tokio-rs/axum
60.3
Weak · 27 September 2026
31.2k
lines of production code
Rust
primary language
4
measurements over time
What this system is
This system is the Axum web framework for Rust, providing a modular architecture for building high-performance HTTP servers. It enables developers to define routes, extract request data, and generate responses through a composable layer system and a suite of derive macros for type-safe extraction and routing. The framework supports diverse workloads including REST APIs, real-time WebSocket communication, and streaming data, with extensive examples covering database integrations, authentication, and static file serving.
How it got here
2021 — Axum 0.8 major release and example expansion
46 changes.
This period centered on the Axum 0.8 release, which introduced a new Router-based routing API, internal refactoring for type-erased routing, and the separation of core types into axum-core. The work also involved a significant expansion of the examples directory, adding comprehensive demonstrations for features like WebSocket, OAuth, TLS, and dependency injection to support the new framework capabilities.
2022 — derive macros and middleware expansion
25 changes.
This period focused on introducing the axum-macros crate to provide derive macros for request extraction, routing, and state management, alongside significant updates to middleware utilities. The work also expanded the axum-extra crate with new extractors for cookies, body streaming, and handler chaining, while adding comprehensive compile-time validation tests and numerous usage examples.
2023–2025 — comprehensive example expansion and serve API refinement
15 changes.
This period focused on significantly expanding the repository's example suite to cover diverse integrations such as Diesel, MongoDB, Redis, and low-level TLS, alongside new development workflow tools. Concurrently, the core framework received enhancements to the \serve\ API, introducing connection limits, listener extensions, and lifetime controls to improve server robustness and observability.
Features
Add CORS example demonstrating cross-origin request handling
A new example application has been added to demonstrate how to configure Cross-Origin Resource Sharing (CORS) using the \tower-http\ \CorsLayer\. The example runs two local services: a frontend on port 3000 and a backend on port 4000, illustrating how to allow specific origins and methods while noting the requirement to explicitly allow headers like \Content-Type\ for POST requests with JSON payloads.
examples/cors · high confidence
Add InnerPath extractor for scoped path parameter extraction
Axum now provides an \InnerPath\ extractor that retrieves URL path parameters only from the innermost matched router, excluding captures from parent \nest\ routes. This allows handlers to remain agnostic of their nesting context, whereas the existing \Path\ extractor continues to return all captures in the request path. The implementation includes a dedicated deserializer (\de.rs\) and rejection types to handle parsing and validation for this new scoped extraction.
axum/src/extract/path · high confidence
Add JWT authentication example
Introduces a new example demonstrating JWT-based authorization and authentication. The example provides a complete implementation including token generation via an \/authorize\ endpoint, token validation via a custom \Claims\ extractor, and a protected \/protected\ route, serving as a reference for integrating JSON Web Tokens with Axum.
examples/jwt · high confidence
Add MiniJinja templating example
A new example demonstrating how to integrate the MiniJinja templating engine with an Axum application. It provides a runnable demo featuring a shared layout and three pages (Home, Content, About) that render HTML templates using context data.
examples/templates-minijinja · high confidence
Add MongoDB integration example
A new example application demonstrating how to integrate Axum with MongoDB has been added. It provides a complete CRUD (Create, Read, Update, Delete) service for a 'Member' entity, showcasing route definitions, state management via the MongoDB driver, and request/response handling with JSON serialization.
examples/mongodb · high confidence
Add PrivateCookieJar and SignedCookieJar extractors with feature-gated availability
axum-extra now provides \PrivateCookieJar\ and \SignedCookieJar\ extractors for handling encrypted and signed cookies, respectively. These types are gated behind the \cookie-private\ and \cookie-signed\ Cargo features and require a cryptographic \Key\ to be available in the application state via \FromRef\. Users must return the updated jar from their handlers to propagate cookie changes, and the \cookie-key-expansion\ feature is required if using \Key::derive\_from\.
axum-extra/src/extract/cookie · high confidence
Add Prometheus metrics example for Axum applications
A new example demonstrating how to integrate Prometheus metrics with Axum has been added. It shows how to track HTTP request counts and latencies using a custom middleware, configure Prometheus buckets, and run a separate server on port 3001 to expose the /metrics endpoint while the main application runs on port 3000.
