Framework-independent HTTP policy engine for TypeScript — define caching, security headers, CORS and custom headers as typed, composable policies, then compile them once into deeply immutable objects with precomputed header strings.
Zero dependencies. No framework code — pair it with an adapter (@http-policy/express, @http-policy/fastify, @http-policy/hono, @http-policy/nestjs) or use applyPolicy directly on node:http.
import { policy } from '@http-policy/core';
const apiPolicy = policy()
.cache((c) => c.public().browser('5m').cdn('1h').staleWhileRevalidate('10m'))
.security((s) => s.nosniff().hsts('180d').referrer('strict-origin-when-cross-origin'))
.cors((c) => c.origin('https://app.example.com').credentials())
.headers((h) => h.set('X-App-Version', '1.0'))
.compile();Invalid combinations never compile — policy().cache((c) => c.private().cdn('1h')) is rejected because s-maxage only exists on the public cache model. CRLF injection is rejected at the call site; credentials() + wildcard CORS is a compile-time error.
See the full documentation.