{"_id":"@supabase/middleware","_rev":"7-6957514b8f8607fddd7576f49ed69201","name":"@supabase/middleware","dist-tags":{"latest":"0.6.0","rc":"0.6.0-rc.28"},"versions":{"0.2.0":{"name":"@supabase/middleware","version":"0.2.0","keywords":["middleware","fetch","edge","supabase"],"author":{"name":"supabase"},"license":"MIT","_id":"@supabase/middleware@0.2.0","maintainers":[{"name":"etienne_supa","email":"etienne@supabase.io"},{"name":"kiwicopple","email":"pcopplestone@gmail.com"},{"name":"ange1ico","email":"angelico.delosreyes@gmail.com"},{"name":"awalias","email":"antwilson@hotmail.co.uk"},{"name":"gregnr","email":"greg.nmr@gmail.com"},{"name":"phamhieu1998","email":"phamhieu1998@gmail.com"},{"name":"inian","email":"inian1234@gmail.com"},{"name":"stdim","email":"sdimitrovski@gmail.com"},{"name":"ziinc_supabase","email":"tzeyiing@supabase.com"},{"name":"mandarini","email":"katerina.skroumpelou@supabase.io"},{"name":"chase.cresgy","email":"chase.cresgy@supabase.io"},{"name":"dswbx","email":"dennis.senn@gmx.ch"},{"name":"ceeteelam","email":"charisxl@gmail.com"},{"name":"kevin-supabase","email":"kevin@supabase.com"},{"name":"mattrossman","email":"matthewjonrossman@gmail.com"}],"homepage":"https://github.com/supabase/middleware#readme","bugs":{"url":"https://github.com/supabase/middleware/issues"},"dist":{"shasum":"1a101f18a23c2ab5e2434579bcfa16444e76d1df","tarball":"https://registry.npmjs.org/@supabase/middleware/-/middleware-0.2.0.tgz","fileCount":20,"integrity":"sha512-I0jmML1BDXEh5PqrET56Rz2dmxDVhLsFd/I0ujUH47drNIt8zwIIl6B/PHx+gkimpyG8JhE+2KyMDiPd+yUi1A==","signatures":[{"sig":"MEUCIEKQ6JNMz+7YpCgjmXHQfsVZpkusb8GxBKqPRWEp4XmDAiEAwipcYPQpBKLRvY95gfC/W34CydxtfFXHbM3/YbW24Lk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":98111},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.cts","engines":{"node":">=22"},"exports":{".":{"import":{"types":"./dist/index.d.mts","default":"./dist/index.mjs"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}},"./cors":{"import":{"types":"./dist/middleware/cors/index.d.mts","default":"./dist/middleware/cors/index.mjs"},"require":{"types":"./dist/middleware/cors/index.d.cts","default":"./dist/middleware/cors/index.cjs"}},"./feature-flag":{"import":{"types":"./dist/middleware/feature-flag/index.d.mts","default":"./dist/middleware/feature-flag/index.mjs"},"require":{"types":"./dist/middleware/feature-flag/index.d.cts","default":"./dist/middleware/feature-flag/index.cjs"}},"./package.json":"./package.json"},"gitHead":"12e1ee7e23fe541faae1594cfbdc9d24a70d068b","scripts":{"dev":"tsdown --watch","docs":"typedoc","lint":"eslint src","test":"vitest run","build":"tsdown","smoke":"node scripts/smoke-load.mjs","format":"prettier --write .","prepare":"tsdown","lint:fix":"eslint src --fix","typecheck":"tsc --noEmit","test:watch":"vitest","check-exports":"attw --pack ."},"_npmUser":{"name":"mandarini","email":"katerina.skroumpelou@supabase.io"},"repository":{"url":"git+https://github.com/supabase/middleware.git","type":"git"},"_npmVersion":"10.9.7","description":"Composable, type-safe middleware for Web Fetch handlers. A middleware is a (config, handler) wrapper that runs against the inbound Request, contributes a typed key to ctx, and either short-circuits or falls through — the same shape across every runtime an","directories":{},"sideEffects":false,"_nodeVersion":"22.22.2","dependencies":{"std-env":"^4.2.0"},"_hasShrinkwrap":false,"packageManager":"pnpm@11.1.2+sha512.415a1cc25974731e75455c1468371be74c5aa5fb7621b50d4056d222451609f11412f23fd602e6169f1e060466641f798597e1be961a10688836a67b16569499","devDependencies":{"eslint":"^10.0.2","tsdown":"^0.20.3","vitest":"^4.0.18","typedoc":"^0.28.20","prettier":"3.8.1","typescript":"^5.9.3","typescript-eslint":"^8.56.1","@arethetypeswrong/cli":"^0.18.4"},"_npmOperationalInternal":{"tmp":"tmp/middleware_0.2.0_1786024407152_0.30743464171485324","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@supabase/middleware","version":"0.3.0","keywords":["middleware","fetch","edge","supabase"],"author":{"name":"supabase"},"license":"MIT","_id":"@supabase/middleware@0.3.0","maintainers":[{"name":"etienne_supa","email":"etienne@supabase.io"},{"name":"kiwicopple","email":"pcopplestone@gmail.com"},{"name":"ange1ico","email":"angelico.delosreyes@gmail.com"},{"name":"awalias","email":"antwilson@hotmail.co.uk"},{"name":"gregnr","email":"greg.nmr@gmail.com"},{"name":"phamhieu1998","email":"phamhieu1998@gmail.com"},{"name":"inian","email":"inian1234@gmail.com"},{"name":"stdim","email":"sdimitrovski@gmail.com"},{"name":"ziinc_supabase","email":"tzeyiing@supabase.com"},{"name":"mandarini","email":"katerina.skroumpelou@supabase.io"},{"name":"chase.cresgy","email":"chase.cresgy@supabase.io"},{"name":"dswbx","email":"dennis.senn@gmx.ch"},{"name":"ceeteelam","email":"charisxl@gmail.com"},{"name":"kevin-supabase","email":"kevin@supabase.com"},{"name":"mattrossman","email":"matthewjonrossman@gmail.com"}],"homepage":"https://github.com/supabase/middleware#readme","bugs":{"url":"https://github.com/supabase/middleware/issues"},"dist":{"shasum":"398c350d9452e6a5c2990fa6ef02008c38f981ef","tarball":"https://registry.npmjs.org/@supabase/middleware/-/middleware-0.3.0.tgz","fileCount":20,"integrity":"sha512-JN+dUr7Fyx96jfCUEXpzPEIpmkkogxHfII+fx7wWIiAUFI8C0lObDlzKIqrSVEKiFEK6CMsHWcqRarBQ8azCtw==","signatures":[{"sig":"MEYCIQCd1a0EsXiAJxv19LxcsnZ2q2LO0nod8JbeI99ibNIuOQIhANLJ+EQx3DHe9RbHoUtGh8xV8ATtuwkp82p6cuSkneiG","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@supabase%2fmiddleware@0.