Repository navigation
packages api
Scope. Root Hono app for golden-path only. SentraBot's public API is
projects/product/sentrabot/apps/api(default127.0.0.1:3100). Kediri uses Payload inside its capsule. Do not import@safrs/apifrom a new capsule.
Typed HTTP boundary of the golden-path demo. @safrs/api owns the Hono application mounted under /api, the typed RPC client (hc from hono/client), the error envelope, and a schema-driven OpenAPI endpoint. It imports validation contracts from @safrs/schemas and database access from @safrs/database — never the other way around.
| File | Purpose |
|---|---|
packages/api/src/app.ts |
Hono app: routes, correlation-ID middleware, telemetry middleware, store injection |
packages/api/src/client.ts |
Typed RPC client factory (createApiClient) over AppType
|
packages/api/src/error.ts |
ApiError envelope builders (internalError, validationError) |
packages/api/src/openapi.ts |
buildOpenApiDocument + embedded Swagger UI HTML |
packages/api/src/index.ts |
Public barrel |
packages/api/package.json |
Depends on @safrs/database, @safrs/schemas, @safrs/telemetry, hono, zod
|
packages/api/src/app.ts builds the app from createRoutes:
- base path
/api - per request:
crypto.randomUUID()correlation ID stored in HonoVariablesand returned as thex-correlation-idheader -
telemetryMiddleware()from@safrs/telemetrystarts an OpenTelemetry span per request and attaches the correlation ID to it -
GET /api/health→{ status: "ok" } -
GET /api/openapi.json→ the generated OpenAPI 3.1 document -
GET /api/docs→ Swagger UI (CDN assets) pointing at the local document -
GET /api/demos→ all demo records, serialized throughdemoSchema -
POST /api/demos→ validated withzValidator("json", createDemoInputSchema, ...); on success creates a record via the injectedDemoStoreand returns201 -
.onError→ a500with the correlation-ID-bearinginternalErrorenvelope
The DemoStore interface ({ demo: { create, findMany } }) is injected, so tests can pass a fake store; createApp() defaults to the live @safrs/database client.
packages/api/src/error.ts implements apiErrorSchema:
-
INTERNAL_ERROR— generic 500 ("Terjadi kesalahan internal."), carries only the correlation ID. -
VALIDATION_ERROR— 400 withfieldErrorsderived fromz.flattenError, message "Permintaan tidak valid.".
No stacks, no database URLs, no server secrets are ever exposed.
packages/api/src/client.ts wraps hc<AppType>(...) so every consumer gets fully typed request/response contracts:
import { createApiClient } from "@safrs/api/client";
const client = createApiClient("http://localhost:3000");
const res = await client.api.demos.$post({ json: { name: "Example" } });GlobalErrorResponses adds the 500 envelope to the inferred AppType.
packages/api/src/openapi.ts builds an OpenAPI 3.1 document whose components are derived from the Zod schemas via Zod 4's z.toJSONSchema(...) (draft 2020-12), stripping the non-OpenAPI $schema key. Paths cover health, demos listing, and demo creation with proper $refs to ApiError, Demo, and CreateDemoInput.
-
@safrs/webmounts the app on the Node runtime and rides the typed client (see the web app). -
@safrs/schemassupplies all validation contracts; drift is structurally impossible. -
tools/codegengenerates an OpenAPI document and a typed fetch wrapper (createTypedClient) layered over@safrs/api/clientwith timeout and retry-on-network-error (tools/codegen/src/client.mjs). -
@safrs/telemetryprovides the request middleware used by the app.
pnpm --filter @safrs/api test
pnpm --filter @safrs/api typecheck
pnpm --filter @safrs/api lint- Schemas — the contracts this API validates against
- Database — default demo store
- Telemetry — request instrumentation
- Codegen tool — generated OpenAPI/client artifacts
- Shared packages
SAFRS — the Sentra Agent-First Repository Standard — defines how a software repository should be structured, governed, and enforced when autonomous Artificial Intelligence agents perform a substantial share of engineering work by Sentra Artificial Intelligence.
SAFRS v1.1 addresses that problem through five coupled mechanisms:
- a six-layer repository architecture from Trust Boundary to Human Authority;
- a role-based permission model in which capability never implies trust;
- a four-tier risk model with cumulative mandatory controls;
- a multi-agent execution protocol with explicit task states and one mutation owner per bounded scope;
- a knowledge governance model that distinguishes current architecture, historical decisions, execution plans, Git history, and running code.
Built in Indonesia as part of the Sentra Artificial Intelligence ecosystem.
Sentra Artificial Intelligence · Source Repository · Official Website
Dr Ferdi Iskandar — Creator & Maintainer
LinkedIn ·
ORCID ·
Hugging Face ·
Kaggle ·
Medium ·
Substack ·
X ·
Threads
MyPrompt · Sentra Artificial Intelligence · Indonesia
- SentraBot
- Kediri History
- Academic Smartboard
- Avery
- Portfolio Dr. Novia
- Golden Path (legacy demonstrator)
- Control Center
- Capsule template
- Risk model (R0–R3)
- Agent roles and permissions
- Capsule sovereignty
- Multi-agent protocol
- Document lifecycle
- Sensitive paths
- Verification integrity
Lore — how this repository grew
- Schemas (
@safrs/schemas) - Environment (
@safrs/env) - Database (
@safrs/database) - API (
@safrs/api) - UI (
@safrs/ui) - Telemetry (
@safrs/telemetry) - Token (
@sentra/token) - Config (
@safrs/config) - Auth (
packages/auth)
- SAFRS governance checkers
- SAFRS Automation Control Plane
- Gaffer Runtime
- Doctor
- Project wizard
- project-standalone
- Capabilities
- Codegen
- Deps-graph
- Status CLI
- Task CLI