AI Power Ups
Contents

Dev · npm Registry

npm.package

Retrieve a public npm package, including scoped names. Omit version for the full package document and version history, or specify latest, a dist-tag or an exact version. Returns a compact summary; details returns the complete retrieved document, including dependencies, license, repository, maintainers, tarball URLs and README when available.
Operation
POST /v1/capabilities/npm.package/execute
operationId
executeNpmPackage
Typical credits
0
Search deadline
15 s server-side
Paging
single result
Availability
Not checked
Cost basis: Free public npm API; cached details cost 0 credits. Availability is reported per deployment by GET /v1/catalog (available). The timestamped snapshot describes configuration, not provider uptime or your account's enabled choices. Check the catalog with your own key before a call. Credits are explained under credits and limits.

Request

Body of POST /v1/capabilities/npm.package/execute, JSON, validated against the NpmPackageRequest component of the public OpenAPI document. Defaults are applied server-side, so an omitted optional field behaves exactly as its default.

Request fields of npm.package
FieldTypeRequiredDefaultConstraints and description
packagestringyesmin length 1, max length 214, pattern ^(?:@[a-zA-Z0-9_~][a-zA-Z0-9._~-]*/)?[a-zA-Z0-9_~][a-zA-Z0-9._~-]*$
Public npm package name, including scoped names such as @babel/core.
versionstringnomin length 1, max length 256, pattern ^[a-zA-Z0-9][a-zA-Z0-9._+~-]*$
latest, a dist-tag, or an exact version such as 3.23.8. Omit for full metadata and version history.
  • Unknown keys are rejected with 400 invalid_request.

Examples

Full version history

curl
curl -s -X POST https://ai-powerups.smalltree.cloud/v1/capabilities/npm.package/execute \
  -H "Authorization: Bearer $AIPA_API_KEY" -H "Content-Type: application/json" \
  -d '{"package":"zod"}'

Latest version

curl
curl -s -X POST https://ai-powerups.smalltree.cloud/v1/capabilities/npm.package/execute \
  -H "Authorization: Bearer $AIPA_API_KEY" -H "Content-Type: application/json" \
  -d '{"package":"zod","version":"latest"}'

Specific version

curl
curl -s -X POST https://ai-powerups.smalltree.cloud/v1/capabilities/npm.package/execute \
  -H "Authorization: Bearer $AIPA_API_KEY" -H "Content-Type: application/json" \
  -d '{"package":"zod","version":"3.23.8"}'

Scoped package

curl
curl -s -X POST https://ai-powerups.smalltree.cloud/v1/capabilities/npm.package/execute \
  -H "Authorization: Bearer $AIPA_API_KEY" -H "Content-Type: application/json" \
  -d '{"package":"@babel/core","version":"latest"}'
No recorded response is published for this capability yet. The envelope is the ExecuteResponse component (see sessions and records); the record keys below are what the adapter emits. A first call with the example above returns search_id, the records and the charge.

Result record

Every item in results[] carries record_id and title (contract, always present) and usually url and snippet. The keys below are the documented tier: produced deterministically by this capability, omitted when the source has no value, checked against recorded source fixtures in our test suite, and published as the NpmPackageRecord component (all optional, extra keys allowed) so generated clients type them. The wire schema itself still validates only the base keys. See stability tiers.

Record keys of npm.package
KeyTypePresenceNote
packagestringalways
versionstringwhen the source has it
licensestring | objectwhen the source has it
repositorystring | objectwhen the source has it
maintainersobject[]when the source has it
dependenciesobjectwhen the source has it
distobjectwhen the source has it
dist_tagsobjectwhen the source has it
version_countintegerwhen the source has it

Caveats

  • Omit version for all version manifests and README when available; latest or an exact version returns one manifest.
  • Metadata documents larger than 8 MiB return provider_error. Request a specific version for large packages.

Follow-ups

  • Paging: Single result; more is refused with 400 invalid_request.
  • Update: not offered.
  • Record actions:
    • details: Complete cached package or version metadata from this lookup.
  • Detail behaviour: Stored at search time; details is free and never calls the provider. details returns the complete cached package or version document for free.
record action
curl -s -X POST https://ai-powerups.smalltree.cloud/v1/follow-up \
  -H "Authorization: Bearer $AIPA_API_KEY" -H "Content-Type: application/json" \
  -d '{"record_id":"rec_…","action":"details"}'

Record detail objects of this capability are provider-shaped: documented by observation, not by schema. Full follow-up semantics: follow-up.

Typed client

With types generated from the public document (see types, client and samples) the call is path-keyed and the body is checked at compile time:

TypeScript (openapi-fetch)
const { data, error } = await client.POST("/v1/capabilities/npm.package/execute", {
  body: {
    "package": "zod"
  },
});
if (error) throw new Error(`${error.error.code}: ${error.error.message}`);
for (const record of data.results) console.log(record.record_id, record.title);