Runtime reference
What a function finds when it runs: the ECMAScript standard library plus a small set of natively-backed globals and context helpers. Everything here is implemented in Rust behind the scenes — not interpreted polyfills — and present on every path: deployed functions, execute, MCP tools, and rusted run.
Globals
| global | what you get |
|---|---|
| ES2020 standard library | JSON, RegExp, Date, Math, Map/Set, Promise, BigInt, Proxy/Reflect, typed arrays — the language itself, complete. |
fetch(url, init?) | Outbound HTTP/HTTPS, SSRF-guarded (no private networks) and capped per plan. Reduced on purpose: plain objects in and out — no body streams, blob, formData, statusText, redirect control, or Headers/Request/Response classes. The response offers status, headers, text(), and json(). |
console | log, info, warn, error — captured per invocation and returned with it (see rusted logs), not written to stdout. Capped at 100 entries of 1024 characters. No debug, table, trace, or time. |
URL / URLSearchParams | WHATWG URL parsing, relative resolution against a base, component setters that re-serialize through the real parser, and a live-linked searchParams. Backed by the same URL implementation browsers follow. |
TextEncoder / TextDecoder | UTF-8 only — any other label is a RangeError. Invalid bytes become U+FFFD unless constructed with { fatal: true }, which throws. Accepts Uint8Array, ArrayBuffer, and views. |
btoa / atob | Standard base64 of binary strings. |
Building responses — context
| helper | what it does |
|---|---|
context.json(body, init?) | An application/json response; init sets status and extra headers. |
context.text(body, init?) | text/plain; charset=utf-8. |
context.html(body, init?) | text/html; charset=utf-8 — pages and htmx fragments. |
context.render(template, data?) | Server-side templating (minijinja): {{ expr }}, {% if %}/{% for %}, filters. HTML auto-escaping is always on; |safe marks a value as pre-escaped. Pairs with .html imports, which bundle as strings. A syntax error throws, naming the line. |
context.redirect(url, init?) | A redirect; status defaults to 302. |
context.setCookie(name, value, options?) | A set-cookie header value with safe defaults: Path=/, HttpOnly, SameSite=Lax, Secure. |
context.formEncode(values) | application/x-www-form-urlencoded — for query strings and form bodies. |
Crypto and codecs — native, not interpreted
The primitives every credential-handling function otherwise imports an npm package (and pays interpreter time) for:
| helper | what it does |
|---|---|
context.randomBytes(n) | 1–1024 bytes from the OS cryptographic source — for state, nonces, and keys, where Math.random() must never be used. |
context.randomBase64Url(n) | The same, as unpadded base64url — URL- and cookie-safe. 32 bytes encodes to 43 characters. |
context.sha256(data) | SHA-256 of a string or bytes. |
context.toBase64Url / fromBase64Url | Unpadded base64url, both directions. |
context.toHex / fromHex | Hex, both directions. |
context.timingSafeEqual(a, b) | Equality without leaking where inputs differ through timing — compare tokens and signatures with this, never ===. |
context.seal / context.open | Authenticated encryption (AES-256-GCM) of a JSON payload, keyed by one of your vault secrets — the key never enters JavaScript. Compact base64url output, fit for a cookie. See security. |
Declared capabilities
Present only when the module asks (see the module reference) and the host supplies them:
| helper | appears when |
|---|---|
context.env | config.secrets is declared — each name decrypted per invocation, per environment. |
context.db | config.db: true — parameterized SQL against the account's per-environment SQLite database: query, exec, atomic transaction batches. |
context.state | config.state: true — durable JSON state with compare-and-set. |
context.objects.<NAME> | config.objects declares the binding — presigned S3 puts and gets. |
context.inbox | Deployed functions — read your inboxes. |
context.currentEnv | Deployed and local runs — "prod", the @env the URL selected, or "local". |
Deliberately absent
The sandbox is smaller than Node or a browser, on purpose:
- Timers — no
setTimeout,setInterval, or any scheduling: the uncatchable wall-clock deadline owns time. - Node built-ins — no
fs,process,net,child_process,Buffer, orrequire. There is no filesystem to find. - Web APIs beyond the list above — no
crypto.subtle,Intl,Blob,FormData,AbortController, orHeaders/Request/Responseclasses. - Runtime
import— nothing resolves at run time. npm packages work by being bundled in:rusted pushbundles imports automatically, so pure-JS packages (zod,date-fns,@noble/hashes, …) just work, while packages needing node built-ins or timers do not.
rusted types writes rusted.d.ts — this whole surface as TypeScript declarations, so your editor promises exactly what the runtime keeps.
rusted