Breaking-change diffs for npm packages: removed exports, changed signatures, migration notes.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag β we're steadily working through the catalog.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
A breaking-change diff API for npm packages. Given a package and two versions, it returns a structured, machine-readable list of what actually broke: removed exports, changed function signatures, and removed or changed class and interface members. Each entry includes the before and after signatures plus a short migration note.
Live at https://vdiff-api.onrender.com. Most easily consumed through the MCP server, vdiff-mcp:
Or call the REST API directly:
LLMs learn a package's API surface during training, then the package moves on. When a coding agent writes code against zod or express, it writes for the version it remembers, which is often not the version in your lockfile. The result is confident code that calls functions that were renamed or removed two majors ago.
Existing tools only solve part of this. Version lookup tools tell the agent what the current version is. Documentation tools tell it what the docs say today. Neither answers the question the agent actually has mid-edit: "what changed between the version I know and the version installed here?"
vdiff answers exactly that. Diffs are computed from the package's own type declarations rather than changelogs, so the output reflects the real exported surface, and every response carries a confidence score so the consumer knows how much to trust it.
Endpoint reference: docs/api.md.
.d.ts files, and build a table of public exports (functions, classes, members, normalized call signatures) using the TypeScript compiler API. Bundled declarations are preferred; packages that ship none fall back to the matching DefinitelyTyped @types/* package, version-matched by major.minor.export_removed, signature_changed, member_removed and so on), each with before/after signatures and a migration note.Diffs are type-level: a runtime behavior change that leaves the types untouched is invisible. Responses using bundled types carry confidence 0.9; responses using community-maintained @types/* declarations carry 0.8.
| Endpoint | Purpose |
|---|---|
GET /v1/diff | Breaking-change diff between two versions (from required, to defaults to latest) |
GET /v1/resolve | Latest version and dist-tags for a package |
GET /healthz | Liveness check |
See docs/api.md for parameters, response shapes, change types, error codes and rate limits.
| Layer | Choice | Why |
|---|---|---|
| Runtime | Node 20+, TypeScript | npm-only .d.ts diffing needs the TS compiler API, so one language |
| API | Fastify 5 | Fast, minimal, good TypeScript support |
| Diffing | typescript compiler API | Structured symbol tables from .d.ts files, the core of the product |
| Database | Postgres 18 (Docker local, Neon prod) | JSONB for variable-shape diff payloads, SQL for billing and analytics |
| Registry | npm registry HTTP API + tar | Packuments and tarball extraction, declarations only |
| Tests | Vitest | Unit tests for compare logic and @types version matching |
The code is cloud-agnostic: a plain container plus a DATABASE_URL. It currently runs on Render with Neon Postgres.
Or containerized, the way a PaaS runs it (applies the schema on boot, then serves):
All configuration is via environment variables:
| Env var | Default | Purpose |
|---|---|---|
PORT | 3000 | Listen port |
DATABASE_URL | local Docker Postgres | Postgres connection string |
RATE_LIMIT_DIFF_MAX | 30 | Per-IP /v1/diff requests per minute |
RATE_LIMIT_RESOLVE_MAX | 120 | Per-IP /v1/resolve requests per minute |
COMPUTE_CONCURRENCY | 2 | Max simultaneous diff computations |
TRUST_PROXY | unset | Set true behind a PaaS proxy so the rate limiter sees real client IPs |
/healthz is exempt for platform health checks.COMPUTE_CONCURRENCY uncached diffs compile at once; excess requests get a 503 with retry-after. Cached diffs are always served.422.registry.npmjs.org over HTTPS.The API and diff engine are licensed under the Functional Source License, v1.1, MIT Future License (FSL-1.1-MIT): free to use, read and modify for anything except offering a competing service, and each release automatically becomes MIT two years after publication.
The MCP server wrapper in mcp/ is MIT licensed.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/vdiff-mcp)<a href="https://allmcps.com/mcp/vdiff-mcp"><img src="https://allmcps.com/api/badge/vdiff-mcp?style=directory" alt="Vdiff MCP on AllMCPs" /></a>