
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
@typeful-api/hono
Advanced tools
Hono adapter for typeful-api - works on Node.js, Cloudflare Workers, Deno, Bun, and more
Hono adapter for typeful-api — build end-to-end type-safe OpenAPI-first APIs with Hono. Works on Node.js, Cloudflare Workers, Deno, Bun, and more.
npm install @typeful-api/core @typeful-api/hono hono @hono/zod-openapi zod
import { defineApi, route } from '@typeful-api/core';
import { z } from 'zod';
const api = defineApi({
v1: {
children: {
hello: {
routes: {
greet: route
.get('/')
.returns(z.object({ message: z.string() }))
.withSummary('Say hello'),
},
},
},
},
});
import { Hono } from 'hono';
import { createHonoRouter } from '@typeful-api/hono';
const router = createHonoRouter(api, {
v1: {
hello: {
greet: async () => ({ message: 'Hello, World!' }),
},
},
});
const app = new Hono();
app.route('/api', router);
export default app;
Use WithVariables to compose context types for Hono's bindings and variables:
import { createHonoRouter, WithVariables } from '@typeful-api/hono';
type BaseEnv = { Bindings: { DATABASE_URL: string } };
type WithDb = WithVariables<BaseEnv, { db: Database }>;
type WithAuth = WithVariables<WithDb, { user: User }>;
const router = createHonoRouter<
typeof api,
{
v1: {
products: WithDb;
users: WithAuth;
};
}
>(api, {
v1: {
products: {
list: async ({ c }) => {
const db = c.get('db');
return await db.products.findMany();
},
},
},
});
Apply middleware at version, group, or route level:
const router = createHonoRouter(api, {
v1: {
middlewares: [corsMiddleware], // All v1 routes
products: {
middlewares: [dbMiddleware], // All product routes
list: handler,
create: handler,
},
},
});
Derive handler types from the contract for type-safe standalone handler files:
import type { InferHonoHandlersWithVars } from '@typeful-api/hono';
import type { api } from './api';
type AppHandlers = InferHonoHandlersWithVars<typeof api, { db: Database }>;
export type ProductHandlers = AppHandlers['v1']['products'];
import type { ProductHandlers } from '../types';
export const list: ProductHandlers['list'] = async ({ c }) => {
const db = c.get('db');
return await db.products.findMany();
};
| Export | Description |
|---|---|
createHonoRouter(contract, handlers) | Create a typed Hono router from an API contract |
createHonoRegistry() | Create an OpenAPI registry for spec generation |
composeMiddleware(...mw) | Compose multiple Hono middlewares |
conditionalMiddleware(pred, mw) | Apply middleware conditionally |
createTypedMiddleware(fn) | Create middleware with typed context |
createVariableMiddleware(fn) | Create middleware that sets context variables |
getVariables(c) | Get typed variables from Hono context |
| Export | Description |
|---|---|
InferHonoHandlers | Infer handler types from a contract |
InferHonoGroupHandlers | Infer handler types for a specific group |
InferHonoHandlersWithVars | Infer handlers with shared context variables |
WithVariables<Env, Vars> | Compose Hono environment types |
For full documentation, examples, and guides, visit the typeful-api repository.
MIT
FAQs
Hono adapter for typeful-api - works on Node.js, Cloudflare Workers, Deno, Bun, and more
We found that @typeful-api/hono demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.