
Security News
/Company News
Securing the Financial Frontier: How Capital One Uses Socket for Open Source Security
Capital One is partnering with Socket to proactively secure its open source supply chain.
@mastra/server
Advanced tools
Affected versions:
Typed, framework-agnostic HTTP route definitions, handlers, schemas, and adapter utilities for exposing a Mastra instance over HTTP. This package powers Mastra's development server and the framework-specific server adapters.
npm install @mastra/server
The handlers are framework-agnostic functions that accept a Mastra instance and request context. Import them from @mastra/server/handlers, then mount the route handlers under a URL prefix in your web framework:
import { RequestContext } from '@mastra/core/request-context';
import { agents } from '@mastra/server/handlers';
import { Hono } from 'hono';
import { mastra } from './mastra-instance';
const app = new Hono();
app.get('/mastra/agents', async c => {
const result = await agents.LIST_AGENTS_ROUTE.handler({
mastra,
partial: c.req.query('partial'),
requestContext: new RequestContext(),
});
return c.json(result);
});
export default app;
Each exported route combines its HTTP method, path, validation schemas, permission requirements, response type, and handler. Framework adapter packages automate this registration and translate framework requests and responses into the common handler context.
Handler groups cover agents and agent controllers, conversations, workflows and dynamic workflows, tools, MCP, memory, vectors, voice, logs, observability, scores, schedules, datasets, processors, workspaces, skills, plans, authentication, A2A tasks, and stored entities.
Route handlers return serializable values or streams and throw HTTPException when an error should map to a non-2xx response. Shared schemas and error-formatting helpers are available through package subpaths for adapters that need to validate requests or emit OpenAPI metadata.
@mastra/server/server-adapter exports the abstract MastraServer contract and common route-registration utilities. Adapter packages implement framework-specific streaming, parameter extraction, response handling, context middleware, authentication middleware, and HTTP logging around this contract.
The package's OpenAPI-derived route metadata can be refreshed from packages/server with:
pnpm run pull:openapispec
See the package changelog for version history and release notes.
We have an open community Discord. Come and say hello and let us know if you have any questions or need any help getting things running.
FAQs
Unknown package
The npm package @mastra/server receives a total of 736,080 weekly downloads. As such, @mastra/server popularity was classified as popular.
We found that @mastra/server demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 7 open source maintainers collaborating on the project.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.