Native SDK (formerly Zero Native)
Vercel Labs' pre-1.0 native application toolkit: declarative
.nativemarkup, TypeScript or Zig state logic, a native renderer, deterministic record/replay, accessibility snapshots, and an agent automation server.
Repo: vercel-labs/native. Site: native-sdk.dev. The old repository URL redirects to the current project; retain “Zero Native” as a historical search alias, not as the current install or architecture authority.
Routing Summary
| Need | Route | Boundary |
|---|---|---|
| An installable experience that does not require native APIs | PWA | Keep the distribution and security model web-first |
| A new native desktop app with deterministic state, agent automation, and project-owned UI | Native SDK, candidate | Pre-1.0; desktop is maturest and mobile remains experimental. Prove the exact platform, widgets, accessibility, packaging, and replay behavior. |
| A shell around an existing web application | PWA or a mature reviewed webview shell | Native SDK's current primary path is native markup/rendering, not the old Zero Native webview-first promise. |
| An Android-only, on-device APK/AAB experiment over an owned test site | WebToApp, guarded | Isolated test device only; disable unnecessary permissions, injection, extensions, MITM, runtimes, and repackaging |
| The Kevin Wiki viewer | Existing web deployment | Do not add a native shell without a product requirement and measured benefit |
Current Source Snapshot
At the latest pinned 2026-08-12 review, the canonical GitHub identity is
vercel-labs/native at ed84e35975cc58515336843c07b153a54b499d58, release
and npm CLI 0.8.4, Apache-2.0, with a non-truncated 1,670-blob tree, 81
detected test files, three workflows, and seven agent-skill files. The project
is explicitly pre-1.0. Current source evidence replaces the old
zero-native@0.3.0 snapshot for adoption decisions. Source: commit-pinned
repository receipt and release/package metadata, 2026-08-12
Architecture
| Layer | Detail |
|---|---|
| View | Declarative .native markup compiled into the executable |
| State | Model/message/update loop in TypeScript compiled to native code, or Zig |
| Renderer | SDK engine draws into real OS windows; no browser, WebView, or JS runtime in the primary release binary |
| Agent surface | Accessibility snapshots, widget driving, assertions, deterministic screenshots, record/replay, and bundled skills |
| Platforms | macOS primary; Linux and Windows exercised; iOS/Android experimental |
Code and drag surfaces
The saved <code /> announcement maps to a real example and test surface, not
only a screenshot. The pinned examples/code-editor implements a bounded
filesystem tree, binary/oversize states, typed tree semantics, keyboard
navigation, preview versus pinned tabs, async stale-read rejection, line
numbers, no-wrap scrolling, and extension-derived syntax highlighting. Its
tests build both compiled and interpreted markup, exercise real temporary
directories, and verify tree caps and generated-directory exclusions. This is
useful evidence for native developer tools; the 25-language marketing count
still requires an exact language registry and representative script/font/IME
test before becoming a product promise.
The saved drag-and-drop announcement also resolves to an explicit model-owned
contract. At the pinned revision, on-drag carries a numeric source identity,
phase (change, end, cancel encoded as 0–2), floating view-local geometry,
and stable global-key identity. The Kanban example keeps committed order
unchanged during motion, uses one reserved insertion slot, commits only on end,
cancels on Escape/pointer cancellation, animates displaced keyed neighbors, and
snaps under reduced motion. Source tests reject malformed payload shapes and
exercise pointer capture and drop targets. A drag demo therefore becomes a
candidate only after keyboard/assistive alternatives, touch, cancellation,
off-view geometry, reduced motion, model replay, and platform behavior pass in
the target app. Source: Native SDK docs, examples, and tests at ed84e359,
reviewed 2026-08-12
Launch: @ctatedev (also Browser Testing Skills, JSON Render -- Generative UI Framework author) — 3,889 likes, 3,559 bookmarks. Source: X/@ctatedev, 2026-05-09
vs Electron / Tauri
| Approach | Tradeoff |
|---|---|
| Electron | Mature; heavy RAM/binary |
| Tauri | Rust shell; webview |
| Native SDK | Native markup/rendering plus TypeScript/Zig state; deterministic automation; pre-1.0 and platform-maturity caveats |
| WebToApp | Android-only on-device APK workshop with runtimes, signing, extensions, network modification, and correspondingly broad authority |
Guarded Android Workshop: WebToApp
WebToApp is not merely a URL wrapper. It can package remote sites, static frontends, local Node/PHP/Python/Go servers, WordPress, media, and multiple sites; generate and sign APK/AAB files; inject permissions; run user scripts and MV3 extensions; install runtime binaries; and automate the builder through an on-device agent. That makes it a useful Android prototyping and packaging reference when a phone-only build is a real requirement. Source: WebToApp README and source, reviewed 2026-08-10
It is also a high-authority application. The reviewed host manifest requests network, media, package-install, camera, microphone, location, Wi-Fi, Bluetooth, biometric, overlay, battery-optimization, notification-policy, foreground service, wake-lock, boot, and alarm permissions. Cleartext traffic is enabled; the product can run a local TLS MITM bridge, bypass CORS, spoof TLS fingerprints, load community modules and Chrome extensions, inject JavaScript, execute local runtimes, clone/re-sign applications, and alter generated permissions. These are capabilities, not proof of maliciousness, but they exclude it from the default developer workstation and production route.