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":112175},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.cts","engines":{"node":">=22"},"exports":{".":{"import":{"types":"./dist/index.d.mts","default":"./dist/index.mjs"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}},"./cors":{"import":{"types":"./dist/middleware/cors/index.d.mts","default":"./dist/middleware/cors/index.mjs"},"require":{"types":"./dist/middleware/cors/index.d.cts","default":"./dist/middleware/cors/index.cjs"}},"./feature-flag":{"import":{"types":"./dist/middleware/feature-flag/index.d.mts","default":"./dist/middleware/feature-flag/index.mjs"},"require":{"types":"./dist/middleware/feature-flag/index.d.cts","default":"./dist/middleware/feature-flag/index.cjs"}},"./package.json":"./package.json"},"gitHead":"98eb5b29634e954bed2c551d2eeb250a211ce6de","scripts":{"dev":"tsdown --watch","docs":"typedoc","lint":"eslint src","test":"vitest run","build":"tsdown","smoke":"node scripts/smoke-load.mjs","format":"prettier --write .","prepare":"tsdown","lint:fix":"eslint src --fix","typecheck":"tsc --noEmit","test:watch":"vitest","check-exports":"attw --pack ."},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:de288a05-47ab-423f-b36d-a17675c67c21"}},"repository":{"url":"git+https://github.com/supabase/middleware.git","type":"git"},"_npmVersion":"12.0.2","description":"Composable, type-safe middleware for Web Fetch handlers. A middleware is a (config, handler) wrapper that runs against the inbound Request, contributes a typed key to ctx, and either short-circuits or falls through — the same shape across every runtime an","directories":{},"sideEffects":false,"_nodeVersion":"22.23.1","dependencies":{"std-env":"^4.2.0"},"_hasShrinkwrap":false,"packageManager":"pnpm@11.1.2+sha512.415a1cc25974731e75455c1468371be74c5aa5fb7621b50d4056d222451609f11412f23fd602e6169f1e060466641f798597e1be961a10688836a67b16569499","devDependencies":{"eslint":"^10.0.2","tsdown":"^0.20.3","vitest":"^4.0.18","typedoc":"^0.28.20","prettier":"3.8.1","typescript":"^5.9.3","typescript-eslint":"^8.56.1","@arethetypeswrong/cli":"^0.18.4"},"_npmOperationalInternal":{"tmp":"tmp/middleware_0.3.0_1786433703336_0.6483537033684701","host":"s3://npm-registry-packages-npm-production"}},"0.3.1":{"name":"@supabase/middleware","version":"0.3.1","keywords":["middleware","fetch","edge","supabase"],"author":{"name":"supabase"},"license":"MIT","_id":"@supabase/middleware@0.3.1","maintainers":[{"name":"etienne_supa","email":"etienne@supabase.io"},{"name":"kiwicopple","email":"pcopplestone@gmail.com"},{"name":"ange1ico","email":"angelico.delosreyes@gmail.com"},{"name":"awalias","email":"antwilson@hotmail.co.uk"},{"name":"gregnr","email":"greg.nmr@gmail.com"},{"name":"phamhieu1998","email":"phamhieu1998@gmail.com"},{"name":"inian","email":"inian1234@gmail.com"},{"name":"stdim","email":"sdimitrovski@gmail.com"},{"name":"ziinc_supabase","email":"tzeyiing@supabase.com"},{"name":"mandarini","email":"katerina.skroumpelou@supabase.io"},{"name":"chase.cresgy","email":"chase.cresgy@supabase.io"},{"name":"dswbx","email":"dennis.senn@gmx.ch"},{"name":"ceeteelam","email":"charisxl@gmail.com"},{"name":"kevin-supabase","email":"kevin@supabase.com"},{"name":"mattrossman","email":"matthewjonrossman@gmail.com"}],"homepage":"https://github.com/supabase/middleware#readme","bugs":{"url":"https://github.com/supabase/middleware/issues"},"dist":{"shasum":"898b63b509c5640ad193ff489fde06698f914984","tarball":"https://registry.npmjs.org/@supabase/middleware/-/middleware-0.3.1.tgz","fileCount":27,"integrity":"sha512-ssU8dSgRkKJwwT8AaAno4HDrXs0iD4ocNKDPeBGmi3KIQNtjXZrW4ae4NAPg5O75xHkheOfrZPeXhH2edwgeRw==","signatures":[{"sig":"MEUCIBzsuTbk3Nzg2ipfZUKX1cyYuMdHh41SBX+KalN+tJYfAiEA+KrvdK/fzerNcXC5WFpUmRZLZ4PRMJq9AQFFr2jMjE8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIHVXvXugXpMtzoIkLp4+6FKzoHVbebeLr/YYZE0UGIgTAiBdUJK71DxnBA6HtTCYe6BGDfsgIqDzLzDjLsmVttNoWw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@supabase%2fmiddleware@0.3.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":194296},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.cts","engines":{"node":">=22"},"exports":{".":{"import":{"types":"./dist/index.d.mts","default":"./dist/index.mjs"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}},"./cors":{"import":{"types":"./dist/middleware/cors/index.d.mts","default":"./dist/middleware/cors/index.mjs"},"require":{"types":"./dist/middleware/cors/index.d.cts","default":"./dist/middleware/cors/index.cjs"}},"./feature-flag":{"import":{"types":"./dist/middleware/feature-flag/index.d.mts","default":"./dist/middleware/feature-flag/index.mjs"},"require":{"types":"./dist/middleware/feature-flag/index.d.cts","default":"./dist/middleware/feature-flag/index.cjs"}},"./package.json":"./package.json"},"gitHead":"5a71a3c4c9e9d35f7d86718da658f7c3b383bc3e","scripts":{"dev":"tsdown --watch","docs":"typedoc","lint":"eslint src","test":"vitest run","build":"tsdown","smoke":"node scripts/smoke-load.mjs","format":"prettier --write .","prepare":"tsdown","lint:fix":"eslint src --fix","typecheck":"tsc --noEmit","test:watch":"vitest","format:check":"prettier --check .","check-exports":"attw --pack .","typecheck:min":"pnpm --dir test/ts-floor install --ignore-workspace && pnpm --dir test/ts-floor exec tsc --noEmit --project ../../tsconfig.json","typecheck:consumer":"pnpm --dir test/ts-floor install --ignore-workspace && pnpm --dir test/ts-floor exec tsc --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:de288a05-47ab-423f-b36d-a17675c67c21"}},"repository":{"url":"git+https://github.com/supabase/middleware.git","type":"git"},"_npmVersion":"12.0.2","description":"Composable, type-safe middleware for Web Fetch handlers. A middleware is a (config, handler) wrapper