Skip to content

basalt / http/src / rawBody

Function: rawBody() ​

> rawBody(options?): ZodType<RawBody>

Defined in: http/src/raw-body.ts:92

Declares that a route wants the untouched request bytes — adapter-neutral: the same route sees byte-identical input on Fastify, Express and Hono.

ts
route({
  method: 'POST', url: '/webhooks/stripe',
  body: rawBody({ maxBytes: 64 * 1024 }),
  handler({ body, request }) {
    const event = stripe.webhooks.constructEvent(
      body.text(),
      request.headers['stripe-signature'] as string,
      secret,
    )
  },
})

Why this has to exist: every adapter parses application/json before a handler runs, and a signature covers the bytes that arrived. JSON.stringify of the parsed object is not an approximation of those bytes — key order, whitespace, number formatting and escaping all differ — so a route that verified against it would reject every genuine delivery (or, if it shrugged the mismatch off, accept every forgery).

The usual pipeline order is preserved: pre-hooks (rate limiting), enrichers (tenant, user) and guards (auth, permissions) all run BEFORE a single body byte is read, exactly as for upload. A body the route never gets to read — a guard rejected first — is drained and the connection closed, so nothing hangs. The bytes are never handed to a parser, this package's or the app's.

Parameters ​

options? ​

RawBodyOptions = {}

Returns ​

ZodType<RawBody>

Released under the MIT License.