
Security News
pnpm 12’s Rust Rewrite Cuts Install Times by Up to 90%
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.
@copilotkit/core
Advanced tools
@copilotkit/core is the framework-neutral client for CopilotKit runtimes. It
manages runtime agents, frontend tools, shared context, suggestions, thread
stores, and subscriptions.
When the connected runtime reports inspectorMetadata: true in its runtime-info
response, Core loads the optional InspectorMetadataV1 value in the background.
The runtime connection and agent notifications finish first, so a slow or
unavailable metadata route cannot delay the app.
Core exposes the object returned by Shared normalization unchanged through the
getter and subscriber event. Older runtimes may omit
usage.expiringSoonCount; that absence remains valid V1 usage. A value of 0
means known zero and stays different from absence. Shared omits a malformed
expiry leaf without removing valid used, limit, or sibling modules. Core
does not calculate or rebuild expiry and does not require a V2 schema.
Read the latest value with inspectorMetadata, refresh it without reconnecting,
or subscribe to changes:
import { CopilotKitCore } from "@copilotkit/core";
const copilotkit = new CopilotKitCore({
runtimeUrl: "/api/copilotkit",
headers: { Authorization: "Bearer app-session" },
credentials: "include",
});
const subscription = copilotkit.subscribe({
onInspectorMetadataChanged: ({ inspectorMetadata }) => {
console.log(inspectorMetadata);
},
});
await copilotkit.refreshInspectorMetadata();
console.log(copilotkit.inspectorMetadata);
subscription.unsubscribe();
Core sends the current headers and fetch credentials to the Copilot Runtime. A
call to setHeaders() or setCredentials() clears the prior value before it
starts a new metadata refresh, so trusted context cannot cross an auth-context
change. Changing the runtime URL or transport, losing the capability, or
disconnecting also clears the value.
Each refresh cancels the prior request and has a five-second deadline. Core also checks the runtime URL, requested and resolved transport, headers, credentials, connection, and capability before publishing a response. A stale success or failure cannot replace metadata from a newer connection. Route, timeout, parse, and subscriber failures stay isolated from the runtime connection.
See the
CopilotKitCore reference
and
CopilotKitCoreSubscriber reference
for the full API.
FAQs
Core web utilities for CopilotKit2
The npm package @copilotkit/core receives a total of 316,527 weekly downloads. As such, @copilotkit/core popularity was classified as popular.
We found that @copilotkit/core demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.

Security News
Socket CTO Ahmad Nassri joins AppSec leaders at Black Hat to discuss active malware, package manager risks, and software supply chain defense.

Research
/Security News
Thirteen malicious Packagist themes expose visitors on unpatched iPhones to a WebKit-to-kernel exploit chain that steals device data and wallet seeds.