examples/prometheus-metrics · high confidence
Add README example project
A new example project has been added to demonstrate the core functionality of the library. It provides a runnable Rust application that sets up a router with GET and POST endpoints, handles JSON request bodies, and serves the application using the \axum::serve\ function.
examples/readme · high confidence
Add SQLx PostgreSQL example with connection pool and custom extractor
The \examples/sqlx-postgres\ directory now contains a complete example application demonstrating how to integrate Axum with SQLx for PostgreSQL. The example shows how to set up a \PgPool\ connection pool, configure tracing, and serve HTTP routes. It illustrates two approaches for database access: using Axum's built-in \State\ extractor to share the pool across handlers, and implementing a custom \FromRequestParts\ extractor (\DatabaseConnection\) to acquire individual connections from the pool on demand.
examples/sqlx-postgres · high confidence
Add SSE example with integration tests
The SSE example now includes a complete implementation featuring a server that streams events every second with a keep-alive mechanism, serves static assets (HTML/JS) for client-side consumption, and provides an integration test to verify the event stream functionality.
examples/sse · high confidence
Add TLS graceful shutdown example with HTTP-to-HTTPS redirect
The \examples/tls-graceful-shutdown\ directory now includes a complete runnable example demonstrating how to handle graceful shutdowns in an Axum application. The example features an HTTPS server using Rustls for TLS termination and a separate HTTP server that automatically redirects incoming requests to the HTTPS endpoint. It includes self-signed certificates for local testing and implements signal handling (Ctrl+C and Unix terminate signals) to ensure the server shuts down gracefully within a specified timeout.
examples/tls-graceful-shutdown, examples/tls-rustls · high confidence
Add WASM serverless example for axum
A new example (\examples/simple-router-wasm\) demonstrates how to run axum in a WebAssembly context (target \wasm32-unknown-unknown\). It shows a minimal serverless-style setup where a \Router\ handles a request and returns a response, noting that \default-features = false\ is required because tokio's IO layer (mio) does not support the WASM target.
examples/simple-router-wasm · high confidence
Add WebSocket chat example
A new chat example has been added to the \examples/chat\ directory, demonstrating a real-time WebSocket application built with Axum. The example includes a Rust backend (\src/main.rs\) that manages user connections, validates unique usernames, and broadcasts messages to all connected clients using Tokio's broadcast channel. It also provides a frontend (\chat.html\) that allows users to join a chat room, send messages, and view real-time updates via a WebSocket connection on localhost:3000.
examples/chat · high confidence
Add auto-reload example for development workflows
A new example demonstrating how to set up a development environment for an Axum service that automatically recompiles and restarts upon source code changes. The example utilizes \listenfd\ to migrate connections from an old version of the app to the newly compiled version, ensuring minimal downtime during development.
examples/auto-reload · high confidence
Add compression example demonstrating request decompression and response compression
The \examples/compression\ directory now includes a runnable example that demonstrates how to automatically decompress request bodies (gzip, brotli, zstd) and compress response bodies based on the client's \Accept-Encoding\ header. The example uses \tower-http\'s \RequestDecompressionLayer\ and \CompressionLayer\ within an Axum router, and includes tests verifying correct handling of both compressed and uncompressed payloads.
examples/compression · high confidence
Add dependency injection example
A new example application has been added to demonstrate two approaches to dependency injection in Axum: using trait objects (\dyn UserRepo\) and using generics (\T: UserRepo\). The example implements an in-memory user repository and exposes routes under \/dyn\ and \/generic\ paths to illustrate the trade-offs between dynamic dispatch and static dispatch in terms of code complexity and flexibility.
(repo-wide) · high confidence
Add diesel-postgres example application
A new example application demonstrating how to integrate Axum with Diesel and PostgreSQL has been added. This example includes a complete setup with database migrations, a connection pool using deadpool-diesel, and REST endpoints for creating and listing users, providing a reference implementation for building data-driven web services.
examples/diesel-postgres · high confidence
Add example for consuming request body in middleware and extractor
A new example demonstrates how to consume the HTTP request body upfront within both a middleware and a custom extractor. The middleware buffers the body into bytes before passing the request downstream, while the custom \BufferRequestBody\ extractor implements \FromRequest\ to collect the body payload, allowing users to inspect or process the full request content before it reaches the final handler.