that runs against the inbound Request, contributes a typed key to ctx, and either short-circuits or falls through — the same shape across every runtime an","directories":{},"sideEffects":false,"_nodeVersion":"22.23.2","dependencies":{"std-env":"^4.2.0"},"_hasShrinkwrap":false,"packageManager":"pnpm@11.1.2+sha512.415a1cc25974731e75455c1468371be74c5aa5fb7621b50d4056d222451609f11412f23fd602e6169f1e060466641f798597e1be961a10688836a67b16569499","devDependencies":{"eslint":"^10.0.2","tsdown":"^0.20.3","vitest":"^4.0.18","typedoc":"^0.28.20","prettier":"3.8.1","typescript":"^5.9.3","typescript-eslint":"^8.56.1","@arethetypeswrong/cli":"^0.18.4"},"peerDependencies":{"typescript":">=5.4"},"peerDependenciesMeta":{"typescript":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/middleware_0.3.1_1787585432435_0.8415875775673625","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@supabase/middleware","version":"0.4.0","keywords":["middleware","fetch","edge","supabase"],"author":{"name":"supabase"},"license":"MIT","_id":"@supabase/middleware@0.4.0","maintainers":[{"name":"etienne_supa","email":"etienne@supabase.io"},{"name":"kiwicopple","email":"pcopplestone@gmail.com"},{"name":"ange1ico","email":"angelico.delosreyes@gmail.com"},{"name":"awalias","email":"antwilson@hotmail.co.uk"},{"name":"gregnr","email":"greg.nmr@gmail.com"},{"name":"phamhieu1998","email":"phamhieu1998@gmail.com"},{"name":"inian","email":"inian1234@gmail.com"},{"name":"stdim","email":"sdimitrovski@gmail.com"},{"name":"ziinc_supabase","email":"tzeyiing@supabase.com"},{"name":"mandarini","email":"katerina.skroumpelou@supabase.io"},{"name":"chase.cresgy","email":"chase.cresgy@supabase.io"},{"name":"dswbx","email":"dennis.senn@gmx.ch"},{"name":"ceeteelam","email":"charisxl@gmail.com"},{"name":"kevin-supabase","email":"kevin@supabase.com"},{"name":"mattrossman","email":"matthewjonrossman@gmail.com"}],"homepage":"https://github.com/supabase/middleware#readme","bugs":{"url":"https://github.com/supabase/middleware/issues"},"dist":{"shasum":"baea2fb0e86fa750fa2ec327b2d48f953977b65e","tarball":"https://registry.npmjs.org/@supabase/middleware/-/middleware-0.4.0.tgz","fileCount":27,"integrity":"sha512-iGDAzSQVKRzaKkcbap4G9C20NWc6MYXNht2Mgg7dkY1E8H3Y4bsR7UlWiaL1sbMkgVO/qS0GnrEEXPnzzBXd0A==","signatures":[{"sig":"MEUCIQCK8L+/Qih44TdQOAykV2AxLbYvD+LlxvJIuunOkztuJgIgQaRBkNP9T45YHTT62va4V8dDfqPXwRSjZ8Q+2PPwVQ4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIBNiNg2Yt2rMi+8oyys+MnZjrtPqu7jj/pfxZEXZglmDAiBSFQmLw7n/GmIJTBgwJsf6ijQgTcf99xhGpmC87uLzhA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@supabase%2fmiddleware@0.4.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":195762},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.cts","engines":{"node":">=22"},"exports":{".":{"import":{"types":"./dist/index.d.mts","default":"./dist/index.mjs"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}},"./cors":{"import":{"types":"./dist/middleware/cors/index.d.mts","default":"./dist/middleware/cors/index.mjs"},"require":{"types":"./dist/middleware/cors/index.d.cts","default":"./dist/middleware/cors/index.cjs"}},"./feature-flag":{"import":{"types":"./dist/middleware/feature-flag/index.d.mts","default":"./dist/middleware/feature-flag/index.mjs"},"require":{"types":"./dist/middleware/feature-flag/index.d.cts","default":"./dist/middleware/feature-flag/index.cjs"}},"./package.json":"./package.json"},"gitHead":"1cfbd55b086a1b2515f36076e81f83e337cde0ca","scripts":{"dev":"tsdown --watch","docs":"typedoc","lint":"eslint src","test":"vitest run","build":"tsdown","smoke":"node scripts/smoke-load.mjs","format":"prettier --write .","prepare":"tsdown","lint:fix":"eslint src --fix","typecheck":"tsc --noEmit","test:watch":"vitest","format:check":"prettier --check .","check-exports":"attw --pack .","typecheck:min":"pnpm --dir test/ts-floor install --ignore-workspace && pnpm --dir test/ts-floor exec tsc --noEmit --project ../../tsconfig.json","typecheck:consumer":"pnpm --dir test/ts-floor install --ignore-workspace && pnpm --dir test/ts-floor exec tsc --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:de288a05-47ab-423f-b36d-a17675c67c21"}},"repository":{"url":"git+https://github.com/supabase/middleware.git","type":"git"},"_npmVersion":"12.0.2","description":"Composable, type-safe middleware for Web Fetch handlers. A middleware is a (config, handler) wrapper that runs against the inbound Request, contributes a typed key to ctx, and either short-circuits or falls through — the same shape across every runtime an","directories":{},"sideEffects":false,"_nodeVersion":"22.23.2","dependencies":{"std-env":"^4.2.0"},"_hasShrinkwrap":false,"packageManager":"pnpm@11.1.2+sha512.415a1cc25974731e75455c1468371be74c5aa5fb7621b50d4056d222451609f11412f23fd602e6169f1e060466641f798597e1be961a10688836a67b16569499","devDependencies":{"eslint":"^10.0.2","tsdown":"^0.20.3","vitest":"^4.0.18","typedoc":"^0.28.20","prettier":"3.8.1","typescript":"^5.9.3","typescript-eslint":"^8.56.1","@arethetypeswrong/cli":"^0.18.4"},"peerDependencies":{"typescript":">=5.4"},"peerDependenciesMeta":{"typescript":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/middleware_0.4.0_1787736837173_0.807618710356619","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@supabase/middleware","version":"0.5.0","keywords":["middleware","fetch","edge","supabase"],"author":{"name":"supabase"},"license":"MIT","_id":"@supabase/middleware@0.5.0","maintainers":[{"name":"etienne_supa","email":"etienne@supabase.io"},{"name":"kiwicopple","email":"pcopplestone@gmail.com"},{"name":"ange1ico","email":"angelico.delosreyes@gmail.com"},{"name":"