
Security News
/Company News
Securing the Financial Frontier: How Capital One Uses Socket for Open Source Security
Capital One is partnering with Socket to proactively secure its open source supply chain.
High-performance audio synthesis for Node/Bun/Deno via native Rust bindings
High-performance audio synthesis for Node.js, Bun, and Deno — backed by native Rust bindings via CPAL.
The organ engine is the current focus of active development and is the most polished part of the library. The baroque pipe organ simulation — including the
principalwaveform, mixture ranks, breaking stops, drawbar control, key-click, and Leslie rotary speaker — is production-quality.All other instrument classes (
Piano,Guitar,Flute,Trumpet, etc.) are works in progress. They produce sound and are usable, but their voices have not been tuned to the same standard. Expect rough edges.
npm install supersynth
Prerequisites: Rust and Cargo must be installed to build the native addon. Install from rustup.rs.
import { Synth } from 'supersynth';
// Play a note through your speakers
const synth = new Synth({ masterVolume: 0.5 });
await synth.start();
synth.noteOn(69, 100); // A4, velocity 100
await new Promise(r => setTimeout(r, 2000));
synth.noteOff(69);
synth.stop();
Use a pre-built instrument class for a specific sound:
import { Organ, Piano, Flute } from 'supersynth';
const organ = new Organ({ masterVolume: 0.7 });
await organ.start();
organ.activatePreset('principal');
organ.noteOn(60, 100).noteOn(64, 100).noteOn(67, 100); // C major chord
Configure voice directly for custom synthesis:
import { Synth } from 'supersynth';
const synth = new Synth({
voice: {
oscillators: [{ waveform: 'sawtooth', attackTime: 0.1, releaseTime: 0.4 }],
},
reverb: { roomSize: 0.8, wet: 0.3 },
masterVolume: 0.6,
});
| Topic | Description |
|---|---|
| Synth | Core class — constructor, methods, events |
| Voice & Oscillators | VoiceConfig, OscillatorTemplate, VelocityCurve |
| Waveforms | All 12 waveforms with parameters and implementation notes |
| Instruments | 20 pre-built instrument classes |
| Organ | Organ engine — stops, presets, drawbars, mixture ranks |
| Effects | Reverb, overdrive, Leslie, limiter |
| MIDI | Hardware input, events, raw MIDI bytes |
| Errors | Error classes and handling |
npm run example:tone # 440 Hz sine for 2 seconds
npm run example:chord # C major chord with reverb
npm run example:midi # Bach BWV 532 MIDI file through organ
Play any MIDI file:
node --import tsx examples/midi-file.ts /path/to/your.mid
See the examples/ directory for 20+ instrument demonstrations.
npm run bench # throughput vs node-web-audio-api and web-audio-api
npm run bench:realtime # real-time callback timing under GC pressure
npm test # TypeScript integration tests (no hardware required)
npm run test:rust # Rust unit tests
git clone https://github.com/jddubois/supersynth
cd supersynth
npm install
npm run build
npm test
TypeScript API (src/)
↓ napi-rs bindings
Rust synthesis engine (native/src/)
├── synth/ oscillators, envelopes, LFOs, chiff, waveforms, Karplus-Strong
├── effects/ Freeverb reverb, overdrive, biquad, low-pass, limiter, Leslie
├── midi/ MIDI parsing, device input (midir)
└── audio/ CPAL backend selection and stream management
↓ CPAL
CoreAudio / WASAPI / ALSA / PulseAudio / PipeWire / JACK
MIT
FAQs
High-performance audio synthesis for Node/Bun/Deno via native Rust bindings
The npm package supersynth receives a total of 11 weekly downloads. As such, supersynth popularity was classified as not popular.
We found that supersynth demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.