examples/consume-body-in-extractor-or-middleware · high confidence
Add example for customizing extractor error responses
The \examples/customize-extractor-error\ directory has been added to demonstrate three distinct approaches for customizing error responses from existing extractors: using \axum\_extra::extract::WithRejection\ to wrap an extractor, deriving \FromRequest\ to create a wrapper with a custom rejection type, and manually implementing \FromRequest\ for full control. The example shows how to transform standard rejections (like \JsonRejection\) into custom API errors that include status codes and structured JSON bodies.
examples/customize-extractor-error · high confidence
Add example for defining routes and handlers close together
A new example demonstrates how to define routes and their corresponding handlers in close proximity within the same module. The example shows creating a Router by merging separate route definitions for root, GET /foo, and POST /foo, and serving the application using the \axum::serve\ function.
examples/routes-and-handlers-close-together · high confidence
Add example for handling anyhow::Error in Axum responses
A new example demonstrates how to integrate the \anyhow\ crate with Axum by wrapping \anyhow::Error\ in a custom \AppError\ type that implements \IntoResponse\. This allows handlers to use the \?\ operator with \anyhow\-returning functions while ensuring errors are converted into a consistent 500 Internal Server Error response with a descriptive message. The example includes a test verifying this error-handling behavior.
examples/anyhow-error-response · high confidence
Add example for parsing request body based on Content-Type
Introduces a new example demonstrating how to create a custom extractor that automatically parses incoming request bodies as either JSON or form data depending on the Content-Type header. This allows API endpoints to handle multiple content formats seamlessly without requiring clients to specify a single strict format.
examples/parse-body-based-on-content-type · high confidence
Add example for proxying reqwest responses
A new example application demonstrates how to proxy a \reqwest::Response\ within an Axum service. The example shows how to forward the upstream status code and headers, and stream the response body using \Body::from\_stream\, while also including a simple streaming endpoint and HTTP tracing for debugging.
examples/reqwest-response · high confidence
Add initial performance benchmarks for axum
A new benchmark suite has been added to the axum crate to measure performance across various routing and handling scenarios. The benchmarks cover minimal setups, basic routing, route merging and nesting, complex routing tables, JSON request/response handling, and the use of Extensions and State. This allows developers to track performance regressions or improvements in these core areas.
axum/benches · high confidence
Add low-level OpenSSL example for Axum 0.7
A new example demonstrating how to integrate OpenSSL for TLS with Axum 0.7 has been added to the repository. This example includes a complete Rust source file and self-signed certificate/key pairs, showing users how to manually handle TLS handshakes using \tokio-openssl\ and \hyper-util\ alongside an Axum router.
examples/low-level-openssl · high confidence
Add low-level Rustls TLS example
The low-level-rustls example now includes self-signed certificate and key files, enabling users to run the HTTPS server locally for testing. The example code demonstrates how to configure a Rustls server with HTTP/2 and HTTP/1.1 ALPN support, accept TLS connections, and serve requests using Axum and Hyper.
examples/low-level-rustls · high confidence
Add request-id example demonstrating request ID propagation
A new example application has been added at examples/request-id that demonstrates how to generate unique request IDs using tower-http's MakeRequestUuid and propagate them from request headers to response headers. The example also shows how to include the request ID in trace spans for better observability.
examples/request-id · high confidence
Add reverse-proxy example demonstrating proxying to a local backend
A new reverse-proxy example has been added to the examples directory. It runs two local services: a backend server on port 3000 that returns a simple greeting, and a proxy server on port 4000 that forwards incoming requests to the backend. The example uses Axum for routing and state management, and hyper-util with a Tokio executor for the HTTP client, illustrating how to build a basic reverse proxy using these libraries.
examples/reverse-proxy · high confidence
Add stream-to-file example demonstrating secure file uploads
The \examples/stream-to-file\ example has been added, providing a reference implementation for handling file uploads via HTTP. It demonstrates how to stream request bodies and multipart form fields directly to disk using \tokio\ and \axum\, including a specific \path\_is\_valid\ check to prevent directory traversal attacks by ensuring uploaded filenames contain only a single normal path component.
examples/stream-to-file · high confidence
Add templates example with Askama integration and tests
Introduces a new example demonstrating how to integrate the Askama templating engine with Axum. The example includes a custom \HtmlTemplate\ wrapper that implements \IntoResponse\ to render HTML templates, a simple route for greeting users, and a test suite verifying the rendered output.
