
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
Routup is a minimalistic, runtime-agnostic HTTP routing framework for Node.js, Bun, Deno, and Cloudflare Workers.
Handlers return values directly — routup converts them to Web Response objects automatically.
Table of Contents
npm install routup --save
Response directlyevent.next()request, response, error for cross-cutting concernsTo read the docs, visit https://routup.net
Handlers receive an event and return a value. Routup converts the return value to a Web Response automatically.
Shorthand
import { Router, defineCoreHandler, defineErrorHandler, serve } from 'routup';
const router = new Router();
router.get('/', defineCoreHandler(() => 'Hello, World!'));
router.get('/greet/:name', defineCoreHandler((event) => `Hello, ${event.params.name}!`));
router.use(defineErrorHandler((error) => ({ error: error.message })));
serve(router, { port: 3000 });
Verbose
import { Router, defineCoreHandler, serve } from 'routup';
const router = new Router();
router.use(defineCoreHandler({
path: '/',
method: 'GET',
fn: () => 'Hello, World!',
}));
router.use(defineCoreHandler({
path: '/greet/:name',
method: 'GET',
fn: (event) => `Hello, ${event.params.name}!`,
}));
serve(router, { port: 3000 });
| Return type | Response |
|---|---|
string | text/plain |
object / array | application/json |
Response | Passed through as-is |
ReadableStream | Streamed to client |
Blob | Sent with blob's content type |
null | Empty response (status from event.response) |
Middleware calls event.next() to continue the pipeline:
router.use(defineCoreHandler(async (event) => {
console.log(`${event.method} ${event.path}`);
return event.next();
}));
Routup runs on Node.js, Bun, Deno, and Cloudflare Workers. In most cases, import from routup:
import { Router, defineCoreHandler, serve } from 'routup';
const router = new Router();
router.get('/', defineCoreHandler(() => 'Hello, World!'));
serve(router, { port: 3000 });
For runtime-specific APIs (e.g. toNodeHandler), use the corresponding entrypoint like routup/node.
Routup is minimalistic by design. Plugins extend the framework with additional functionality.
| Name | Description |
|---|---|
| assets | Serve static files from a directory |
| basic | Bundle of body, cookie, and query plugins |
| body | Read and parse the request body |
| cookie | Read and parse request cookies |
| decorators | Class, method, and parameter decorators |
| prometheus | Collect and serve Prometheus metrics |
| query | Parse URL query strings |
| rate-limit | Rate limit incoming requests |
| rate-limit-redis | Redis adapter for rate-limit |
| swagger | Serve Swagger/OpenAPI docs |
Note: These benchmarks were recorded with routup v4 (Node.js 18, Sep 2023). Updated v5 benchmarks will follow.
| Package | Requests/s | Latency (ms) | Throughput/MB |
|---|---|---|---|
| http | 61062 | 15.87 | 10.89 |
| fastify | 59679 | 16.26 | 10.70 |
| koa | 45763 | 21.35 | 8.16 |
| routup | 44588 | 21.91 | 9.02 |
| hapi | 41374 | 23.67 | 7.38 |
| express | 13376 | 74.18 | 2.39 |
To run benchmarks yourself, see the benchmarks repository.
Before starting to work on a pull request, it is important to review the guidelines for contributing and the code of conduct. These guidelines will help to ensure that contributions are made effectively and are accepted.
Made with 💚
Published under MIT License.
FAQs
Routup is a minimalistic http based routing framework.
The npm package routup receives a total of 429 weekly downloads. As such, routup popularity was classified as not popular.
We found that routup demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.