zttp

v0.18.0: TypeScript handlers proven at compile time

zts subset - compile-time proof - compiler-in-the-loop agent

~7ms cold start
4.8MB binary size
~13MB memory baseline
The Product

v0.18.0 tightens the proof loop end to end

Install once. Edit your code. Run zttp dev --watch --prove and watch the compile-time proofs update on every save. Ship only code the compiler can prove and the contract diff keeps green.

📦 Single-binary install

Linux and macOS builds keep the first run short and start from a binary, not a toolchain.

🔗 Compile-time proof on save

zttp dev --watch --prove re-runs path and guarantee proofs on every save, then hot-swaps only on safe / safe_with_additions.

⚙️ Compiler-in-the-loop agent

zttp expert asks when intent is ambiguous, runs the proof pass, reads diagnostics, and repairs until the compiler accepts the handler.

The Insight

The subset is what makes compile-time proof tractable

Your handler code is checked as the spec.

No back-edges, no exceptions, no hidden I/O. The compiler walks every path in finite time, enforces guarantees by default (narrow with Spec<...> when you need a chosen few), and emits a behavioral contract small enough to diff between versions.

Handler Code
Compiler Analysis
Proven Contract
Auto Sandbox
Language Design

TypeScript, narrowed until the compiler can prove it

REMOVED (zts)
✕ classes / this / new
✕ var / null / == / !=
✕ while / do...while
✕ async / await / Promises
✕ try / catch / throw
✕ regex / delete / any / as
KEPT + ADDED (zts)
✓ arrow functions + destructuring
✓ const / let / for...of
✓ match expressions (exhaustive)
✓ pipe operator (|>)
✓ guard() composition
✓ comptime() evaluation
✓ JSX / TSX (first-class SSR)

Unsupported features fail at parse time with a suggested alternative, not after deploy.

Verification

Compile-time proof for paths, types, and guarantees

Every code path returns a Response No forgotten early returns. No implicit undefined.
Result values checked before access jwtVerify(...).ok must be tested - the BoolChecker enforces it.
No unreachable code Dead branches are a build error, not a linter warning.
Boolean enforcement Truthy/falsy coercion rejected everywhere. Progressive type inference for env(), cacheGet(), and match arms.
Full type checking Variable types, function signatures, property access, nominal interfaces - all validated.
$ zts check handler.ts --json --contract → PROVEN 7/7 paths + Spec<idempotent, deterministic> ✓
Security

Automatic least-privilege sandboxing

The compiler extracts a contract of what the handler does, then restricts runtime access to exactly those proven values.

contract.json
{
  "env": ["API_KEY", "DB_URL"],
  "egress": ["api.stripe.com"],
  "cache": ["sessions"],
  "sql": ["getUserById"],
  "properties": {
    "read_only": true,
    "retry_safe": true
  },
  "proof": "complete"
}
🛡 Zero configuration required
🛡 Env vars scoped to declared set
🛡 Egress locked to proven hosts
🛡 Effect classification per handler
🛡 OpenAPI spec from -Dopenapi
Concurrency & Durability

Linear code. Parallel I/O. Crash recovery.

Structured Concurrent I/O

parallel() and race() from zttp:io

Handler code stays synchronous and linear. Concurrency happens in the I/O layer using OS threads.

3 API calls × 50ms each = ~50ms total

🔄 Durable Execution

--durable <dir> enables crash recovery

Write-ahead oplog. Each I/O call persisted before returning. On crash, replay without touching the network.

sleep() - sleepUntil() - waitSignal()
Evolution

Prove before deploy

Deterministic Replay

Record every I/O boundary with --trace. Replay against new versions. Handlers = pure functions of (Request, VirtualModuleResponses).

--trace / --replay
Proven Evolution

Diff behavioral contracts and replay traces between handler versions. Verdicts are safe, safe_with_additions, breaking, or needs_review - with a proof certificate.

zts prove old.json new.json
Proof Ledger

Every successful deploy and proven hot-swap appends one row to .zttp/proofs.jsonl with verdicts, proven facts, and contract sha. Export as markdown, HTML, or an SVG verdict badge for the PR description.

zttp proofs list | show | diff | export
Developer Experience

Three binaries. The proof loop in your terminal, the agent inside it.

zttp CLI v0.18.0
init → dev → test → expert → deploy
$
zttp init my-app Scaffold a project with a handler, zttp.json, and zts-ready defaults
$
zttp test Run handler tests as golden request/response cases against the proven handler
$
zttp dev --watch --prove Proven live reload - hot-swap only on safe / safe_with_additions verdicts
$
zttp deploy Self-contained binary + one proof-ledger row; verify with zttp verify against the embedded Ed25519 key
$
zttp expert Asks one clarifying question when needed, compiles the patch, and reports proof-loop metrics
$
zttp proofs / witnesses Browse the proof ledger; manage the per-handler witness corpus that defends against regressions
curl -fsSL https://raw.githubusercontent.com/srdjan/zttp/main/install.sh | sh Pre-built binaries for macOS and Linux (x86_64, aarch64) - v0.18.0
Composition

Zero-overhead composition. Native speed.

📦 Guard Composition
guard(auth) |> guard(log) |> handler |> guard(cors)

Desugared to a single flat function with sequential if-checks at compile time. Zero runtime overhead.

⚙️ Native Virtual Modules
zttp:auth JWT + webhooks
zttp:crypto SHA/HMAC/B64
zttp:validate JSON Schema
zttp:decode Parse + validate
zttp:cache KV store + TTL
zttp:sql SQLite
zttp:io Parallel I/O
zttp:durable Crash recovery
zttp:compose Guards + pipe
zttp:router Route matching
zttp:env Environment
zttp:http Cookies + CORS
zttp:url URL parsing
zttp:id UUID/ULID/nano
zttp:log Structured logs
zttp:text Escape + slug
zttp:time ISO/HTTP dates
zttp:ratelimit Token bucket
zttp:service Service calls
zttp:scope Resource scopes

20 modules implemented in Zig - zero interpretation overhead.

Comparison

zttp vs the general-purpose runtimes

zttp
Node.js
Deno
Bun
Performance
Cold start
~7ms
~200-300ms
~150-200ms
~100-130ms
Binary
4.8MB
~80MB
~130MB
~90MB
Memory
~13MB
~30MB
~25MB
~20MB
Verification
Compile-time proofs
-
-
-
Auto sandboxing
-
Perms
-
Injection prevention
Proof
Manual
Manual
Manual
OWASP compliance
Auto
Audit
Audit
Audit
DX & Trade-offs
Deploy manifest
Compiler
Template
Template
Template
AI agents
Compiler loop
Generic
Generic
Generic
Language
zts subset
Yes
Yes
Yes
npm ecosystem
Virtual
Full
Full
Full

zttp trades generality for compile-time proof, least privilege, and deployment automation.

zttp

Write handlers. Prove them at compile time. Ship them.

Opinionated subset Parse-time rejection of footguns
Compile-time verification Every path, every type, every boolean
Compiler-in-the-loop agent Writes, compiles, and repairs before review
Automatic sandboxing Least-privilege derived from analysis
Structured I/O Linear code, parallel execution
Durable execution Crash recovery via write-ahead oplog
Deterministic replay Record I/O boundaries, replay anywhere
Proven evolution Diff contracts, classify changes into four verdicts
Guarantees by default All enforced by default; Spec<...> narrows to a chosen few
Proof ledger A persistent verdict timeline for every deploy
Witness corpus Counterexamples persist; regressions are caught, not rediscovered
Native performance ~7ms cold start - 4.8MB - ~13MB baseline