examples/templates · high confidence
Add todos example demonstrating RESTful CRUD with Axum
The \examples/todos\ crate has been added, providing a complete RESTful web server example for managing todos. It demonstrates key Axum features including route definition via \Router\, state management using \State\, and extractors like \Path\, \Query\, and \Json\. The example implements standard CRUD operations (GET, POST, PATCH, DELETE) on a \/todos\ endpoint, utilizes \tower\ middleware for timeout handling and HTTP tracing, and employs \tracing-subscriber\ for logging configuration.
examples/todos · high confidence
Add tokio-postgres example with connection pool integration
A new example demonstrating how to integrate a PostgreSQL connection pool into an Axum application has been added. The example showcases two approaches for accessing the database: using the built-in \State\ extractor to retrieve a connection from the pool directly within a handler, and implementing a custom \FromRequestParts\ extractor (\DatabaseConnection\) to abstract pool access. It utilizes \bb8\ and \bb8\_postgres\ for connection management and \tokio\_postgres\ for the database driver, serving as a reference for setting up persistent database connections in Axum services.
examples/tokio-postgres · high confidence
Add tokio-redis example with connection pooling
A new example application has been added at examples/tokio-redis that demonstrates integrating Axum with Redis using the redis crate and bb8 for connection pooling. The example includes a custom extractor (DatabaseConnection) to fetch connections from the pool and shows how to set up tracing with environment-based filtering.
examples/tokio-redis · high confidence
Add utility to convert HTTP body to bytes with size limiting
A new \to\_bytes\ function is now available in the \axum::body\ module, allowing users to convert an HTTP body into a \Bytes\ slice while enforcing a configurable maximum size limit. This utility simplifies reading request or response bodies by handling the collection and size-checking logic, returning an error if the body exceeds the specified limit.
axum/src/body · high confidence
Add validator example with custom form extraction
The examples/validator directory now contains a new example demonstrating how to validate form input using the \validator\ crate. It introduces a \ValidatedForm\ extractor that automatically validates deserialized structs and returns a \BAD\_REQUEST\ response with a clear error message when validation fails, such as requiring a name field to be at least two characters long. The example includes unit tests verifying both successful and failed validation scenarios.
examples/validator · high confidence
Add versioning example with custom extractor
Introduces a new example demonstrating how to implement a custom request extractor for handling API versioning. The example defines a \Version\ enum and implements \FromRequestParts\ to parse the version from the URL path, routing requests to \/v1/foo\, \/v2/foo\, or \/v3/foo\ while returning a 404 for unknown versions. It also includes tests verifying correct handling of valid and invalid version parameters.
examples/versioning · high confidence
Example demonstrating custom path rejection error handling
The \examples/customize-path-rejection\ example now shows how to implement a custom \Path\ extractor that overrides the default error response. It maps specific \PathRejection\ variants (such as wrong parameter counts, parse errors, or invalid UTF-8) to tailored JSON error bodies containing a message and optional location, and upgrades unsupported-type errors to a 500 Internal Server Error status.
examples/customize-path-rejection · high confidence
Example demonstrating explicit HEAD request handling
A new example in \examples/handle-head-request\ shows how to explicitly handle HTTP HEAD requests by extracting the \http::Method\ from the request context. The example illustrates a pattern where HEAD requests return specific headers without executing the full body-generation logic used by GET requests, and includes tests verifying both GET and implicit HEAD behaviors.
examples/handle-head-request · high confidence
Expanded static-file-server example with multiple serving strategies
The static-file-server example has been significantly expanded to demonstrate various ways to serve static assets using \tower-http\ services. It now includes runnable configurations for serving directories via \ServeDir\, handling Single Page Application (SPA) fallbacks with \ServeFile\ and status code manipulation, nesting multiple serve directories, integrating custom handlers as fallback services, and calling \ServeDir\ directly from within a handler. The example also includes tests to verify correct fallback behavior.
examples/static-file-server · high confidence
Introduce \`AppendHeaders\` for non-destructive header appending
Axum now provides the \AppendHeaders\ type in \axum-core/src/response\, allowing handlers to add multiple headers to a response without overriding existing ones. Unlike returning a tuple of headers which replaces the header set, \AppendHeaders\ iterates through the provided items and appends each key-value pair to the response's header map, which is essential for scenarios like setting multiple \Set-Cookie\ headers.
