Installation
Install mongoose-guard from npm next to mongoose. It needs Node.js 20 or newer and Mongoose 8 or 9. It has no runtime dependencies of its own.
npm install mongoose-guardpnpm add mongoose-guardyarn add mongoose-guardbun add mongoose-guardRequirements
Section titled “Requirements”| Requirement | Supported | Notes |
|---|---|---|
| Node.js | 20, 22, 24 | Older versions are not tested. |
| Mongoose | 8.x, 9.x | Every test runs against both. Mongoose 7 and older are not supported. |
| Express | 4.x, 5.x | Only needed if you use mongoose-guard/express. |
| TypeScript | tested with 5.9 and 6.0 | Optional. Types ship with the package. |
mongoose is a peer dependency, so mongoose-guard uses the copy your app already has. express and @types/express are optional peers: you only need them for the Express adapter.
Pick an import
Section titled “Pick an import”The package has three entry points. Import only the one you need.
| Import | Use it when |
|---|---|
mongoose-guard/express | You use Express. Gives you a middleware. |
mongoose-guard/web | Your framework hands you a standard Request: Next.js route handlers, Hono, Remix, React Router, SvelteKit. |
mongoose-guard | Anything else, or tests. Gives you a plain function that takes a body and returns a result. |
import { guard } from "mongoose-guard/express";import { guard as webGuard, invalidResponse } from "mongoose-guard/web";import { createGuard, validateBody, GuardConfigError } from "mongoose-guard";Importing mongoose-guard/express doesn’t load the web adapter and vice versa.
ESM and CommonJS
Section titled “ESM and CommonJS”Both work. Use whichever your project already uses.
// ESMimport { guard } from "mongoose-guard/express";
// CommonJSconst { guard } = require("mongoose-guard/express");TypeScript projects work with every moduleResolution setting, including the older node (node10) setting that many CommonJS Express projects still have.
Where it does not run
Section titled “Where it does not run”mongoose-guard is tested on Node.js. Bun and Deno may work wherever Mongoose works on them, but they aren’t tested. It does not run on edge runtimes such as Cloudflare Workers or Vercel Edge functions, because Mongoose needs a TCP connection to MongoDB that those runtimes don’t provide.