awalias","email":"antwilson@hotmail.co.uk"},{"name":"gregnr","email":"greg.nmr@gmail.com"},{"name":"phamhieu1998","email":"phamhieu1998@gmail.com"},{"name":"inian","email":"inian1234@gmail.com"},{"name":"stdim","email":"sdimitrovski@gmail.com"},{"name":"ziinc_supabase","email":"tzeyiing@supabase.com"},{"name":"mandarini","email":"katerina.skroumpelou@supabase.io"},{"name":"chase.cresgy","email":"chase.cresgy@supabase.io"},{"name":"dswbx","email":"dennis.senn@gmx.ch"},{"name":"ceeteelam","email":"charisxl@gmail.com"},{"name":"kevin-supabase","email":"kevin@supabase.com"},{"name":"mattrossman","email":"matthewjonrossman@gmail.com"}],"homepage":"https://github.com/supabase/middleware#readme","bugs":{"url":"https://github.com/supabase/middleware/issues"},"dist":{"shasum":"0850466fed4b31c80cb372b09d35078ac4b73d57","tarball":"https://registry.npmjs.org/@supabase/middleware/-/middleware-0.5.0.tgz","fileCount":27,"integrity":"sha512-OjukUo+5p14zxTuylf2zVg1hZCHWKLO6VrZhtVeQQw09yrVo3GAduvFJPiFDhTAz/Du1ZfEzAR+s6aRAWD5wzQ==","signatures":[{"sig":"MEUCIHyB4hiFUgkJuSUPMthh0AQv/ht89zPx0e7bAw8rhubsAiEA9I5KX7ugh+plfKdspMxepHzn3H/U+Lp/l29cocgRfa0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQD8lT9giiCqQ4X1OabXtyL3r77/e7QfXkn0AL0+89xHhAIhAK9S4BtGJteh3/Lm9j4CIZa+RAjTxVslubVfse1LaRqr","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@supabase%2fmiddleware@0.5.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":233532},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.cts","engines":{"node":">=22"},"exports":{".":{"import":{"types":"./dist/index.d.mts","default":"./dist/index.mjs"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}},"./cors":{"import":{"types":"./dist/middleware/cors/index.d.mts","default":"./dist/middleware/cors/index.mjs"},"require":{"types":"./dist/middleware/cors/index.d.cts","default":"./dist/middleware/cors/index.cjs"}},"./feature-flag":{"import":{"types":"./dist/middleware/feature-flag/index.d.mts","default":"./dist/middleware/feature-flag/index.mjs"},"require":{"types":"./dist/middleware/feature-flag/index.d.cts","default":"./dist/middleware/feature-flag/index.cjs"}},"./package.json":"./package.json"},"gitHead":"b0ee50a758d8ec38adf96769bfeaa8d399bab13d","scripts":{"dev":"tsdown --watch","docs":"typedoc","lint":"eslint src","test":"vitest run","build":"tsdown","smoke":"node scripts/smoke-load.mjs","format":"prettier --write .","prepare":"tsdown","lint:fix":"eslint src --fix","typecheck":"tsc --noEmit","test:watch":"vitest","format:check":"prettier --check .","check-exports":"attw --pack .","typecheck:min":"pnpm --dir test/ts-floor install --ignore-workspace && pnpm --dir test/ts-floor exec tsc --noEmit --project ../../tsconfig.json","typecheck:consumer":"pnpm --dir test/ts-floor install --ignore-workspace && pnpm --dir test/ts-floor exec tsc --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:de288a05-47ab-423f-b36d-a17675c67c21"}},"repository":{"url":"git+https://github.com/supabase/middleware.git","type":"git"},"_npmVersion":"12.0.2","description":"Composable, type-safe middleware for Web Fetch handlers. A middleware is a (config, handler) wrapper that runs against the inbound Request, contributes a typed key to ctx, and either short-circuits or falls through — the same shape across every runtime an","directories":{},"sideEffects":false,"_nodeVersion":"22.23.2","dependencies":{"std-env":"^4.2.0"},"_hasShrinkwrap":false,"packageManager":"pnpm@11.1.2+sha512.415a1cc25974731e75455c1468371be74c5aa5fb7621b50d4056d222451609f11412f23fd602e6169f1e060466641f798597e1be961a10688836a67b16569499","devDependencies":{"eslint":"^10.0.2","tsdown":"^0.20.3","vitest":"^4.0.18","typedoc":"^0.28.20","prettier":"3.8.1","typescript":"^5.9.3","typescript-eslint":"^8.56.1","@arethetypeswrong/cli":"^0.18.4"},"peerDependencies":{"typescript":">=5.4"},"peerDependenciesMeta":{"typescript":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/middleware_0.5.0_1788524866735_0.31779114672063935","host":"s3://npm-registry-packages-npm-production"}},"0.6.0-rc.28":{"name":"@supabase/middleware","version":"0.6.0-rc.28","keywords":["middleware","fetch","edge","supabase"],"author":{"name":"supabase"},"license":"MIT","_id":"@supabase/middleware@0.6.0-rc.28","maintainers":[{"name":"etienne_supa","email":"etienne@supabase.io"},{"name":"kiwicopple","email":"pcopplestone@gmail.com"},{"name":"ange1ico","email":"angelico.delosreyes@gmail.com"},{"name":"awalias","email":"antwilson@hotmail.co.uk"},{"name":"gregnr","email":"greg.nmr@gmail.com"},{"name":"phamhieu1998","email":"phamhieu1998@gmail.com"},{"name":"inian","email":"inian1234@gmail.com"},{"name":"stdim","email":"sdimitrovski@gmail.com"},{"name":"ziinc_supabase","email":"tzeyiing@supabase.com"},{"name":"mandarini","email":"katerina.skroumpelou@supabase.io"},{"name":"chase.cresgy","email":"chase.cresgy@supabase.io"},{"name":"dswbx","email":"dennis.senn@gmx.ch"},{"name":"ceeteelam","email":"charisxl@gmail.com"},{"name":"kevin-supabase","email":"kevin@supabase.com"},{"name":"mattrossman","email":"matthewjonrossman@gmail.com"}],"homepage":"https://github.com/supabase/middleware#readme","bugs":{"url":"https://github.com/supabase/middleware/issues"},"dist":{"shasum":"647ccb6bb5918cef4efba97f0d22a7fb31e7bb9c","tarball":"https://registry.npmjs.org/@supabase/middleware/-/middleware-0.6.0-rc.28.tgz","fileCount":27,"integrity":"sha512-aR+o/PRwNNAOwva+9LHQG6VVpphiRXAQHmIZhL8vE4/FqUntnHPpwViseMjFezUOSMbHOEevtNxxP9507FlXEQ==","signatures":[{"sig":"MEYCIQCyJ8kKm5snMqwl6TyTHkXYCsRp2CFqO8jINXkqz4OTWgIhAM5QxQdKMYcUMzeeDesVzqDZNsq4A7F/vakSdwy3goE6","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQDGxwAgc1xHBL