Zod

TypeScript-first schema validation with static type inference and zero dependencies.

Library
npm
v4.6.5
44,052 stars
MIT License

Repository Health

Pre-computed score based on development activity, maintenance, community, maturity, and trend momentum. How we score it →
92 /100 Excellent
Development Activity 100
Maintenance 100
Community 68
Maturity 60
Momentum 40

Technical Analysis

AI-assessed by reading the actual repository — architecture, code quality, innovation, and documentation. How we score it →
89 /100 Excellent
Architecture 90
Code Quality 90
Innovation 92
Learning Curve 85

Zod is a TypeScript-first schema declaration and validation library. You define a schema once, and Zod both validates untrusted data against it at runtime and infers a precise static TypeScript type from it, so the type system and the runtime check can never drift apart. It ships with zero external dependencies, a roughly 2kb gzipped core bundle, and works identically in Node.js, Deno, Bun, and every modern browser.

Beyond primitive and object schemas, Zod supports unions, discriminated unions, recursive types, refinements, transforms, and built-in JSON Schema conversion, and its .safeParse() API returns a typed result object instead of throwing, making error handling explicit. It has become the de facto standard for runtime validation in the TypeScript ecosystem, with first-class integrations across tRPC, React Hook Form, Next.js Server Actions, and dozens of other frameworks.

What You Get

  • A fluent, chainable schema-builder API covering primitives, objects, arrays, unions, discriminated unions, tuples, records, maps, sets, and recursive types
  • Automatic static type inference (z.infer, z.input, z.output) so schemas double as your TypeScript types
  • .parse() / .safeParse() (and async variants) for throwing or non-throwing validation with a structured ZodError and granular issue list
  • Built-in transforms and refinements (.transform(), .refine(), .superRefine()) for coercion and cross-field validation logic
  • Native JSON Schema generation (z.toJSONSchema()) and Standard Schema interop for tooling that speaks a common validation contract
  • A zod/mini build with a functional, tree-shakeable API for bundle-size-sensitive projects

Common Use Cases

  • Validating and typing incoming API request bodies and query parameters in an Express, Fastify, Next.js, or Hono route handler
  • Defining end-to-end typesafe contracts in tRPC procedures or Server Actions without hand-written DTOs
  • Validating environment variables at process startup so misconfiguration fails fast with a readable error
  • Powering form validation and typed form state in React Hook Form, Formik, or Conform integrations
  • Parsing and normalizing third-party API responses at the network boundary before they enter application code

Under The Hood

Architecture — Zod’s source (packages/zod/src) is split into a v4/core layer (schema traits, parsing engine, error formatting, JSON Schema conversion, in core.ts, parse.ts, schemas.ts) and a v4/classic layer that layers the familiar chainable z.object()-style API on top of it. A parallel v3 tree preserves the legacy API verbatim for backward compatibility, and v4-mini/mini expose a functional, tree-shakeable variant of the same core. Schema classes are built with a custom $constructor trait system (core.ts) rather than plain ES classes, which lets one definition be shared across the classic, mini, and JSON Schema surfaces without duplicating parsing logic — a deliberate structural choice to support three public API shapes from one validation core.

Tech Stack — Pure TypeScript (~89% of the repo by bytes) with zero runtime dependencies, targeting Node.js, Deno, Bun, and browsers via dual ESM/CJS output built with zshy/tsdown. The repo is a pnpm workspace (packages/zod, packages/docs, packages/bench, packages/integration) with Biome handling linting and formatting and Vitest running the test suite; a check:semver pre-commit hook enforces that version numbers stay in sync across package.json, jsr.json, and the in-source versions.ts.

Code Quality — The v4/core and v4/classic trees each carry their own tests/ directories (168+ test files repo-wide) covering primitive types, refinements, error formatting, and JSON Schema conversion, and AGENTS.md codifies house rules enforced in review: every feature or fix needs a test, no console.log/debugger in shipped code, and tests must stay dense rather than padded with redundant assertions. Error handling is explicit throughout — .safeParse() returns a discriminated-union result rather than relying on exceptions for control flow, and ZodError carries a structured, machine-readable issues array.

