---
title: "@playstack/registry-swift"
description: "Swift Package Manager registry v1 read protocol over the registry core."
tags: ["package","infrastructure","registry","swift","pro"]
---

{/* package-access:start */}

> **Pro.** Covered by the Playstack Pro License. Registry access is required; check preview availability before installing. See [package access](/docs/packages#access-policy).

{/* package-access:end */}

`@playstack/registry-swift` implements the Swift Package Manager registry v1 read protocol over [`@playstack/registry`](/docs/packages/infrastructure/registry). It is a TypeScript server library, not a Swift client and not an npm-to-Swift proxy, and it adds no account, billing, or persistence authority.

{/* package-install:start */}

## Install

After confirming [preview access](/docs/packages#access-policy), install the package at your application's shared Playstack version:

```sh
npm install --save-exact @playstack/registry-swift@0.1.0-beta.1
```

Check the peer requirements below before choosing a runtime or provider.

{/* package-install:end */}

## Composition

```ts
import { createSwiftRegistryHandler } from '@playstack/registry-swift'
import { verifySwiftArchive } from '@playstack/registry-swift/node'
import { createRegistryStorage } from '@playstack/registry/storage'

const artifacts = createRegistryStorage({
  storage: privateStorageDriver,
  verifyTarball: (body, release, key, signal) => verifySwiftArchive(body, release, key, { signal }),
})

const handler = createSwiftRegistryHandler({
  registry,
  baseUrl: 'https://registry.playstack.dev/-/v1/swift',
  authenticate: authenticateAccountKey,
  resolvePackage: async (identity, principal) => resolveOwnedSwiftPackage(identity, principal),
  download: artifacts.download,
})
```

Use a separate namespace and route from npm, for example key `{ namespace: 'swift', name: 'playstack.licensingkit' }` for the Swift identity `playstack.licensingkit`. The resolver maps identities to host-owned keys; it does not grant access. The registry authorizes each catalog, version, manifest, and archive read with the current principal, filters frozen releases, and denies withdrawn versions.

## Protocol surface

GET and HEAD release lists, exact release metadata, canonical `Package.swift`, toolchain variant manifests, source ZIP downloads, optional authorized source-URL identifier lookup, Bearer and Basic account credentials, v1 headers, and problem details. URLs derive only from the configured `baseUrl`, never from incoming Host headers, and HTTPS is required outside explicit local development.

## Boundary

Namespace allocation, identity-to-plan mapping, and membership policy remain host-owned, as does publishing: this package reads.

{/* package-reference:start */}

## API entry points and requirements

Reference snapshot: `@playstack/registry-swift@0.1.0-beta.1`. Import only the entry point your runtime needs. Paths below are relative to the installed package; use **Go to Definition** in your editor to inspect exact parameters, return types and overloads. Do not import the declaration-file paths directly.

| Public entry point | Declaration file |
| --- | --- |
| `@playstack/registry-swift` | `./dist/index.d.ts` |
| `@playstack/registry-swift/node` | `./dist/node.d.ts` |
| `@playstack/registry-swift/package.json` | No TypeScript declaration (asset or metadata export). |

Node.js engine requirement: `>=20`. This is not a claim that every entry point works in browsers or Workers.

### Peer dependencies

Keep existing framework versions that satisfy these ranges. Install optional peers only when using the corresponding adapter. The package manager resolves ordinary dependencies separately.

| Peer | Compatible range | When needed |
| --- | --- | --- |
| `yauzl` | `^3.2.0` | Optional; only for the entry points that use it. |

For a complete first program, start with [Getting started](/docs/getting-started). For API lookup and partial-example conventions, see [Reading the reference](/docs/packages#reading-the-reference). Provider failures, lifecycle requirements and application responsibilities remain described in the guide above; types alone do not establish production safety.

{/* package-reference:end */}
