
Security News
GitHub Actions Adds cache-mode to Limit Cache Poisoning Risk
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.
acp-client
Advanced tools
Standalone TypeScript helpers for connecting host applications to Agent Client Protocol agents.
acp-clientStandalone TypeScript helpers for connecting host applications to Agent Client Protocol agents.
Use this package when you want to launch an ACP agent from a registry id or inline distribution manifest, connect over stdio, and work with a small typed client instead of wiring JSON-RPC streams by hand.
acp-client is a good fit for:
codex-acp.It is not a good fit when you need:
zod v3.25 or v4.AcpAdapterId improves autocomplete for
bundled ids while still accepting custom or newly published ids.The package deliberately stays close to ACP protocol shapes. You get a typed connection/session layer, registry launch support, and optional Node host callbacks, but application policy and user experience remain host-owned.
npm install acp-client zod
This example proves the primary value path: resolve a known registry adapter, launch it over stdio, create a session, send a prompt, and close the managed process.
import { createNodeAcpClient } from "acp-client/node"
const client = await createNodeAcpClient({
agent: "codex-acp",
cwd: process.cwd(),
clientInfo: {
name: "example-client",
version: "1.0.0",
},
handler: {
async requestPermission() {
return { outcome: { outcome: "cancelled" } }
},
async sessionUpdate({ params }) {
console.log(params)
},
},
})
try {
const session = await client.newSession({
cwd: process.cwd(),
mcpServers: [],
})
await session.prompt("Hello from ACP")
} finally {
await client.close()
}
Use acp-client for runtime-neutral client/session helpers, transport
primitives, adapter metadata, and Zod schemas:
import {
createAcpClient,
knownAcpAdapterIds,
type AcpAdapterId,
type AgentDistribution,
} from "acp-client"
Use acp-client/node from Node runtimes that need to launch agents, synchronize
the ACP registry cache, manage local installs, or provide filesystem/terminal
callbacks:
import {
createAcpRegistryService,
createNodeAcpClient,
ensureAgentInstalled,
} from "acp-client/node"
Use acp-client/protocol for curated ACP SDK protocol constants, request
errors, NDJSON framing, and protocol types without higher-level client helpers:
import {
PROTOCOL_VERSION,
RequestError,
methods,
type SessionNotification,
} from "acp-client/protocol"
Use AcpAdapterId when downstream SDKs should autocomplete bundled registry ids
while still accepting custom registry entries:
import {
knownAcpAdapterIds,
type AcpAdapterId,
type AgentDistribution,
} from "acp-client"
export const defaultAgent = knownAcpAdapterIds[0]
export type AgentInput = AcpAdapterId | AgentDistribution
knownAcpAdapterIds is generated from the bundled ACP registry fallback. Full
catalog reads go through createAcpRegistryService() from acp-client/node;
registry-backed catalog entries include display metadata such as website, icon,
source, unofficial status, and GitHub star count when available.
Managed install APIs are available from acp-client/node for hosts that want to
preinstall agents before launch, run deterministic updates, and read persisted
install status without maintaining parallel metadata:
import {
ensureAgentInstalled,
getInstalledAgent,
resolveInstalledAgentProcessSpec,
updateAgent,
} from "acp-client/node"
await updateAgent(agentDistribution, { cacheDir })
const status = await getInstalledAgent(agentDistribution.id, { cacheDir })
const processSpec = await resolveInstalledAgentProcessSpec(agentDistribution, {
cacheDir,
installIfMissing: true,
maxInstalledAgeMs: 24 * 60 * 60 * 1000,
})
This project is licensed under the MIT License.
FAQs
Standalone TypeScript helpers for connecting host applications to Agent Client Protocol agents.
The npm package acp-client receives a total of 3 weekly downloads. As such, acp-client popularity was classified as not popular.
We found that acp-client demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.

Company News
Allow myself to introduce... myself.

Research
/Security News
A Twitch browser extension on Chrome and Firefox forwards users’ live OAuth session tokens through proxies controlled by a Russian bot service.