---
title: "@playstack/nest-feedback"
description: "NestJS route for the anonymous feedback intake used by the CLI."
tags: ["package","events-operations","feedback","nestjs","paid"]
---

{/* package-access:start */}

> **Paid.** Covered by the Playstack Pro License; access and tier assignment are not yet announced. See [package access](/docs/packages#access-policy).

{/* package-access:end */}

`@playstack/nest-feedback` mounts `POST /v1/feedback`, the anonymous intake route `playstack feedback` posts to, and exports the intake for hosts that need it elsewhere.

{/* package-install:start */}

## Install

After confirming [preview access](/docs/packages#access-policy), install the package at your application's shared Playstack version:

```sh
npm install --save-exact @playstack/nest-feedback@0.1.0-beta.1
```

Check the peer requirements below before choosing a runtime or provider.

{/* package-install:end */}

## Configure

```ts
import { Module } from '@nestjs/common'
import { PlaystackFeedbackModule } from '@playstack/nest-feedback'
import { PrismaFeedbackStore } from '@playstack/feedback/prisma'

@Module({
  imports: [
    PlaystackFeedbackModule.forRoot({
      store: new PrismaFeedbackStore(prisma, { outbox }),
      limiter: { consume: ({ ip }) => limiter.consume('feedback.ip', { subjects: { ip } }) },
      hashAddress: (ip) => keyedHash(ip),
      // The client address per your reviewed proxy policy; without it the
      // socket address is used and forwarded headers are never trusted.
      clientAddress: (request) => trustedClientAddress(request),
    }),
  ],
})
export class ApplicationModule {}
```

`forRootAsync({ imports, inject, useFactory })` resolves the same options from application providers. The module is not global and exports `NEST_FEEDBACK_OPTIONS` and `PLAYSTACK_FEEDBACK_INTAKE`.

## HTTP contract

| Outcome | Response |
| --- | --- |
| stored | `202 { id, status: 'accepted' }` |
| known id | `202 { id, status: 'duplicate' }`, nothing written |
| malformed or empty body | `400 { error: 'malformed_json' }` |
| schema failure | `400 { error: 'invalid_report', detail }` |
| body over `maxBodyBytes` (64 KiB default) | `413` |
| address limited | `429` with `Retry-After` and `RateLimit-*` headers |
| storage or limiter failure | `503` |

The route reads the client address before the body, so a limited address never costs a parse. The address is hashed with the host's keyed hash before it is stored.

## Boundary

The package chooses no proxy policy: supply `clientAddress` from the host's reviewed number of trusted hops. Authentication is deliberately absent; the CLI submits anonymously and the report's contact field is the only identity.

{/* package-reference:start */}

## API entry points and requirements

Reference snapshot: `@playstack/nest-feedback@0.1.0-beta.1`. Import only the entry point your runtime needs. Paths below are relative to the installed package; use **Go to Definition** in your editor to inspect exact parameters, return types and overloads. Do not import the declaration-file paths directly.

| Public entry point | Declaration file |
| --- | --- |
| `@playstack/nest-feedback` | `./dist/index.d.ts` |
| `@playstack/nest-feedback/package.json` | No TypeScript declaration (asset or metadata export). |

Node.js engine requirement: `>=20`. This is not a claim that every entry point works in browsers or Workers.

### Peer dependencies

Keep existing framework versions that satisfy these ranges. Install optional peers only when using the corresponding adapter. The package manager resolves ordinary dependencies separately.

| Peer | Compatible range | When needed |
| --- | --- | --- |
| `@nestjs/common` | `^10.0.0 \|\| ^11.0.0` | Required by the package. |
| `@playstack/feedback` | `0.1.0-beta.1` | Required by the package. |
| `reflect-metadata` | `^0.1.13 \|\| ^0.2.0` | Required by the package. |
| `rxjs` | `^7.0.0` | Required by the package. |

For a complete first program, start with [Getting started](/docs/getting-started). For API lookup and partial-example conventions, see [Reading the reference](/docs/packages#reading-the-reference). Provider failures, lifecycle requirements and application responsibilities remain described in the guide above; types alone do not establish production safety.

{/* package-reference:end */}
