## What does this PR do? Adds the CopilotKit consumer side of ENT-1173 across Shared, Runtime, Core, Web Inspector, and the existing Shell Docs pages. - Defines and parses optional trusted Inspector metadata for identity, plan, license, action, usage, and expiry. Runtime proxies it through a private, failure-isolated route, and Core refreshes it without changing connection state. - Groups Inspector navigation into Threads, Agents, and Learning. Threads renders finite, unlimited, unknown, overage, and expiring usage states plus matching trusted plan or license actions. - Keeps explicit `threadEndpoints` as the only authority for Thread requests. Locked or absent capability states make no list, subscription, detail, message, event, or state calls. - Keeps the zero-thread video, three example Threads, detail tabs, and guided tour in empty and locked states. General Intelligence remains the default onboarding path; only trusted `team_self_hosted` metadata uses self-hosted onboarding. - Gives an active license with missing Runtime routes a short **Finish setting up Rich Threads** state. Users can copy a safe coding-agent prompt or open the public Runtime setup guide. The same copy control appears in that guide, and raw Markdown/LLM views include the full prompt. - Keeps finite usage green below 90%, orange from 90% to the limit, and red at or above the limit. At 90%, a trusted plan action changes from **Manage Your Plan** to a purple **Upgrade Your Plan** without changing its trusted URL, action kind, or telemetry contract. - Adds a deterministic 33-state loopback lab for CopilotKit developers. It has no production route or export, is absent from public docs and package metadata, and is excluded from the npm tarball. `Expiring Soon` is display-only; this PR does not enable the thread culler. Managed Enterprise receives no manage-plan action, and Team Self-Hosted receives no hosted plan action. Optional metadata and the additive expiry field remain compatible across mixed producer, Runtime, Core, and Inspector versions. A small Channels test-only change updates fetch mocks for current TypeScript types. It changes no Slack or Teams docs or runtime behavior. ## Related PRs and issues - Refs [ENT-1173](https://linear.app/copilotkit/issue/ENT-1173/ship-plg-ready-inspector-navigation-metadata-and-locked-threads) - Producer: [CopilotKit/Intelligence#696](https://github.com/CopilotKit/Intelligence/pull/696) ## Validation - `@copilotkit/web-inspector`: 20 files and 372 tests passed; typecheck and production build passed. - Shell Docs: 57 files and 383 tests passed; lint, typecheck, and production build passed. The build generated all 222 static pages. - Browser checks cover the copy-prompt flow, unchanged white **Manage Your Plan**, purple **Upgrade Your Plan**, orange 4,500/5,000 usage, and red 5,000/5,000 usage. - Independent review found no Critical or Important issues. - The broader Runtime, React Native, Channels, package-quality, compatibility, and Node-version checks from the prior pushed head remain green. ## Checklist - [x] I have read the [Contribution Guide](https://github.com/copilotkit/copilotkit/blob/master/CONTRIBUTING.md) - [x] I updated the relevant documentation - [ ] "Allow edits by maintainers" is checked
CopilotKit - Runtime
✨ Why CopilotKit?
- Minutes to integrate - Get started quickly with our CLI
- Framework agnostic - Works with React, Next.js, AGUI and more
- Production-ready UI - Use customizable components or build with headless UI
- Built-in security - Prompt injection protection
- Open source - Full transparency and community-driven
🧑💻 Real life use cases
Deploy deeply-integrated AI assistants & agents that work alongside your users inside your applications.
🏆 Featured Examples
Trusted Inspector metadata
An Intelligence-backed v2 runtime can proxy trusted project and license context
to the Inspector. The runtime advertises this support with
inspectorMetadata: true in its runtime-info response.
| Runtime mode | Request |
|---|---|
| Multi-route | GET {basePath}/inspector-metadata |
| Single-route | POST {basePath} with { "method": "inspector/metadata" } |
A valid response is a sanitized InspectorMetadataV1 JSON object with
Cache-Control: no-store, private. Missing data, an unsupported schema, a
non-Intelligence runtime, or a provider failure returns 204 with the same
cache policy. This optional request never changes the main runtime connection
state. The upstream Intelligence request has a five-second deadline; a timeout
uses the same private 204 path.
Runtime keeps schemaVersion: 1 and returns the object normalized by Shared.
Older producers may omit usage.expiringSoonCount, and 0 stays a known zero.
If this optional leaf is malformed, Shared removes only the leaf and keeps valid
base usage and sibling modules. Runtime does not calculate or cache expiry, and
older consumers ignore the additive leaf.
The Intelligence request uses the API key configured on the server-side
CopilotKitIntelligence client. The proxy does not forward browser headers or
cookies to Intelligence, and it does not expose provider error bodies to the
browser. Browser headers and configured fetch credentials still apply between
@copilotkit/core and your Copilot Runtime, so you can protect the runtime route
with your normal app auth.
Deploy the Intelligence producer before releasing a runtime that advertises the
capability. New runtimes treat a 404 from an older Intelligence App API as
compatible absence and return 204 to the client.
Documentation
To get started with CopilotKit, please check out the documentation.
Intelligence identity and Memory
An Intelligence Runtime supports web only, Channels only, or both. Web routes
need identifyUser(request). Each Channel has its own identifyUser policy in
createChannel. A Channels-only Runtime omits the web callback and exposes no
functional web routes.
const runtime = new CopilotRuntime({
agents,
intelligence,
identifyUser: authenticateApplicationUser,
channels: [supportChannel],
memory: {
access: async ({ request, user, consumer }) => {
const role = await roleFor(request, user);
if (role === "blocked") return null;
return consumer === "client"
? { user: "read", project: "none" }
: { user: "read-write", project: "read" };
},
},
});
The callback runs once per web request. Its user owns ordinary web Threads and
is reused for agent and browser Memory policy. Adding memory exposes the
browser Memory routes and agent tools under the same policy. A denial returns
403; a policy error fails the request. Omitting memory hides the browser
routes and does not attach Memory tools.
exposeMemoryRoutes and
CopilotKitIntelligence({ enableEnterpriseLearning: true }) remain for one
compatibility window. New code should use memory.access.
Analytics & Privacy
CopilotKit uses Scarf for anonymous usage analytics to help improve the product. Scarf handles all privacy compliance and does not store raw IP addresses. This helps us understand how CopilotKit is being used and prioritize improvements.
Opting Out
To disable analytics, set the environment variable:
export COPILOTKIT_TELEMETRY_DISABLED=true
Or use the DO_NOT_TRACK standard:
export DO_NOT_TRACK=1