One schema, not two
Your Mongoose schema stays the source of truth. You don’t copy its rules into Zod or Joi.
mongoose-guard is a small TypeScript library for Node.js. It checks an incoming request body against an existing Mongoose model before your route code runs. You tell it which fields a route accepts. It rejects unknown fields, fields the route doesn’t allow, wrong types and anything your Mongoose rules reject, and it tells the client exactly what was wrong.
import { guard } from "mongoose-guard/express";
app.post("/signup", guard(User, { allow: ["name", "email", "password"] }), signup);Send { "name": "Amrit", "email": "amrit@example.com", "password": "correct-horse", "role": "admin" } to that route and it never reaches signup. The client gets a 400:
{ "errors": [{ "code": "forbidden_field", "path": "role", "message": "Field is not allowed" }]}One schema, not two
Your Mongoose schema stays the source of truth. You don’t copy its rules into Zod or Joi.
Stops mass assignment
Each route lists the fields it accepts. role, credits or isVerified can’t sneak in through a signup form.
Strict types
"25" is not a number. Mongoose would cast it quietly. mongoose-guard reports it.
Blocks injection keys
__proto__, $where, $gt and dotted keys are rejected anywhere in the body.
| Package | mongoose-guard on npm |
| License | MIT |
| Runtime | Node.js 20 or newer |
| Mongoose | 8 and 9 |
| Express | 4 and 5 |
| Other frameworks | anything that gives you a standard Request (Next.js, Hono, Remix, React Router, SvelteKit) |
| Module formats | ESM and CommonJS, with TypeScript types |
| Runtime dependencies | none |