/lLiMJDPPhx8fzoh8zB9xCUEIAlzOvtAIgb6ZzAdwZNkGkGiGRYE2LvC9EQRKF7XTUTtR8qGTRMFs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@supabase%2fmiddleware@0.6.0-rc.28","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":255825},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.cts","engines":{"node":">=22"},"exports":{".":{"import":{"types":"./dist/index.d.mts","default":"./dist/index.mjs"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}},"./cors":{"import":{"types":"./dist/middleware/cors/index.d.mts","default":"./dist/middleware/cors/index.mjs"},"require":{"types":"./dist/middleware/cors/index.d.cts","default":"./dist/middleware/cors/index.cjs"}},"./feature-flag":{"import":{"types":"./dist/middleware/feature-flag/index.d.mts","default":"./dist/middleware/feature-flag/index.mjs"},"require":{"types":"./dist/middleware/feature-flag/index.d.cts","default":"./dist/middleware/feature-flag/index.cjs"}},"./package.json":"./package.json"},"gitHead":"fd5e805303867fcaf3cd19732a867b8c46d751c0","scripts":{"dev":"tsdown --watch","docs":"typedoc","lint":"eslint src","test":"vitest run","build":"tsdown","smoke":"node scripts/smoke-load.mjs","format":"prettier --write .","prepare":"tsdown","lint:fix":"eslint src --fix","test:bun":"bun test test/runtimes/bun","test:deno":"deno test --no-check --allow-env --allow-net test/runtimes/deno","typecheck":"tsc --noEmit","test:watch":"vitest","format:check":"prettier --check .","test:workers":"pnpm --dir test/runtimes/workers install && pnpm --dir test/runtimes/workers exec vitest run","check-exports":"attw --pack .","typecheck:min":"pnpm --dir test/ts-floor install --ignore-workspace && pnpm --dir test/ts-floor exec tsc --noEmit --project ../../tsconfig.json","typecheck:consumer":"pnpm --dir test/ts-floor install --ignore-workspace && pnpm --dir test/ts-floor exec tsc --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:de288a05-47ab-423f-b36d-a17675c67c21"}},"repository":{"url":"git+https://github.com/supabase/middleware.git","type":"git"},"_npmVersion":"12.0.2","description":"Composable, type-safe middleware for Web Fetch handlers. A middleware is a (config, handler) wrapper that runs against the inbound Request, contributes a typed key to ctx, and either short-circuits or falls through — the same shape across every runtime an","directories":{},"sideEffects":false,"_nodeVersion":"22.23.2","dependencies":{"std-env":"^4.2.0"},"_hasShrinkwrap":false,"packageManager":"pnpm@11.1.2+sha512.415a1cc25974731e75455c1468371be74c5aa5fb7621b50d4056d222451609f11412f23fd602e6169f1e060466641f798597e1be961a10688836a67b16569499","readmeFilename":"README.md","devDependencies":{"eslint":"^10.0.2","tsdown":"^0.20.3","vitest":"^4.0.18","typedoc":"^0.28.20","prettier":"3.8.1","typescript":"^5.9.3","typescript-eslint":"^8.56.1","@arethetypeswrong/cli":"^0.18.4"},"peerDependencies":{"typescript":">=5.4"},"peerDependenciesMeta":{"typescript":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/middleware_0.6.0-rc.28_1789738257649_0.3408856683399697","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"_id":"@supabase/middleware@0.6.0","bugs":{"url":"https://github.com/supabase/middleware/issues"},"dist":{"shasum":"c3506e4996753cc3a2ff2b8692ad0df6d9d76c18","tarball":"https://registry.npmjs.org/@supabase/middleware/-/middleware-0.6.0.tgz","fileCount":27,"integrity":"sha512-0uMdGQLGz7KOxnqYgHaj5ZRjeB8mzqUrkKWjJhdQPns5vJ8bVVyJQ9wOwLaJgxFHO/q0rfPtLisff7DH/nBJeA==","signatures":[{"sig":"MEYCIQD/01ZjZjk4SgGAArhwdhMhva3DU0URLBM1QOuxKe3shQIhAOdhKsrnBqlMlb/g24dmfYf544kw3iOo+iIbqlq8kPAR","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDwfGXzaPfuAy70wQrRd1TvY3VkObPIL/fx9fJY7Y1GMQIgUF62Ave34tdizfFYJ4md1gT3Zzt9jjTRVwJqxb5I200="}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@supabase%2fmiddleware@0.6.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":255819},"main":"./dist/index.cjs","name":"@supabase/middleware","type":"module","types":"./dist/index.d.cts","author":{"name":"supabase"},"engines":{"node":">=22"},"exports":{".":{"import":{"types":"./dist/index.d.mts","default":"./dist/index.mjs"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}},"./cors":{"import":{"types":"./dist/middleware/cors/index.d.mts","default":"./dist/middleware/cors/index.mjs"},"require":{"types":"./dist/middleware/cors/index.d.cts","default":"./dist/middleware/cors/index.cjs"}},"./feature-flag":{"import":{"types":"./dist/middleware/feature-flag/index.d.mts","default":"./dist/middleware/feature-flag/index.mjs"},"require":{"types":"./dist/middleware/feature-flag/index.d.cts","default":"./dist/middleware/feature-flag/index.cjs"}},"./package.json":"./package.json"},"gitHead":"751b3064393e3bff83c5f84e68ad12caf75b350e","license":"MIT","scripts":{"dev":"tsdown --watch","docs":"typedoc","lint":"eslint src","test":"vitest run","build":"tsdown","smoke":"node scripts/smoke-load.mjs","format":"prettier --write .","prepare":"tsdown","lint:fix":"eslint src --fix","test:bun":"bun test test/runtimes/bun","test:deno":"deno test --no-check --allow-env --allow-net test/runtimes/deno","typecheck":"tsc --noEmit","test:watch":"vitest","format:check":"prettier --check .","test:workers":"pnpm --dir test/runtimes/workers install && pnpm --dir test/runtimes/workers exec vitest run","check-exports":"attw --pack .","typecheck:min":"pnpm --dir test/ts-floor install --ignore-workspace && pnpm --dir test/ts-floor exec tsc --noEmit --project ../../tsconfig.json","typecheck:consumer":"pnpm --dir test/ts-floor install --ignore-workspace && pnpm --dir test/ts-floor exec tsc --noEmit"},"version":"0.6.0","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:de288a05-47ab-423f-b36d-a17675c67c21"}},"homepage":"https://github.com/supabase/middleware#readme","keywords":["middleware","fetch","edge","supabase"],"repository":{"url":"git+https://github.com/supabase/middleware.git","type":"git"},"_npmVersion":"12.0.2","description":"Composable, type-safe middleware for Web Fetch handlers. A middleware is a (config, handler) wrapper that runs against the inbound Request, contributes a typed key to ctx, and either short-circuits or falls through — the same shape across every runtime an","directories":{},"maintainers":[{"name":"etienne_supa","email":"etienne@supabase.io"},{"name":"kiwicopple","email":"pcopplestone@gmail.com"},{"name":"ange1ico","email":"angelico.delosreyes@gmail.com"},{"name":"awalias","email":"antwilson@hotmail.co.uk"},{"name":"gregnr","email":"greg.nmr@gmail.com"},{"name":"phamhieu1998","email":"phamhieu1998@gmail.com"},{"name":"inian","email":"inian1234@gmail.com"},{"name":"stdim","email":"sdimitrovski@gmail.com"},{"name":"ziinc_supabase","email":"tzeyiing@supabase.com"},{"name":"mandarini","email":"katerina.skroumpelou@supabase.io"},{"name":"chase.cresgy","email":"chase.cresgy@supabase.io"},{"name":"dswbx","email":"dennis.senn@gmx.ch"},{"name":"ceeteelam","email":"charisxl@gmail.com"},{"name":"kevin-supabase","email":"kevin@supabase.com"},{"name":"mattrossman","email":"matthewjonrossman@gmail.com"}],"sideEffects":false,"_nodeVersion":"22.23.2","dependencies":{"std-env":"^4.2.0"},"_hasShrinkwrap":false,"packageManager":"pnpm@11.1.2+sha512.415a1cc25974731e75455c1468371be74c5aa5fb7621b50d4056d222451609f11412f23fd602e6169f1e060466641f798597e1be961a10688836a67b16569499","devDependencies":{"eslint":"^10.0.2","tsdown":"^0.20.3","vitest":"^4.0.18","typedoc":"^0.28.20","prettier":"3.8.1","typescript":"^5.9.3","typescript-eslint":"^8.56.1","@arethetypeswrong/cli":"^0.18.4"},"peerDependencies":{"typescript":">=5.4"},"peerDependenciesMeta":{"typescript":{"optional":true}},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/middleware_0.6.0_1790000886104_0.44100524571405986"}}},"time":{"created":"2026-08-06T13:53:27.020Z","modified":"2026-09-21T14:28:06.598Z","0.2.0":"2026-08-06T13:53:27.319Z","0.3.0":"2026-08-11T07:35:03.469Z","0.3.1":"2026-08-24T15:30:32.518Z","0.4.0":"2026-08-26T09:33:57.258Z","0.5.0":"2026-09-04T12:27:46.853Z","0.6.0-rc.28":"2026-09-18T13:30:57.749Z","0.6.0":"2026-09-21T14:28:06.205Z"},"bugs":{"url":"https://github.com/supabase/middleware/issues"},"author":{"name":"supabase"},"license":"MIT","homepage":"https://github.com/supabase/middleware#readme","keywords":["middleware","fetch","edge","supabase"],"repository":{"url":"git+https://github.com/supabase/middleware.git","type":"git"},"description":"Composable, type-safe middleware for Web Fetch handlers. A middleware is a (config, handler) wrapper that runs against the inbound Request, contributes a typed key to ctx, and either short-circuits or falls through — the same shape across every runtime an","maintainers":[{"name":"etienne_supa","email":"etienne@supabase.io"},{"name":"kiwicopple","email":"pcopplestone@gmail.com"},{"name":"ange1ico","email":"angelico.delosreyes@gmail.com"},{"name":"awalias","email":"antwilson@hotmail.co.uk"},{"name":"gregnr","email":"greg.nmr@gmail.com"},{"name":"phamhieu1998","email":"phamhieu1998@gmail.com"},{"name":"inian","email":"inian1234@gmail.com"},{"name":"stdim","email":"sdimitrovski@gmail.com"},{"name":"ziinc_supabase","email":"tzeyiing@supabase.com"},{"name":"mandarini","email":"katerina.skroumpelou@supabase.io"},{"name":"chase.cresgy","email":"chase.cresgy@supabase.io"},{"name":"dswbx","email":"dennis.senn@gmx.ch"},{"name":"ceeteelam","email":"charisxl@gmail.com"},{"name":"kevin-supabase","email":"kevin@supabase.com"},{"name":"mattrossman","email":"matthewjonrossman@gmail.com"}],"readme":"# `@supabase/middleware`\n\n[![License: MIT](https://img.shields.io/badge/license-MIT-blue.svg)](./LICENSE)\n[![Package](https://img.shields.io/npm/v/@supabase/middleware)](https://www.npmjs.com/package/@supabase/middleware)\n[![pkg.pr.new](https://pkg.pr.new/badge/supabase/middleware)](https://pkg.pr.new/~/supabase/middleware)\n[![Docs](https://img.shields.io/badge/docs-supabase.github.io-3ECF8E?logo=readthedocs&logoColor=white)](https://supabase.github.io/middleware/)\n\nComposable, type-safe middleware for Web Fetch handlers.\n\n> **Status: public alpha.** The core engine and API are still settling — expect breaking changes before a stable 1.0. The badge above tracks the current release; follow [releases](https://github.com/supabase/middleware/releases) for changes.\n\nA **middleware** is a `withFoo` function. Call it with just the config — `withFoo(config)` — to get an **`Entry`**: a typed placeholder that carries the middleware's key, prerequisites, and contribution as phantom types. Pass a flat array of entries to `pipeline` with a final handler; `pipeline` folds the array into nested calls at runtime and every entry's contribution lands on `ctx` in order. No registry, no `app.use()`, no nesting.\n\n```ts\nimport { pipeline } from '@supabase/middleware'\nimport { withCors } from '@supabase/middleware/cors'\nimport { withFeatureFlag } from '@supabase/middleware/feature-flag'\n\nexport default {\n  fetch: pipeline(\n    [\n      withCors({}),\n      withFeatureFlag({\n        name: 'beta',\n        evaluate: (req) => req.headers.has('x-beta'),\n      }),\n    ],\n    async (_req, ctx) => Response.json({ flag: ctx.featureFlag.name }),\n  ),\n}\n```\n\n`pipeline` returns the outermost `(req, ctx) => Response` — **that is the `fetch` handler directly**, no wrapper. When the runtime invokes it, the framework detects a platform argument (Deno's connection info, a Workers `env`) and seeds a fresh context itself, so platform values never leak into `ctx` — the Workers env is captured behind the importable `getEnv` instead. Because everything is plain Web Fetch, the same stack runs unchanged across Deno, Cloudflare Workers, Bun, and Node.