heretic(config) is the same function from the script tag and the npm package. It runs once per page. Pass the complete configuration to the first call.
Result
requestId is a 32-character lowercase hex string, readable at once from your backend. sessionCreated: true with ok: false means the sensor opened a session that did not complete; it finalizes as refused 15 seconds after opening. sessionCreated: false means nothing to read. reason is prose.
Options
Zero data retention
Content security policy
https://probe.heretic.tech to script-src when loading by script tag. Blocked blob workers reduce compute coverage. Do not put a CDN or proxy between the browser and the sensor; the sensor would measure the proxy.
Exports
heretic, resolveEndpoint, PROBE_VERSION, SURFACE_VERSION, RENDER_VERSION, COLLECTOR_VERSION, TELEMETRY_CONTRACT_VERSION, WASM_PROBE_VERSION. The script tag exposes the same values as properties of heretic.