npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@cordierite/react-native

v0.3.1

Published

Expo native client for Cordierite sessions

Downloads

311

Readme

Cordierite

Tools and state from outside the app—without debug menus

MIT license npm downloads PRs Welcome

This package is the native client for Cordierite. Your app registers tools in JavaScript; developers, testers, and agents invoke them from a CLI or host after the app opens a bootstrap link and completes a pinned wss:// handshake. You get production-grade transport (TLS + SPKI) instead of burying debug-only screens in the UI to flip state or trigger flows.

Why use it

  • No in-app debug chrome: influence screens, flags, fixtures, and flows from the host, not from hidden menus shipped to users.
  • Same path for people and automation: CLI for devs/QA, agents for scripted or LLM-driven control—both use tool calls after session claim.
  • Production-capable: ship the client in real builds when your pins and operational model say it is acceptable; connectivity still requires a trusted host, not public anonymous access.

Security highlights

  • TLS required for the Cordierite socket; pins are SHA-256 over SPKI (sha256/...) so only your host keys match.
  • Optional allowPrivateLanOnly: when enabled, bootstrap must target a local IPv4 address (RFC1918 private ranges or 127.0.0.1)—a dev-hardening switch, not a claim that Cordierite is LAN-only.

Getting started

[!NOTE] Use a development build or bare native app. Expo Go is not enough—this library ships native code and pinning configuration.

Install with your package manager (npm, yarn, pnpm, …). Add the @cordierite/react-native config plugin to Expo config with cliPins (required) and optionally allowPrivateLanOnly; then run your usual prebuild so plist and manifest receive the values. For bare React Native, autolink the module and set the equivalent native keys—field names and semantics mirror the plugin (see app.plugin.js).

Generate a matching host key and pin with:

cordierite keygen

Use the printed fingerprint value verbatim in cliPins.

Bare React Native — native keys

iOS Info.plist:

| Key | Purpose | | --- | ------- | | CordieriteCliPins | String array of sha256/... SPKI pins | | CordieriteAllowPrivateLanOnly | Boolean; if true, bootstrap host must be a local IPv4 address |

Android <application> meta-data:

| Name | Purpose | | --- | ------- | | com.callstackincubator.cordierite.CLI_PINS | JSON array string of pin values | | com.callstackincubator.cordierite.ALLOW_PRIVATE_LAN_ONLY | "true" / "false" |

Empty or missing pins fail at configuration time. Wire deep links so the OS can open your app with the host’s bootstrap URL.

Bootstrap connection: importing this package registers React Native Linking listeners that watch for URLs with a cordierite query parameter, parse the binary v1 payload, and call connect when the client is idle. You do not need your own Linking handler for the default flow.

Errors: use addCordieriteErrorListener if you want callbacks when bootstrap parsing or that automatic connect fails.

Tools: call registerTool({ ... }) with Standard Schema compatible inputSchema and outputSchema values plus a handler so the host can invoke your tools after the session is active. zod v4 works well here and is used in the playground example.

import { registerTool } from "@cordierite/react-native";
import { z } from "zod";

registerTool(
  {
    name: "sum",
    description: "Add two numeric values",
    inputSchema: z.object({
      a: z.number(),
      b: z.number(),
    }),
    outputSchema: z.object({
      total: z.number(),
    }),
    handler: async ({ a, b }) => ({
      total: a + b,
    }),
  },
);

Platform compatibility

| Platform | Support | | --- | --- | | iOS | 15.1+ (Cordierite.podspec), New Architecture | | Android | Autolinked, New Architecture | | Web | Stub only |

Made with ❤️ at Callstack

cordierite is an open source project and will always remain free to use. If you think it's cool, please star it 🌟. Callstack is a group of React and React Native geeks, contact us at [email protected] if you need any help with these or just want to say hi!

Like the project? ⚛️ Join the team who does amazing stuff for clients and drives React Native Open Source! 🔥