\n\n## Install\n\n```sh\n# npm\nnpm install @supabase/middleware\n\n# pnpm\npnpm add @supabase/middleware\n\n# Deno / Supabase Edge Functions (no install — import directly)\nimport { pipeline } from \"npm:@supabase/middleware\"\n```\n\nAlso published on [JSR](https://jsr.io/@supabase/middleware):\n\n```sh\ndeno add jsr:@supabase/middleware\n```\n\n### Requirements\n\n- **TypeScript 5.4 or newer.** The published types use [`NoInfer`](https://www.typescriptlang.org/docs/handbook/utility-types.html#noinfertype), a 5.4 intrinsic, to keep the accumulated `ctx` flowing inward through nested middleware. This floor applies to typechecking against the shipped `.d.ts` only — the runtime is plain JavaScript with no TypeScript dependency.\n- **Node 22 or newer** on Node (per `engines`). Deno, Bun, and Cloudflare Workers add no floor of their own.\n\n## What's in the box\n\n| Import                              | What it does                                                                                                                                                   |\n| ----------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------- |\n| `@supabase/middleware`              | `pipeline`, `defineMiddleware`, `getEnv`, `runtimeName`, `seedContext`, `isContext`, and the core types: `Entry`, `FetchHandler`, `Middleware`, `BaseContext`. |\n| `@supabase/middleware/feature-flag` | Provider-agnostic feature flag — admit or short-circuit per request.                                                                                           |\n| `@supabase/middleware/cors`         | CORS — answers preflight and stamps response headers (the worked example of the response seam).                                                                |\n\n## Bundling several into one\n\nA middleware contributes one key. When a unit of behavior owns several and\nshould still compose as one thing, `defineComposite` builds it from single-key\nparts and derives its contributions from theirs — so it nests _and_ drops into a\n`pipeline` array from one declaration, and every key still traces to exactly one\n`defineMiddleware` call. See the\n[authoring guide](docs/authoring-guide.md#variant-bundling-middleware-into-one).\n\n## How it composes\n\nEach middleware contributes one typed key to `ctx`. Pass entries as a flat array to `pipeline` — first in the array runs first on the request. The handler sees **every** upstream key ambiently, typed from the entries array (the `satisfies FetchHandler` below just asserts the result is usable as the `fetch` export):\n\n```ts\nimport { pipeline, defineMiddleware } from '@supabase/middleware'\nimport type { FetchHandler } from '@supabase/middleware'\nimport { withFeatureFlag } from '@supabase/middleware/feature-flag'\n\n// A middleware is just a `defineMiddleware` call — bundled or your own.\nconst withRequestId = defineMiddleware<\n  'requestId',\n  void,\n  Record<never, never>,\n  string\n>({\n  key: 'requestId',\n  run: () => async (req) => ({\n    requestId: req.headers.get('x-request-id') ?? crypto.randomUUID(),\n  }),\n})\n\nexport default {\n  fetch: pipeline(\n    [\n      withRequestId(), // no config — still returns an Entry\n      withFeatureFlag({\n        name: 'beta',\n        evaluate: (req) => req.headers.has('x-beta'),\n      }),\n    ],\n    async (_req, ctx) => {\n      ctx.requestId //  from withRequestId\n      ctx.featureFlag //  from withFeatureFlag — ctx holds middleware contributions, nothing else\n      return new Response(null, { status: 200 })\n    },\n  ) satisfies FetchHandler,\n}\n```\n\nTwo type-level guarantees, with no runtime cost:\n\n- **Collision detection.** Two middleware contributing the same key fail to compile, with an error naming the key on the offending call. `pipeline` checks this from the entries array. Nested handlers need `satisfies FetchHandler` on the outermost call — one annotation covers any depth — and without it the duplicate compiles silently and the inner contribution wins at runtime.\n- **Prerequisite enforcement.** A middleware can declare upstream keys it needs (e.g. a database middleware that needs `jwtClaims` from an upstream auth middleware). Any layer further out can supply them, at any distance and with no annotation, and the contribution's type has to match — not just the key name. If **nothing** supplies it, the stack keeps a _required_ `ctx`, which fails only where it is checked against `FetchHandler`. A bare `export default { fetch: app }` is no such check, so it compiles and throws `TypeError` on the first request — annotate the outermost call with `satisfies FetchHandler` (or put the stack in any `FetchHandler`-typed position) to catch it at build time.\n\n### Composing by nesting\n\n`pipeline` is optional. Every middleware also takes the next handler directly, as `withFoo(config, handler)`. Nesting those calls builds the same handler, with the same accumulation and the same prerequisite enforcement, at any depth.