# sdxc > 87 small TypeScript packages published under one npm scope, built on web standards: `Request` and `Response` in, typed values out. Every fallible entry point answers with a `Result`, 40 of them install no external dependency at all, and 46 need no framework. This file lists every page; each link is the page's markdown source. ## Getting started - [What these are](https://sdxc.sergiodxa.com/docs/getting-started/what-these-are.md): A collection of small TypeScript packages that agree with each other, built on what the web platform already provides. - [Install and pin](https://sdxc.sergiodxa.com/docs/getting-started/install-and-pin.md): How a package arrives, what it installs alongside itself, and where the record of a release is kept. - [Your first handler](https://sdxc.sergiodxa.com/docs/getting-started/your-first-handler.md): Three packages composed into a request handler that never throws, and what each line of it demonstrates. ## Conventions - [Result everywhere](https://sdxc.sergiodxa.com/docs/conventions/result-everywhere.md): Every fallible entry point answers with a value instead of throwing, and what that buys you at the call site. - [Standard Schema validation](https://sdxc.sergiodxa.com/docs/conventions/standard-schema-validation.md): Where a package needs a schema it accepts any Standard Schema, so the validation library is yours to choose. - [Subpath exports](https://sdxc.sergiodxa.com/docs/conventions/subpath-exports.md): A package is split into entry points so importing one concern leaves the others out of your bundle. - [Naming](https://sdxc.sergiodxa.com/docs/conventions/naming.md): What a package name tells you, and the conventions its exports follow, so the next package reads like the last one. ## Releases - [Versioning](https://sdxc.sergiodxa.com/docs/releases/versioning.md): Releases are dated rather than semantic, the number records when a release went out, and that is why a dependency is written as one exact date. ## License - [License](https://sdxc.sergiodxa.com/docs/license.md): Every package in the collection is published under the MIT license, on the same terms, and each one carries its own copy of it. ## Packages — HTTP & responses - [@sdxc/http](https://sdxc.sergiodxa.com/api/http.md): Response builders, content negotiation, and HTTP caching for the Fetch API - [@sdxc/response](https://sdxc.sergiodxa.com/api/response.md): Semantic helpers that build Response objects for JSON APIs and redirects - [@sdxc/api-client](https://sdxc.sergiodxa.com/api/api-client.md): Base class for HTTP API clients: one origin, verb methods, shared hooks - [@sdxc/get-client-ip](https://sdxc.sergiodxa.com/api/get-client-ip.md): Read the client IP from a Cloudflare Workers request - [@sdxc/user-agent](https://sdxc.sergiodxa.com/api/user-agent.md): Read a User-Agent string into its browser, engine, operating system and device - [@sdxc/structured-fields](https://sdxc.sergiodxa.com/api/structured-fields.md): Parse and serialize RFC 9651 structured HTTP field values - [@sdxc/server-timing](https://sdxc.sergiodxa.com/api/server-timing.md): Server-Timing measurements collected per request and written to a response header - [@sdxc/catch-response-middleware](https://sdxc.sergiodxa.com/api/catch-response-middleware.md): Router middleware that turns a thrown Response into the request's response - [@sdxc/trailing-slash-middleware](https://sdxc.sergiodxa.com/api/trailing-slash-middleware.md): Router middleware that redirects every path to one canonical trailing-slash form - [@sdxc/well-known](https://sdxc.sergiodxa.com/api/well-known.md): Typed well-known URI documents: security.txt, WebFinger, OIDC metadata, JWKS ## Packages — API design - [@sdxc/openapi](https://sdxc.sergiodxa.com/api/openapi.md): Build, serve and check OpenAPI 3.1 documents from typed operations - [@sdxc/problem](https://sdxc.sergiodxa.com/api/problem.md): Build, detect and parse RFC 9457 problem details, cataloged per API - [@sdxc/json-schema](https://sdxc.sergiodxa.com/api/json-schema.md): Schema builders that validate like remix/data-schema and emit JSON Schema - [@sdxc/pagination](https://sdxc.sergiodxa.com/api/pagination.md): Offset and keyset pagination with parameter parsing and Link headers - [@sdxc/idempotency](https://sdxc.sergiodxa.com/api/idempotency.md): Idempotency-Key requests: replay the first response, refuse conflicting reuse - [@sdxc/merge-patch](https://sdxc.sergiodxa.com/api/merge-patch.md): Apply, diff and read RFC 7396 JSON Merge Patch documents ## Packages — Identity & security - [@sdxc/auth](https://sdxc.sergiodxa.com/api/auth.md): OAuth 2.0 and OpenID Connect client for any runtime that speaks Request and Response - [@sdxc/jwt](https://sdxc.sergiodxa.com/api/jwt.md): JWT payload classes and the keys that sign them - [@sdxc/passkey](https://sdxc.sergiodxa.com/api/passkey.md): Passkeys end to end: a WebAuthn browser API and a verifying relying party - [@sdxc/saml](https://sdxc.sergiodxa.com/api/saml.md): SAML 2.0 service provider: verify signed assertions, build requests and metadata - [@sdxc/scim](https://sdxc.sergiodxa.com/api/scim.md): SCIM 2.0 resources, filters, PATCH operations and discovery documents - [@sdxc/crypto](https://sdxc.sergiodxa.com/api/crypto.md): Web Crypto primitives — hashing, HMAC, tokens, TOTP, AES-GCM — plus scrypt passwords - [@sdxc/security-headers](https://sdxc.sergiodxa.com/api/security-headers.md): Typed CSP, Permissions-Policy and security response headers, with middleware - [@sdxc/webhooks](https://sdxc.sergiodxa.com/api/webhooks.md): Sign and verify Standard Webhooks deliveries, reporting every failure as a typed value ## Packages — Forms & abuse - [@sdxc/captcha](https://sdxc.sergiodxa.com/api/captcha.md): Turnstile, hCaptcha and reCAPTCHA verification, with middleware and widgets - [@sdxc/honeypot](https://sdxc.sergiodxa.com/api/honeypot.md): Honeypot form fields with a signed timestamp, middleware and a UI component - [@sdxc/spam](https://sdxc.sergiodxa.com/api/spam.md): Spam scoring for user content: local rules, reputation checks and a classifier - [@sdxc/password-policy](https://sdxc.sergiodxa.com/api/password-policy.md): Password checks: length, common and breached passwords, similarity and reuse - [@sdxc/email-address](https://sdxc.sergiodxa.com/api/email-address.md): Email address parsing, normalization, disposable-domain and mail-server checks ## Packages — Content & formats - [@sdxc/markdown](https://sdxc.sergiodxa.com/api/markdown.md): GitHub Flavored Markdown: parse to a typed AST, transform it, write it back - [@sdxc/yaml](https://sdxc.sergiodxa.com/api/yaml.md): YAML reading and writing over a documented subset, shaped after the built-in JSON object - [@sdxc/xml](https://sdxc.sergiodxa.com/api/xml.md): XML parser and serializer for RSS-style feeds - [@sdxc/html](https://sdxc.sergiodxa.com/api/html.md): Read a served page: fetch or parse HTML, then query it by role and accessible name - [@sdxc/csv](https://sdxc.sergiodxa.com/api/csv.md): Read and write RFC 4180 CSV, with a streaming writer and formula neutralization - [@sdxc/icalendar](https://sdxc.sergiodxa.com/api/icalendar.md): Read and write iCalendar documents, with recurrence rules and time zones - [@sdxc/distill](https://sdxc.sergiodxa.com/api/distill.md): Extract the article from a web page: bounded fetch, scoring and sanitizing - [@sdxc/jsdoc](https://sdxc.sergiodxa.com/api/jsdoc.md): Read JSDoc out of JavaScript and TypeScript source text into a JSON documentation model ## Packages — Feeds & publishing - [@sdxc/rss](https://sdxc.sergiodxa.com/api/rss.md): RSS 2.0 feed builder and parser - [@sdxc/atom](https://sdxc.sergiodxa.com/api/atom.md): Atom 1.0 feed parser and builder - [@sdxc/json-feed](https://sdxc.sergiodxa.com/api/json-feed.md): JSON Feed 1.1 builder and parser - [@sdxc/feed](https://sdxc.sergiodxa.com/api/feed.md): One feed API over RSS, Atom and JSON Feed, with conditional fetching and autodiscovery - [@sdxc/opml](https://sdxc.sergiodxa.com/api/opml.md): Read and write OPML subscription lists - [@sdxc/sitemap](https://sdxc.sergiodxa.com/api/sitemap.md): Read and write the sitemap protocol: collect URLs, or fetch a published sitemap - [@sdxc/robots](https://sdxc.sergiodxa.com/api/robots.md): Read, write and evaluate robots.txt and robots directives - [@sdxc/microformats](https://sdxc.sergiodxa.com/api/microformats.md): Parse, read and write microformats2 - [@sdxc/micropub](https://sdxc.sergiodxa.com/api/micropub.md): Read Micropub requests into typed operations and build the spec's responses - [@sdxc/webmention](https://sdxc.sergiodxa.com/api/webmention.md): Receive, verify, discover and send Webmentions - [@sdxc/websub](https://sdxc.sergiodxa.com/api/websub.md): WebSub subscriber and publisher: subscribe, verify intent and signatures, notify hubs ## Packages — Data & storage - [@sdxc/cache](https://sdxc.sergiodxa.com/api/cache.md): Cache contract with adapters for memory and Cloudflare KV - [@sdxc/workers-cache](https://sdxc.sergiodxa.com/api/workers-cache.md): Cache tags, purging and cache-status reads for Cloudflare Workers Cache - [@sdxc/session-storage-kv](https://sdxc.sergiodxa.com/api/session-storage-kv.md): A remix/session SessionStorage backed by a Cloudflare Workers KV store - [@sdxc/data-table-d1](https://sdxc.sergiodxa.com/api/data-table-d1.md): A remix/data-table DatabaseDriver backed by Cloudflare D1 - [@sdxc/data-table-sqlstorage](https://sdxc.sergiodxa.com/api/data-table-sqlstorage.md): A remix/data-table database driver backed by a Cloudflare Durable Object's SQL storage ## Packages — Interface - [@sdxc/ui](https://sdxc.sergiodxa.com/api/ui.md): Styled, accessible remix/ui components rendered as server HTML - [@sdxc/u](https://sdxc.sergiodxa.com/api/u.md): Utility-first styling for remix/ui, composed from small, terse mixins - [@sdxc/icons](https://sdxc.sergiodxa.com/api/icons.md): Lucide icons as remix/ui components, one tree-shakeable export per icon - [@sdxc/i18n](https://sdxc.sergiodxa.com/api/i18n.md): Language detection and MessageFormat 2 translators for Remix routers and remix/ui - [@sdxc/messageformat](https://sdxc.sergiodxa.com/api/messageformat.md): Unicode MessageFormat 2 parser and formatter shaped like Intl.MessageFormat - [@sdxc/seo](https://sdxc.sergiodxa.com/api/seo.md): Canonical URLs, typed schema.org structured data and head metadata - [@sdxc/highlight](https://sdxc.sergiodxa.com/api/highlight.md): Syntax highlighting as tokens, with a markdown walk visitor and a stylesheet - [@sdxc/lazy-route](https://sdxc.sergiodxa.com/api/lazy-route.md): Maps a route to a module imported on the first request that reaches it ## Packages — Operations - [@sdxc/jobs](https://sdxc.sergiodxa.com/api/jobs.md): Declared background jobs dispatched over a pluggable queue backend - [@sdxc/cron](https://sdxc.sergiodxa.com/api/cron.md): Cron schedules with zone-aware occurrences and descriptors - [@sdxc/logger](https://sdxc.sergiodxa.com/api/logger.md): One wide event per Worker invocation, attached at the router and the job dispatcher - [@sdxc/trace-context](https://sdxc.sergiodxa.com/api/trace-context.md): W3C Trace Context, carried from each invocation to its jobs and requests - [@sdxc/rate-limit](https://sdxc.sergiodxa.com/api/rate-limit.md): Adapter-based rate limiting with standard response headers - [@sdxc/flags](https://sdxc.sergiodxa.com/api/flags.md): Feature flag evaluation implementing the OpenFeature specification - [@sdxc/flags-engine](https://sdxc.sergiodxa.com/api/flags-engine.md): Flag evaluation engine: typed targeting rules, percentage splits and pluggable stores - [@sdxc/billing](https://sdxc.sergiodxa.com/api/billing.md): Vendor-neutral billing providers and a webhook endpoint that verifies deliveries - [@sdxc/mail](https://sdxc.sergiodxa.com/api/mail.md): Transport-agnostic transactional email with pluggable transports and remix/ui rendering - [@sdxc/hostname](https://sdxc.sergiodxa.com/api/hostname.md): Cloudflare for SaaS custom-hostname client: register, poll and delete customer domains - [@sdxc/doh](https://sdxc.sergiodxa.com/api/doh.md): Typed DNS over HTTPS lookups - [@sdxc/mcp](https://sdxc.sergiodxa.com/api/mcp.md): Model Context Protocol servers as remix/router actions over Streamable HTTP - [@sdxc/cloudflare-pricing](https://sdxc.sergiodxa.com/api/cloudflare-pricing.md): Cloudflare Developer Platform list prices, one module per service ## Packages — Language & values - [@sdxc/result](https://sdxc.sergiodxa.com/api/result.md): Result type for error handling - [@sdxc/types](https://sdxc.sergiodxa.com/api/types.md): Shared TypeScript types - [@sdxc/dates](https://sdxc.sergiodxa.com/api/dates.md): Zone-aware date operations with Intl-only formatting - [@sdxc/duration](https://sdxc.sergiodxa.com/api/duration.md): Typed duration strings converted to milliseconds or seconds - [@sdxc/strings](https://sdxc.sergiodxa.com/api/strings.md): English inflection, Chicago title case, slugs and grapheme-safe text - [@sdxc/semver](https://sdxc.sergiodxa.com/api/semver.md): SemVer 2.0.0 parsing, precedence ordering and range-free version comparisons - [@sdxc/location](https://sdxc.sergiodxa.com/api/location.md): URL-like Location class for URL paths without an origin - [@sdxc/validate](https://sdxc.sergiodxa.com/api/validate.md): Standard Schema validation utilities - [@sdxc/uuid](https://sdxc.sergiodxa.com/api/uuid.md): Validate, assert and generate UUIDs behind a branded UUID type - [@sdxc/typeid](https://sdxc.sergiodxa.com/api/typeid.md): Type-safe TypeID values: a UUID and the prefix that names what it identifies ## Packages — Testing - [@sdxc/spec](https://sdxc.sergiodxa.com/api/spec.md): Executable specification runner for .spec files - [@sdxc/sample](https://sdxc.sergiodxa.com/api/sample.md): Seeded generation of believable people, places, prose, numbers and identifiers - [@sdxc/cloudflare-mocks](https://sdxc.sergiodxa.com/api/cloudflare-mocks.md): In-memory, behavior-accurate Cloudflare binding mocks for tests ## Machine-readable - [Search index](https://sdxc.sergiodxa.com/search.json): every page and heading as JSON. - [MCP endpoint](https://sdxc.sergiodxa.com/mcp): search and enumeration over the same content.