Current snapshot: shiaho777/web-to-app at
87f9510243d0cb188b2d6ac2693b01df649080b9, release v2.4.3, Unlicense,
5,554 stars, and 795 forks; the upstream check job passed on the reviewed
revision. Evaluate only on an isolated Android test device and an owned test
site. Keep extensions, userscripts, MITM, CORS bypass, runtime downloads,
repackaging, and unnecessary permissions off. Inspect the generated manifest,
network behavior, signing key custody, third-party content rights, Play policy,
Data Safety declaration, and final APK before distribution. Prefer a PWA,
mature reviewed webview shell, or Native SDK when one of those
narrower routes meets the product need.
Stack fit (Kevin)
- New desktop control surface — evaluate when deterministic native state, accessibility snapshots, replay, and agent-driven UI testing are product requirements. Do not use it merely to wrap an existing website.
- Agent Machines local tray app — candidate only if the current native component/platform surface fits; an existing web dashboard needs a different shell decision.
- Not for kevin-wiki viewer — wiki stays web-first on Vercel.
- No standalone skill yet — use this as a tool reference when a task explicitly needs native rendering, deterministic replay, automation, or TypeScript/Zig state; ordinary frontend work stays on the Next/Vercel route.
- Evaluate mobile maturity before Cathy-style personal apps ship to App Store.
Timeline
- 2026-08-12 | Refreshed Native SDK to
ed84e359/0.8.4and followed the code-editor and drag-and-drop posts into the exact docs, examples, and tests. Added bounded filesystem/editor behavior plus model-owned drag identity/phases, cancellation, insertion, reduced-motion, accessibility, and target-platform proof. Kept the wiki web-first. Source: X/@ctatedev2083373227674345677and2086244792917270924; pinned source - 2026-08-12 | Corrected the current project identity and architecture:
vercel-labs/zero-nativenow resolves to Native SDK, whose primary route is native.nativemarkup/rendering plus TypeScript or Zig state—not the old webview-shell design. Recorded commit833e79e, pre-1.0 status, deterministic automation/replay, and desktop-versus-mobile maturity boundary. Source:vercel-labs/nativecommit-pinned receipt - 2026-05-09 | Launch thread — Zig native + web UI, 5 platforms. Source: X/@ctatedev, 2026-05-09
- 2026-05-11 | Wiki page from Kevin capture. Source: User, 2026-05-11
- 2026-06-13 | Quality remediation: architecture table, Electron comparison, Agent Machines lens. Source: zero-native.dev, 2026-06-13
- 2026-06-30 | Deep-reviewed the local launch screenshot and current source state; recorded
v0.3.0, main HEAD, npm package, license, and the decision to keep this as a tool route rather than a default executable skill. Source: X bookmark artifact audit, 2026-06-30 - 2026-08-10 | Added WebToApp as a guarded Android-only workshop branch,
preserving its on-device build value while making its broad permissions,
runtimes, injection, MITM/network, extension, signing, and store-review
boundaries explicit. Source: X/@DivyanshT91162; WebToApp source at
87f9510