Programmatic API

Everything the packages export, and which parts are stable. Anything not listed is internal.

Where this fits: Build with TypeScript. The reference at the end of the group; each export links to the page that explains it, and how Kervan works shows which package does what.

On this page

Export names link to the page that explains them.

Everything a package exports is listed here. Stable means it follows semver from 0.1 on (breaking changes only in a new minor version while the version is 0.x, and noted in the changelog). Experimental means it may change in any release. Anything not listed is internal, even if you can reach it through a deep import.

The runtime export lists are pinned by test/api.test.ts in each package.

@kervan/core

ExportKindStatus
createApp, App, AppOptions, AppLimits, ToolInfo, LiveServerfunction, typesStable
ToolDefinition, StructuredToolDefinition, ToolHandler, NoInput, AnyObjectSchema, InputSchema, OutputSchema, InputOf, OutputOftypesStable
ToolContext, ToolLogger, ToolLogFn, ToolLogLeveltypesStable
ToolMiddleware, ToolCall, ToolCallInfotypesStable
ToolRegistry, MutableToolRegistry, ToolEntry, InMemoryToolRegistry, InMemoryToolRegistryOptionstypes, classStable
ServerInfo (ToolRegistry.serverInfo: a registry’s own server identity)typeStable
ServerResolver, ResolveContext (auth, params), ResolveResult, FORBIDDENtypes, constantStable
ToolError, KervanDefinitionError, DefinitionErrorCodeclasses, typeStable
Logger, LogLevel, createConsoleLogger, ConsoleLoggerOptions, silentLoggertypes, functionsStable
DEFAULT_TOOL_TIMEOUT_MS, DEFAULT_MAX_TOOL_INPUT_ELEMENTS, TOOL_NAME_PATTERNconstantsStable
zre-export of Zod 4Stable
AuthInfo, CacheHint, CallToolResult, ContentBlock, ToolAnnotationstype re-exports from the MCP SDKStable (they follow the SDK)
jsonSchema, JsonSchema, rawResult, RawResultfunctions, typesExperimental

@kervan/transport

EntryExportStatus
@kervan/transporttoFetchHandler, FetchHandlerOptions (path may have parameters, e.g. /s/:serverId/mcp; rejectBatches), KervanHttpHandler, Authenticate (receives { params }), AuthInfoStable
@kervan/transport/nodeserve, serveStdio, serveHttp, ServeOptions, StdioOptions, HttpOptions, HttpServerHandle, RateLimitOptionsStable
@kervan/transport/testingcreateTestClient, TestClientOptionsStable

@kervan/spec-runtime

ExportKindStatus
loadSpec, LoadOptions (incl. requireSecrets, allowSecretsOverHttp), LoadedSpec, CompiledTool, CompiledDefinitionfunction, typesStable
applySpecfunctionStable
SpecLoadError, SpecIssue, formatIssueclass, type, functionStable
SecretSource (get(name, context?)), SecretContext, envSecrets, SecretVault, SecretError, REDACTEDtypes, function, classes, constantStable
normalizeHostPortfunctionExperimental
METADATA_RANGESconstantStable name; the list may grow in minor releases
NetworkPolicy (allowPrivate, denyList), NetworkPolicyErrortype, classStable
NetworkPolicy (resolve, localAddresses, lookupGate), Resolver, ResolvedAddress, LookupGatetypes, classExperimental
Spec, SpecTool, specJsonSchematypes, functionStable (the kervan.yaml format, specVersion: 1, including host-bound secrets entries)
HTTP_DEFAULTS, SPEC_LIMITS, SCHEMA_LIMITSconstantsStable names; values may be tuned in minor releases
httpToolfunctionExperimental

Internal (not exported): address classification, pinned DNS lookups, template parsing, schema limit checks, the redaction middleware, and the Zod schema object behind specJsonSchema.

kervan (CLI)

The command line (kervan create, kervan dev, kervan run) and its flags are documented in packages/cli/README.md; flags are stable unless marked otherwise.

ExportKindStatus
run, RunIofunction, typeStable (used by create-kervan)
createProject, CreateOptions, CreateResult, CreateError, PackageManagerfunction, types, classStable
RuntimeInfotypeStable

create-kervan

A binary only (npm create kervan), no programmatic API.