
Security News
Insecure Agents Podcast: How to Keep AI Agents From Bypassing Security Controls
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.
The open-source docs framework for humans and agents. Fast, AI-ready, and zero-config. Free and open source, forever.
Drop Markdown or MDX into a folder, start the dev server, and get a production-grade docs site — navigation, search, theming, Open Graph images, and a rich component library — with no app boilerplate to write or maintain. Blume generates and drives a hidden Astro project for you; run npx blume eject to get a standalone Astro app whenever you want full control.
Documentation · Quickstart · Components · CLI
Blume needs Node.js 22.12 or newer and a content folder with at least one .md/.mdx file — there's nothing else to set up.
npx blume init
It scaffolds docs/index.mdx and blume.config.ts, adds dev and build scripts to a new package.json, and installs dependencies. Run the dev server with hot reload:
npm run dev
Build static HTML, with a local search index, into dist/:
npm run build
In a project that already has a package.json, blume init leaves it alone: add "dev": "blume dev" and "build": "blume build" to its scripts, or run npx blume dev. Blume works with any package manager and never requires you to set up Astro or Tailwind yourself.
Moving from another docs framework? npx blume migrate hands a Mintlify, Fumadocs, Docusaurus, Starlight, or Nextra site to Claude Code or Codex — see Migrate to Blume. On Blume 1, run npx blume@latest upgrade — see Upgrade to Blume 2.
blume.config.ts and every meta.ts are real TypeScript, validated by a schema and authored with defineConfig / defineMeta, so your editor catches mistakes before a build.search: pagefind() from blume/search).llms.txt / llms-full.txt, raw Markdown at any .md URL, a JSON docs API, Copy as Markdown, Open in chat, an optional in-page assistant, and a hosted MCP server so coding agents can search and read your docs directly.robots.txt, RSS feeds, and JSON-LD, built in.openapi(), asyncapi(), and graphql() from blume/reference, or embed Scalar's UI with scalar().theme.css, and a source-component registry (blume add).npx blume eject produces a standalone Astro project that still uses the blume package.| Command | Description |
|---|---|
blume init [dir] | Scaffold a project (interactive by default). |
blume dev | Start the dev server with hot reload. |
blume build | Build the static (or server) site. |
blume preview | Preview the last build. |
blume add <item> | Install a source component from the registry. |
blume sync | Re-fetch remote content sources and regenerate. |
blume eject | Promote the runtime into a standalone Astro app. |
blume check | Type-check the docs site with astro check. |
blume validate | Validate internal, anchor, asset, and external links. |
blume doctor | Diagnose config and content problems. |
blume audit | Audit the built site for SEO and health issues. |
blume eval | Test the docs: an agent answers your questions using only the documentation. |
blume translate | Translate docs into the configured locales with a local agent CLI. |
blume version [id] | Freeze the current docs as an archived version (no id lists configured versions). |
blume migrate [source] | Move a Mintlify, Fumadocs, Docusaurus, Starlight, or Nextra site to Blume with Claude Code or Codex. |
blume upgrade | Move to a new major: bump blume, then list the config changes left or hand them to Claude Code or Codex. |
Run them through your package manager (npx blume <command>) or a package.json script. See the CLI reference for every flag.
The Blume CLI loads blume.config.ts, scans your content into a graph, and generates a hidden Astro project under .blume/ that it drives for dev and build. Astro renders through a catch-all page that imports Blume's shipped components, the generated data, and your overrides. .blume/ is regenerated on each run — only changed files are written, so hot reload stays fast — until you blume eject and own it.
blume build outputs static HTML to dist/ — deploy to any static host (Vercel, Netlify, Cloudflare Pages, GitHub Pages, S3 + CloudFront, or any CDN). For request-time features like the assistant or the MCP server, name a host adapter from blume/deploy in blume.config.ts, which switches the build to server output:
import { defineConfig } from "blume";
import { vercel } from "blume/deploy";
export default defineConfig({
deployment: vercel(),
});
| Adapter | Use for |
|---|---|
vercel() | Vercel |
netlify() | Netlify Functions |
node() | Self-hosted Node servers, containers |
cloudflare() | Cloudflare Workers and Pages |
On Vercel, Netlify, and Cloudflare Pages the site URL is detected automatically. The adapter never is: name it in blume.config.ts.
| Requirement | Supported |
|---|---|
| Node | 22.12+ |
| Package managers | Bun, pnpm, npm, yarn |
| Adapters | Vercel, Netlify, Node, Cloudflare |
This repository is a monorepo: the published package lives in packages/blume, and apps/docs is Blume's own documentation, built with Blume.
bun install
bun run check # lint + format (Ultracite)
bun run typecheck
bun run test
See CONTRIBUTING.md for architecture and conventions.
MIT © Hayden Bleasel
FAQs
The open-source docs framework for humans and agents.
The npm package blume receives a total of 83,674 weekly downloads. As such, blume popularity was classified as popular.
We found that blume demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.