On this page
  1. Install
  2. Compose without adopting a billing or credential system
  3. Reads and downloads
  4. Boundary
  5. API entry points and requirements
  6. Peer dependencies

@playstack/registry

Portable private package registry core: immutable releases, exact reads, and host-owned access decisions.

Pro. Covered by the Playstack Pro License. Registry access is required; check preview availability before installing. See package access.

@playstack/registry is the portable private-registry core: immutable release registration, fenced publication claims, canonical manifests, exact reads, optimistic tag and visibility changes, and host-supplied release eligibility, with an optional read-only npm HTTP entry point, PostgreSQL persistence, bounded tarball inspection, and Playstack Storage composition. It serves registry.playstack.dev.

Install

After confirming preview access, install the package at your application's shared Playstack version:

sh
npm install --save-exact @playstack/registry@0.1.0-beta.1

Check the peer requirements below before choosing a runtime or provider.

Compose without adopting a billing or credential system

ts
import { createRegistry, canAccessRelease } from '@playstack/registry'

const registry = createRegistry({
  persistence, // application-owned RegistryPersistence
  clock,
  ids, // unpredictable claim IDs and tokens
  authorize, // verified principal + operation + optional exact release + transaction
  verifyArtifact, // bytes, size, hashes, canonical manifest, immutable storage
})

authorize is required on reads and mutations, including completed retries. The host authenticates before calling the service and owns live scope and resource policy. Account-owned packages require the principal's account to match the owner; shared packages have ownerAccountId: null, which is not anonymous authorization.

canAccessRelease(accountId, packageRecord, release, snapshot) evaluates a host-owned snapshot: an explicit package set with inclusive releasedThrough cutoffs plus exact-version administrative exceptions. That is how a subscription reaches the registry: the host projects the packages a plan earns through "now" while the subscription is active, freezes the cutoffs at lapse, and advances them on renewal. The core never loads billing projections, calculates grace, or infers tier names.

Reads and downloads

The npm entry point answers packuments, exact versions, and tarball downloads with private no-store headers, ETags, and a signed-redirect or streamed download policy chosen by the host. Withdrawn versions are denied whatever tags or exceptions say; rollback changes pointers, never bytes.

Boundary

Namespace allocation, credentials, subscriptions, and public routes belong to the host. @playstack/nest-registry supplies the Nest HTTP binding and @playstack/registry-swift the Swift Package Manager read protocol over the same core.

API entry points and requirements

Reference snapshot: @playstack/registry@0.1.0-beta.1. Import only the entry point your runtime needs. Paths below are relative to the installed package; use Go to Definition in your editor to inspect exact parameters, return types and overloads. Do not import the declaration-file paths directly.

Public entry pointDeclaration file
@playstack/registry./dist/index.d.ts
@playstack/registry/errors./dist/errors.d.ts
@playstack/registry/npm./dist/npm.d.ts
@playstack/registry/prisma./dist/prisma.d.ts
@playstack/registry/node./dist/node.d.ts
@playstack/registry/storage./dist/storage.d.ts
@playstack/registry/packer./dist/packer.d.ts
@playstack/registry/mirror./dist/mirror.d.ts
@playstack/registry/release./dist/release.d.ts
@playstack/registry/playstack.artifacts.jsonNo TypeScript declaration (asset or metadata export).
@playstack/registry/testing./dist/testing.d.ts
@playstack/registry/package.jsonNo TypeScript declaration (asset or metadata export).

Node.js engine requirement: >=20. This is not a claim that every entry point works in browsers or Workers.

Peer dependencies

Keep existing framework versions that satisfy these ranges. Install optional peers only when using the corresponding adapter. The package manager resolves ordinary dependencies separately.

PeerCompatible rangeWhen needed
@playstack/storage0.1.0-beta.1Optional; only for the entry points that use it.
tar-stream^3.2.0Optional; only for the entry points that use it.

For a complete first program, start with Getting started. For API lookup and partial-example conventions, see Reading the reference. Provider failures, lifecycle requirements and application responsibilities remain described in the guide above; types alone do not establish production safety.

Go

Playstack Pro tag
OriginsPricingBlogNewsletterChangelogStatusRoadmap
ContributorsCommunityIn Use ShowcaseCase StudiesPartnersSponsors
FAQsSupportContact

© 2026 Playstack. All rights reserved.

With OSS
Terms of ServicePrivacy PolicyCookie PolicyImprint

By

Commune Software