Wedge one
A token budget is an API contract
Every incumbent’s MCP server retrofits human-shaped JSON: unbounded payloads, whole stack traces, breadcrumb arrays that were designed for a scrollbar. That is your context window, and your agent bill. Bucker guarantees a bounded projection per issue, publishes the token count on every response, and versions the schema so your prompts do not break underneath you.
The contract
- claim · 01Shipped
A hard ceiling of 500 tokens
The builder aims for 400 and hard-fails nothing: it walks a fixed reduction ladder, dropping the least valuable content first, and then clamps every remaining optional field if the document still does not fit. The ceiling is a constant, and the test suite asserts it against adversarial events with 500 frames and 500 breadcrumbs. - claim · 02Shipped
The count is published, and rounds against us
Every essence carries its ownestimatedTokens. The estimator is a deliberate heuristic — characters divided by 3.6 — rather than a BPE tokenizer, because it must run on every event in the pipeline without a native dependency. At 3.6 characters per token it sits below the usual estimate for English-plus-code, so an agent that trusts the published number is never surprised by a bigger document than advertised. - claim · 03Shipped
What was dropped is reported back
Truncation is not silent. A hidden frame count names how many frames were omitted, and each hydration handle carries a reason that distinguishes “there is no more stack” from “the rest of the stack costs 900 tokens.” The agent decides whether to pay for the rest. - claim · 04Shipped
Every attacker-controlled string is labelled
Error messages are attacker-controlled input, and in June 2026 prompt injection via a fabricated error report into a repo-write coding agent stopped being hypothetical. So every string carries a trust label — platform, repository, untrusted, or quarantined — and a quarantined value is replaced before it is served. The MCP server exposes no argument that un-redacts it; the opt-in does not exist to be found. - claim · 05Shipped
The format is published, not proprietary
The essence is specified as a standalone format any vendor could implement, with a JSON Schema generated from the same schema the server uses — so the two cannot drift — plus worked examples, a versioning policy and a conformance checklist. The schema version is on every document, and you can pin it. - claim · 06Shipped
The budget is a serving concern, not a capture concern
The SDK captures rich and bounded; the compression happens server-side. Context not captured at event time is gone forever, and fix quality is capped by capture breadth — so the essence is a projection that can improve without anyone shipping an SDK release.
Why a ladder rather than a truncation
Read the specification
The essence contract documents the budget, the reduction ladder and the trust labels as they are built. The published specification is what the format is, with a conformance checklist and a versioning policy.