zod is by colinhacks — not by us.
We indexed this project so people can find it. We are not selling it, we host no copy of the code, and we are not affiliated with or endorsed by its authors — get it from them.
Indexed Aug 3, 2026 · 43,391 stars at index time. Maintainers: claiming verifies your identity and unlocks a higher assurance tier. Removal requests are honored.
Application · for humans & their agents
zod
unclaimed listingactively maintainedFreeMIT
TypeScript-first schema validation with static type inference
by Open Source Community · New publisher
Every claim on this page is refundable if it is untrue — refund policy.
colinhacks/zod is an open-source project by colinhacks: TypeScript-first schema validation with static type inference. Indexed here so it can be found — not resold.
It is free. Get it from the upstream repository: https://github.com/colinhacks/zod
From the project's own README (excerpt, reproduced for discovery under its MIT license):
Zod TypeScript-first schema validation with static type inference by @colinhacks
Docs • Discord • 𝕏 • Bluesky
Read the docs →
What is Zod?
Zod is a TypeScript-first validation library. Define a schema and parse some data with it. You'll get back a strongly typed, validated result.
Features • Zero external dependencies • Works in Node.js and all modern browsers • Tiny: 2kb core bundle (gzipped) • Immutable API: methods return a new instance • Concise interface • Works with TypeScript and plain JS • Built-in JSON Schema conversion • Extensive ecosystem
Installation
Basic usage
Before you can do anything else, you need to define a schema. For the purposes of this guide, we'll use a simple object schema.
Parsing data
Given any Zod schema, use .parse to validate an input. If it's valid, Zod returns a strongly-typed deep clone of the input.
Note — If your schema uses certain asynchronous APIs like async refinements or transforms, you'll need to use the .parseAsync() method instead.
Handling errors
When validation fails, the .parse() method will throw a ZodError instance with granular information about the validation issues.
To avoid a try/catch block, you can use the .safeParse() method to get back a plain result object containing either the successfully parsed data or a ZodError. The result type is a discriminated union, so you can handle both cases conveniently.
Note — If your schema uses certain asynchronous APIs like async refinements or transforms, you'll need to use the .safeParseAsync() method instead.
Inferring types
Zod infers a static type from your schema definitions. You can extract…
Preview
See what it does before you commit. Previews show behavior, never source code.
01Capabilities
Does
- + Input validation
- + Schema contract enforcement
- + Type coercion safety
Doesn’t
- No exclusions declared
02Requirements & stack
Depends on
No declared dependencies
Credentials needed
None declared
Stack
03Community
No endorsements yetNo verified confirmations yet — be the first.
Confirmations come from verified purchasers, installers, vetted reviewers, or an installation outcome your org reported through the agent tools. They grade quality — security is verified separately, and community votes can never override the security gate.
Sign in to confirm — weight comes from verified usage, not vote count.
Issues 0
Open an issueNobody has reported anything yet — a success counts as a report too.
04Trust Passport
Full passport →0/0 automated components pass. An automated score is never a security guarantee.
This listing is unclaimed, so publisher identity cannot be verified and it stays below the “verified” tier by design — that is a statement about the listing, not about the project’s quality. Our automated scans still ran; a maintainer who claims it unlocks identity verification.
- publisher identity Publisher status verified; 0 verification(s) on file
- malicious pattern scan No known malicious-behavior patterns across listing text only — no source artifact published
- capability contract All 0 observed capability reference(s) match the declared manifest
- agent safety scan No injection patterns in agent-readable content
- provenance No release signature or provenance attestation
- behavioral sandbox Not performed in this environment — requires the production isolated runner (docs/sandbox-requirements.md). No untrusted code is ever executed on the application host.
Every listing must pass this review before it can be sold, and it is re-run on every release. Verification describes what we checked — it is not a guarantee that the software is safe.
05Versions
Full history →| Version | Channel | Released | Notes |
|---|---|---|---|
| 0.0.0 | stable | Aug 3, 2026 | Indexed listing — see the upstream repository for real release history. |