App code quality
How Retool ensures that generated apps are consistent, type-safe, and secure by default.
The app building agent writes React and TypeScript code to build your Retool apps. Retool constrains how the agent writes code and continuously verifies its output as it works. The agent uses the following strategies so that your code is secure, well-designed, and performant.
Frontend code libraries
The app builder writes frontend code using a fixed set of publicly available libraries rather than develop its own from scratch. Every app uses the same packages:
| Library | Used for |
|---|---|
| shadcn/ui | Most components and component styling |
| TanStack | Tables |
| Recharts | Charts |
| Lucide | Icons |
| Tailwind CSS | Theming |
| React Router | Multipage navigation |
Steering the agent toward these primitives, instead of custom tables, modals, or icons, means accessibility, visual consistency, and theming are built in rather than reimplemented per app. For more detail on the libraries apps are built with, refer to How apps work.
Strict TypeScript and self-correction
Generated code runs using a strict TypeScript configuration. TypeScript extends JavaScript with types, which are labels that describe the kind of value each piece of code works with, such as a number, a string of text, or a list. Retool tells the agent to check those types rigorously and reject code that is ambiguous or likely to break, such as using a value that might not exist.
Retool guides the agent to follow these constraints, and type-checks the code continuously as the agent writes it. When the agent produces code that doesn't satisfy the configuration, Retool surfaces the errors back to the agent, which corrects them before finishing.
Code validation
Before any code the agent writes is saved to your app, it passes through a validation step that blocks unsafe or incorrect patterns. This includes:
- SQL, GraphQL, and SOQL resource query construction that risks injection.
- Invalid or mismatched function parameters.
- Disallowed imports, such as code that tries to reference credentials or bypass Retool's data layer.
If the agent writes code that violates one of these rules, the edit is rejected and the agent has to correct it. The same checks run again when you publish, so unsafe patterns can't reach a published app.
Consistent data access patterns
The app builder is intentionally opinionated about how apps read and write data. The agent doesn't write raw network requests or handle credentials directly. Instead, app code accesses your data only through resources and functions. Retool generates a typed interface for each connected resource that functions call, backed by short-lived, scoped credentials and the requesting user's own resource permissions.
This interface keeps access to your data consistent and resistant to security risks:
- Functions pass values as separate, typed parameters rather than building them into the query string. This is the safe path that the injection checks require.
- Functions run serverlessly on Retool's backend and call your resources through generated clients. Raw credentials are never exposed to app code.
- The agent can only read or write data the builder is already authorized to access.
For more information about functions and resources, refer to Data in apps. To learn about how the agent handles your data and enforces resource access while building, refer to App security.
Constrained package installation
You can add npm packages to extend an app beyond the built-in libraries.
Retool imposes certain restrictions on the types of packages that can be installed:
- The version of the package must be at least 5 days old. Compromised packages are often discovered quickly. By waiting 5 days to install a package, you reduce the risk of installing a package before it's been fully vetted.
- Packages must use one of the following open source licenses, which allow for use and distribution with minimal restrictions. While Retool enforces a list of allowable licenses, it is your responsibility to confirm the license requirements for any third-party packages in your apps.
The agent always asks for permission before installing a third-party package.
Human oversight
Ultimately, maintaining high code quality also depends on keeping a human in the loop (HITL) of the app building process:
- By default, Retool requests approval before a function changes resource data while you preview the app. Builders can turn off preview approval, but all functions must be approved before publishing. Read-only functions run automatically. Refer to App security for more information.
- Each change made by a human or by the agent produces a captured version that you can review and roll back to if necessary. Refer to Change history to learn more.
- Enterprise users can protect apps so that they are managed using Source Control. With this mechanism, changes go through a managed review workflow before being integrated into the published app.