---
title: "@playstack/nest-entitlements"
description: "NestJS guards for explicit Playstack entitlement and limit enforcement."
tags: ["package","identity","nestjs","entitlements","guards","pro"]
---

{/* package-access:start */}

> **Pro.** Covered by the Playstack Pro License. Registry access is required; check preview availability before installing. See [package access](/docs/packages#access-policy).

{/* package-access:end */}

`@playstack/nest-entitlements` resolves a request subject and enforces named capabilities through NestJS guards. It does not authenticate requests or infer account context from route parameters.

```ts
PlaystackEntitlementsModule.forRoot({
  entitlements,
  resolveSubject: (request) => ({
    type: 'account',
    id: request.auth.account.id,
  }),
})

@UseGuards(PlaystackEntitlementsGuard)
@RequireEntitlements('packages.pro')
getProDownload() {}
```

Successful resolution is attached to `request.entitlementSubject`. Authentication, account scope, module ordering, and application-specific denial handling remain explicit composition concerns.

{/* package-install:start */}

## Install

After confirming [preview access](/docs/packages#access-policy), install the package at your application's shared Playstack version:

```sh
npm install --save-exact @playstack/nest-entitlements@0.1.0-beta.1
```

Check the peer requirements below before choosing a runtime or provider.

{/* package-install:end */}

{/* package-reference:start */}

## API entry points and requirements

Reference snapshot: `@playstack/nest-entitlements@0.1.0-beta.1`. Import only the entry point your runtime needs. Paths below are relative to the installed package; use **Go to Definition** in your editor to inspect exact parameters, return types and overloads. Do not import the declaration-file paths directly.

| Public entry point | Declaration file |
| --- | --- |
| `@playstack/nest-entitlements` | `./dist/index.d.ts` |
| `@playstack/nest-entitlements/package.json` | No TypeScript declaration (asset or metadata export). |

Node.js engine requirement: `>=20`. This is not a claim that every entry point works in browsers or Workers.

### Peer dependencies

Keep existing framework versions that satisfy these ranges. Install optional peers only when using the corresponding adapter. The package manager resolves ordinary dependencies separately.

| Peer | Compatible range | When needed |
| --- | --- | --- |
| `@nestjs/common` | `^10.0.0 \|\| ^11.0.0` | Required by the package. |
| `@nestjs/core` | `^10.0.0 \|\| ^11.0.0` | Required by the package. |
| `@playstack/entitlements` | `0.1.0-beta.1` | Required by the package. |
| `reflect-metadata` | `^0.1.13 \|\| ^0.2.0` | Required by the package. |
| `rxjs` | `^7.0.0` | Required by the package. |

For a complete first program, start with [Getting started](/docs/getting-started). For API lookup and partial-example conventions, see [Reading the reference](/docs/packages#reading-the-reference). Provider failures, lifecycle requirements and application responsibilities remain described in the guide above; types alone do not establish production safety.

{/* package-reference:end */}
