLE_TOKEN, RETICLE_HOST, RETICLE_ALLOWED_ORIGINS, RETICLE_PORT, RETICLE_STATE_DIR, RETICLE_CDP_URL, RETICLE_MAX_CONTEXTS, RETICLE_MAX_MESSAGES_PER_SECOND and the rest. ReticleDir names the paths under .reticle/.

Enum-like frozen objects

EventType, ActionType, ElementState, QueryBy, MessageKind, ReticleCommand, PhenomenonType, SettleReason, ComponentStateReason, InputMode, InputModeReason, ActionWarning, DriveErrorCode, TruncationChannel, EventAttribution, PerfMetric, PresenterMode, SnapshotMode, VisualReason, CONSOLE_LEVELS, Verified. ComponentStateResult is an interface, not one of these: it is a type-only export, so importing it as a value fails with 'ComponentStateResult' only refers to a type, but is being used as a value here.

Zod schemas

ReticleMessageSchema (a discriminated union on kind) and its members HelloMessageSchema, CommandMessageSchema, CommandResultSchema, EventMessageSchema, plus ReticleEventSchema. Flows are FlowStepSchema, FlowExpectSchema, FlowAnchorSchema, FlowFileSchema, RecordedFlowSchema. CI runs are ReticleVerificationRunSchema, RunVerdictSchema, RunFlowResultSchema, RunCheckSchema, RunRiskSchema, RepairPacketSchema, VerificationEvidenceSchema. Telemetry is TelemetryEventSchema, SessionSummarySchema, ProjectProfileSchema, FeedbackSchema, IdentitySchema.

Kernel functions

Pure, isomorphic, and safe on both sides of the wire:

The desktop contract

Six strings shared by the Electron preload and the Tauri crate, in CommonJS because a preload script is required before any ESM transform:
The subpath exports those six constants individually and nothing else. The DESKTOP_CONTRACT record they are collected into exists on the ESM side only, so importing it here fails with Module '"@reticlehq/core/desktop-contract"' has no exported member 'DESKTOP_CONTRACT'. Import DESKTOP_CONTRACT from @reticlehq/core instead.

The JSON schemas

Seven files, generated at build from the zod definitions: reticle-message.json, reticle-event.json, hello-message.json, command-message.json, command-result.json, event-message.json, event-type.json.

How the pieces fit

Where the contract sits between the SDK, the bridge, and the agent.
Last modified on September 18, 2026