Runtime reference

What a function finds when it runs: the ECMAScript standard library plus a small set of natively-backed globals and context helpers. Everything here is implemented in Rust behind the scenes — not interpreted polyfills — and present on every path: deployed functions, execute, MCP tools, and rusted run.

Globals

globalwhat you get
ES2020 standard libraryJSON, RegExp, Date, Math, Map/Set, Promise, BigInt, Proxy/Reflect, typed arrays — the language itself, complete.
fetch(url, init?)Outbound HTTP/HTTPS, SSRF-guarded (no private networks) and capped per plan. Reduced on purpose: plain objects in and out — no body streams, blob, formData, statusText, redirect control, or Headers/Request/Response classes. The response offers status, headers, text(), and json().
consolelog, info, warn, error — captured per invocation and returned with it (see rusted logs), not written to stdout. Capped at 100 entries of 1024 characters. No debug, table, trace, or time.
URL / URLSearchParamsWHATWG URL parsing, relative resolution against a base, component setters that re-serialize through the real parser, and a live-linked searchParams. Backed by the same URL implementation browsers follow.
TextEncoder / TextDecoderUTF-8 only — any other label is a RangeError. Invalid bytes become U+FFFD unless constructed with { fatal: true }, which throws. Accepts Uint8Array, ArrayBuffer, and views.
btoa / atobStandard base64 of binary strings.

Building responses — context

helperwhat it does
context.json(body, init?)An application/json response; init sets status and extra headers.
context.text(body, init?)text/plain; charset=utf-8.
context.html(body, init?)text/html; charset=utf-8 — pages and htmx fragments.
context.render(template, data?)Server-side templating (minijinja): {{ expr }}, {% if %}/{% for %}, filters. HTML auto-escaping is always on; |safe marks a value as pre-escaped. Pairs with .html imports, which bundle as strings. A syntax error throws, naming the line.
context.redirect(url, init?)A redirect; status defaults to 302.
context.setCookie(name, value, options?)A set-cookie header value with safe defaults: Path=/, HttpOnly, SameSite=Lax, Secure.
context.formEncode(values)application/x-www-form-urlencoded — for query strings and form bodies.

Crypto and codecs — native, not interpreted

The primitives every credential-handling function otherwise imports an npm package (and pays interpreter time) for:

helperwhat it does
context.randomBytes(n)1–1024 bytes from the OS cryptographic source — for state, nonces, and keys, where Math.random() must never be used.
context.randomBase64Url(n)The same, as unpadded base64url — URL- and cookie-safe. 32 bytes encodes to 43 characters.
context.sha256(data)SHA-256 of a string or bytes.
context.toBase64Url / fromBase64UrlUnpadded base64url, both directions.
context.toHex / fromHexHex, both directions.
context.timingSafeEqual(a, b)Equality without leaking where inputs differ through timing — compare tokens and signatures with this, never ===.
context.seal / context.openAuthenticated encryption (AES-256-GCM) of a JSON payload, keyed by one of your vault secrets — the key never enters JavaScript. Compact base64url output, fit for a cookie. See security.

Declared capabilities

Present only when the module asks (see the module reference) and the host supplies them:

helperappears when
context.envconfig.secrets is declared — each name decrypted per invocation, per environment.
context.dbconfig.db: true — parameterized SQL against the account's per-environment SQLite database: query, exec, atomic transaction batches.
context.stateconfig.state: true — durable JSON state with compare-and-set.
context.objects.<NAME>config.objects declares the binding — presigned S3 puts and gets.
context.inboxDeployed functions — read your inboxes.
context.currentEnvDeployed and local runs — "prod", the @env the URL selected, or "local".

Deliberately absent

The sandbox is smaller than Node or a browser, on purpose:

  • Timers — no setTimeout, setInterval, or any scheduling: the uncatchable wall-clock deadline owns time.
  • Node built-ins — no fs, process, net, child_process, Buffer, or require. There is no filesystem to find.
  • Web APIs beyond the list above — no crypto.subtle, Intl, Blob, FormData, AbortController, or Headers/Request/Response classes.
  • Runtime import — nothing resolves at run time. npm packages work by being bundled in: rusted push bundles imports automatically, so pure-JS packages (zod, date-fns, @noble/hashes, …) just work, while packages needing node built-ins or timers do not.

rusted types writes rusted.d.ts — this whole surface as TypeScript declarations, so your editor promises exactly what the runtime keeps.