\n\n```ts\nimport type { FetchHandler } from '@supabase/middleware'\nimport { withCors } from '@supabase/middleware/cors'\nimport { withFeatureFlag } from '@supabase/middleware/feature-flag'\n\nexport default {\n  fetch: withCors(\n    {},\n    withFeatureFlag(\n      { name: 'beta', evaluate: (req) => req.headers.has('x-beta') },\n      async (_req, ctx) => Response.json({ flag: ctx.featureFlag.name }),\n    ),\n  ) satisfies FetchHandler,\n}\n```\n\nNesting asks one thing of you: keep `satisfies FetchHandler` on the outermost call. That anchor turns on collision detection and the build-time prerequisite check, as the bullets above describe. `ctx` accumulation needs no annotation at any depth.\n\n`FetchHandler` is a type, so importing it adds no runtime code. The [authoring guide](./docs/authoring-guide.md) tells middleware authors to re-export it from their own package. Compose only middleware from packages that do, and your handler file imports nothing from `@supabase/middleware`. Your `package.json` never lists it either. Composition comes free with the middleware themselves.\n\nPast two or three entries, the flat array is easier to read than the nesting it folds into. That is what `pipeline` is for, and why these docs lead with it. Both forms produce the same stack, so pick whichever fits the file.\n\n### Runtime & environment\n\nEnvironment access is a plain import — middleware never reach for `Deno.env` / `process.env` / a Workers bindings object directly, and `ctx` carries no reserved framework key:\n\n```ts\nimport { getEnv, runtimeName } from '@supabase/middleware'\n\ngetEnv('SUPABASE_DB_URL') // string | undefined, resolved per host\nruntimeName // 'node' | 'deno' | 'bun' | 'workerd' | … ('' when unknown) — via std-env\n```\n\nHost detection is delegated to [`std-env`](https://github.com/unjs/std-env) (which tracks the WinterCG Runtime Keys proposal), once at module load. On Cloudflare Workers, env bindings are not ambient — they arrive per request as the second `fetch` argument — so the entry call captures them module-scoped and `getEnv` reads them first, falling back to the host's global env (`process.env`, `Deno.env`). One consequence: on Workers, `getEnv` returns `undefined` at module top level, before the first request.\n\nSupported entry signatures are **`(request)`** and **`(request, env)`**. A third `fetch` argument — the Workers `ExecutionContext` (`waitUntil` / `passThroughOnException`) — is **not honored**: it's ignored with a one-time `console.warn`. The Deno target never passes one.\n\n## Request-side by default\n\nA middleware runs **before** the handler. In the common case it never observes the handler's `Response` — no `next()`, no on-the-way-out mutation — so response shape stays under one owner: the handler. Response-side concerns are then plain `Response` work, right where they belong:\n\n- **Errors** — `try/catch` inside the handler.\n- **Response headers / envelopes** — shape the `Response` the handler returns.\n\n```ts\nimport { withFeatureFlag } from '@supabase/middleware/feature-flag'\n\nexport default {\n  fetch: withFeatureFlag(\n    { name: 'beta', evaluate: (req) => req.headers.has('x-beta') },\n    async (req, ctx) => {\n      try {\n        const body = await req.json()\n        // response headers / envelope — shaped here, by the response's owner\n        return Response.json(\n          { flag: ctx.featureFlag.name, body },\n          { headers: { 'x-powered-by': 'middleware' } },\n        )\n      } catch {\n        return Response.json({ error: 'bad request' }, { status: 400 })\n      }\n    },\n  ),\n}\n```\n\nNormally the `Response` is shaped by whoever returns it — the handler, as above, or a middleware short-circuiting with one of its own. The response seam below is for the other case: a middleware that has to still be running after the downstream stack finishes — to read or replace the `Response` it returned, to catch what it threw, or just to run cleanup.\n\n### The response seam (when a middleware really needs the way out)\n\nSome concerns are irreducibly two-sided — timing, request-spanning cleanup, CORS (preflight in, headers out). For those, write `run` as an **`async function*`** instead of `async`. `yield` is the seam:\n\n```ts\nrun: (config) =>\n  async function* (req, ctx) {\n    const start = performance.now() // request phase (before)\n    const response = yield { timing: { route: req.url } } // ← contribute, then suspend\n    response.headers.set('x-time', `${performance.now() - start}`) // response phase (after)\n    return response\n  }\n```\n\nThe `yield` expression resolves to the downstream `Response` (typed as `Response`, inferred — no annotation). `yield` the contribution at most once — `yield` means \"run downstream and hand me the response.\" To short-circuit (handler never runs), `return new Response(...)`, exactly as a plain request-side middleware does. `try/finally` around the `yield` gives request-spanning cleanup; `try/catch` can turn a downstream throw into a `Response`.\n\nThis is the **one** place the \"request-side\" guarantee is relaxed, and writing `function*` is the visible, opt-in signal — the 95% plain-`async` path is unchanged. [`/cors`](./src/middleware/cors/README.md) is the worked example.\n\n## Docs\n\n- [Authoring guide](./docs/authoring-guide.md) — **build your own middleware**: `defineMiddleware`, tests, publishing, and composing it in the same `pipeline` array as the built-in entries.\n- [Composition primitives](./src/core/README.md) — `ctx` shape, conflict & prerequisite enforcement, composition rules, the response seam.\n- Per-middleware: [feature-flag](./src/middleware/feature-flag/README.md) — the request-side worked example · [cors](./src/middleware/cors/README.md) — the response-seam worked example.\n\nFull generated API reference: [supabase.github.io/middleware](https://supabase.github.io/middleware/).\n\n## License\n\nMIT\n","readmeFilename":"README.md"}