API Design — The chainable builder API (z.string().min(3).email()) reads close to prose, and .safeParse()/.parse() give callers a choice between exception-based and result-based error handling depending on context. Getting started requires no boilerplate beyond import * as z from "zod" and one schema declaration — the inferred type is available immediately via z.infer<typeof Schema> with no code generation step. Naming is consistent across the whole surface (.min/.max/.optional/.nullable behave the same on every schema type), and the package even publishes an llms.txt/llms-full.txt and an MCP server specifically to make its API legible to AI coding tools.

Used by 277 apps in this directory

TypeScript
72%
Apache 2.0

Supabase

Authentication · Databases · Developer Tools

110,828

The open-source Postgres development platform that replaces Firebase with authentication, real-time APIs, edge functions, storage, and vector embeddings — all built on PostgreSQL.

View details
90
Repo Health
91
Technical
62
Dependency
Built with
TypeScript 72%
MDX 26%
Updated 1 weeks ago
TypeScript
91%
MIT

Super Productivity

Productivity · Project Management

22,309

A privacy-respecting, local-first task manager with built-in timeboxing, Pomodoro timer, and deep integrations for Jira, GitHub, GitLab, and CalDAV — no accounts, no data collection, ever.

View details
91
Repo Health
81
Technical
72
Dependency
Built with
TypeScript 91%
Updated 1 weeks ago
TypeScript
54%
MIT

Superagent

AI Agents · Security

6,757

An open-source SDK that blocks prompt injections, redacts PII and secrets, scans repositories for AI-targeted attacks, and red-teams production agents.

View details
69
Repo Health
66
Technical
74
Dependency
Built with
TypeScript 54%
Python 43%
Updated 1 months ago
TypeScript
96%
Other

superglue

AI Agents · Data Engineering · Developer Tools

2,063

superglue is an AI-agent-driven integration engine that turns plain-English descriptions of enterprise systems into production-grade API tools, ERP/CRM connectors, and data pipelines — self-hosted or cloud, Y Combinator-backed (W25).

View details
49
Repo Health
79
Technical
67
Dependency
Built with
TypeScript 96%
Updated 1 months ago
TypeScript
98%
Apache 2.0

superlog

AI Agents · Monitoring

1,455

Open-source agentic observability that ingests OpenTelemetry signals, groups them into incidents, and deploys AI agents to investigate and fix your production bugs automatically.

View details
64
Repo Health
73
Technical
73
Dependency
Built with
TypeScript 98%
Updated 2 weeks ago
TypeScript
54%
MIT

supermemory

AI Development · AI Memory · Note Taking

30,958

The state-of-the-art memory and context engine for AI agents — ranked #1 on all three major AI memory benchmarks.

View details
87
Repo Health
82
Technical
68
Dependency
Built with
TypeScript 54%
MDX 31%
Python 13%
Updated 2 weeks ago
TypeScript
85%
Apache 2.0

superset

AI Code Assistants · AI Development

14,690

Orchestrate an army of AI coding agents—Claude Code, Codex, Gemini CLI, and more—running simultaneously in isolated git worktrees from a single Electron desktop app.

View details
86
Repo Health
80
Technical
64
Dependency
Built with
TypeScript 85%
Updated 1 weeks ago
Python
67%
Apache 2.0

SurfSense

AI Assistants · Search

16,270

The open-source, unlimited NotebookLM alternative with real-time collaboration, a desktop app, and no vendor lock-in.

View details
87
Repo Health
71
Technical
66
Dependency
Built with
Python 67%
TypeScript 30%
Updated 1 weeks ago
TypeScript
97%
AGPL 3.0

Swetrix

Analytics

1,200

Privacy-first, cookieless web analytics with error tracking, session replays, and performance monitoring — self-host or use Cloud.

View details
88
Repo Health
71
Technical
66
Dependency
Built with
TypeScript 97%
Updated 1 weeks ago

Join founders buildingwith open source

Opinionated takes, migration guides, cost-saving tips, and insights from the open source ecosystem.

Subscribe on Substack
Join 750+ subscribers