npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@copilotkit/runtime

v1.69.0

Published

<img src="https://github.com/user-attachments/assets/0a6b64d9-e193-4940-a3f6-60334ac34084" alt="banner" style="border-radius: 12px; border: 2px solid #d6d4fa;" />

Readme

CopilotKit - Runtime

✨ Why CopilotKit?

  • Minutes to integrate - Get started quickly with our CLI
  • Framework agnostic - Works with React, Next.js, AGUI and more
  • Production-ready UI - Use customizable components or build with headless UI
  • Built-in security - Prompt injection protection
  • Open source - Full transparency and community-driven

🧑‍💻 Real life use cases

Deploy deeply-integrated AI assistants & agents that work alongside your users inside your applications.

🏆 Featured Examples

Trusted Inspector metadata

An Intelligence-backed v2 runtime can proxy trusted project and license context to the Inspector. The runtime advertises this support with inspectorMetadata: true in its runtime-info response.

| Runtime mode | Request | | ------------ | ----------------------------------------------------------- | | Multi-route | GET {basePath}/inspector-metadata | | Single-route | POST {basePath} with { "method": "inspector/metadata" } |

A valid response is a sanitized InspectorMetadataV1 JSON object with Cache-Control: no-store, private. Missing data, an unsupported schema, a non-Intelligence runtime, or a provider failure returns 204 with the same cache policy. This optional request never changes the main runtime connection state. The upstream Intelligence request has a five-second deadline; a timeout uses the same private 204 path.

Runtime keeps schemaVersion: 1 and returns the object normalized by Shared. Older producers may omit usage.expiringSoonCount, and 0 stays a known zero. If this optional leaf is malformed, Shared removes only the leaf and keeps valid base usage and sibling modules. Runtime does not calculate or cache expiry, and older consumers ignore the additive leaf.

The Intelligence request uses the API key configured on the server-side CopilotKitIntelligence client. The proxy does not forward browser headers or cookies to Intelligence, and it does not expose provider error bodies to the browser. Browser headers and configured fetch credentials still apply between @copilotkit/core and your Copilot Runtime, so you can protect the runtime route with your normal app auth.

Deploy the Intelligence producer before releasing a runtime that advertises the capability. New runtimes treat a 404 from an older Intelligence App API as compatible absence and return 204 to the client.

Documentation

To get started with CopilotKit, please check out the documentation.

Intelligence identity and Memory

An Intelligence Runtime supports web only, Channels only, or both. Web routes need identifyUser(request). Each Channel has its own identifyUser policy in createChannel. A Channels-only Runtime omits the web callback and exposes no functional web routes.

const runtime = new CopilotRuntime({
  agents,
  intelligence,
  identifyUser: authenticateApplicationUser,
  channels: [supportChannel],
  memory: {
    access: async ({ request, user, consumer }) => {
      const role = await roleFor(request, user);
      if (role === "blocked") return null;
      return consumer === "client"
        ? { user: "read", project: "none" }
        : { user: "read-write", project: "read" };
    },
  },
});

The callback runs once per web request. Its user owns ordinary web Threads and is reused for agent and browser Memory policy. Adding memory exposes the browser Memory routes and agent tools under the same policy. A denial returns 403; a policy error fails the request. Omitting memory hides the browser routes and does not attach Memory tools.

exposeMemoryRoutes and CopilotKitIntelligence({ enableEnterpriseLearning: true }) remain for one compatibility window. New code should use memory.access.

Analytics & Privacy

CopilotKit uses Scarf for anonymous usage analytics to help improve the product. Scarf handles all privacy compliance and does not store raw IP addresses. This helps us understand how CopilotKit is being used and prioritize improvements.

Opting Out

To disable analytics, set the environment variable:

export COPILOTKIT_TELEMETRY_DISABLED=true

Or use the DO_NOT_TRACK standard:

export DO_NOT_TRACK=1