axum-core/src/response · high confidence
Introduce axum-core crate with core body and error types
The \axum-core\ crate is introduced to host core types and traits, allowing library authors to depend on it for \FromRequest\ and \IntoResponse\ implementations without pulling in the full \axum\ framework. This location provides the foundational \Body\ type, which now supports creating bodies of unknown size via \Body::unknown()\ (useful for HEAD requests) and converting streams into data via \Body::from\_stream()\. It also defines the \Error\ type with an \into\_inner()\ method to retrieve the underlying boxed error, and implements \From\<()\>\ for \Body\ to allow empty responses from unit returns. Additionally, internal macros for rejection handling and logging are centralized here.
axum-core/src · high confidence
Introduce axum-extra crate with new extractors, responses, and utilities
The \axum-extra\ crate is introduced to host optional utilities for Axum, organized behind feature flags. This release adds the \Either2\ through \Either7\ types for combining multiple extractors or responses into a single type, a \JsonLines\ extractor and response for newline-delimited JSON streams, and a \Protobuf\ extractor and response for Protocol Buffer messages. It also includes a \TypedHeader\ extractor and response for working with typed headers from the \headers\ crate, and an \option\_layer\ middleware utility that conditionally applies a layer while ensuring the output body type remains \axum::body::Body\.
axum-extra/src · high confidence
Introduction of HandleError layer for custom error handling
Axum now provides a \HandleError\ layer and service adapter that allows users to intercept errors from inner services and convert them into custom HTTP responses. This new component enables developers to define custom error-handling logic via a closure, supporting both simple error-to-response conversion and extractors that can inspect the request context before handling the error, thereby integrating error management directly into the service tower stack.
_axum/src/error\handling · high confidence
Introduction of axum-macros crate with derive macros
The \axum-macros\ crate is introduced, providing procedural macros to simplify request extraction and routing. It adds \\#\[derive(FromRequest)\]\ and \\#\[derive(FromRequestParts)\]\ to automatically generate extractor implementations for custom structs, supporting field-level configuration like \via\ extractors and custom rejections. The \\#\[derive(TypedPath)\]\ macro enables type-safe routing by generating \Display\ and \FromRequestParts\ implementations for structs representing URL patterns. Additionally, \\#\[derive(FromRef)\]\ allows automatic state decomposition, while \\#\[debug\_handler\]\ and \\#\[debug\_middleware\]\ provide compile-time validation of handler signatures, such as checking extractor counts and state type inference.
axum-macros/src · high confidence
New AsyncReadBody for streaming AsyncRead sources
The \axum-extra\ crate now exposes an \AsyncReadBody\ type (behind the \async-read-body\ feature flag) that allows users to convert any \tokio::io::AsyncRead\ implementation, such as a file handle, directly into an HTTP response body. This enables efficient streaming of data from async read sources without requiring manual buffering or conversion to bytes, simplifying the implementation of handlers that serve large files or other stream-based content.
axum-extra/src/body · high confidence
New Discord OAuth example application
Added a new example application in the \examples/oauth\ directory that demonstrates how to implement OAuth 2.0 authentication with Discord using Axum. The example includes full source code for handling the authorization flow, managing user sessions via cookies, protecting routes, and logging out, serving as a reference implementation for integrating Discord identity providers.
examples/oauth · high confidence
New RequestExt and RequestPartsExt traits for simplified extraction
The \axum-core\ crate now exposes \RequestExt\ and \RequestPartsExt\ traits, providing convenient methods like \extract\, \extract\_with\_state\, and \extract\_parts\ on \Request\ and \Parts\ objects. These additions allow users to apply extractors directly to request instances or parts without manually invoking the \FromRequest\ or \FromRequestParts\ traits, streamlining the process of pulling data from requests in handlers.
_axum-core/src/ext\traits · high confidence
New WebSocket example supporting HTTP/2
Added a new example in the \examples/websockets-http2\ directory that demonstrates how to run WebSocket connections over HTTP/2. The example includes a Rust server (\src/main.rs\) using \axum\ and \axum-server\ with a self-signed TLS certificate, specifically enabling the HTTP/2 CONNECT protocol to support WebSocket upgrades. It also provides the necessary client-side assets (\assets/index.html\ and \assets/script.js\) for testing the connection.
examples/websockets-http2 · high confidence
New WebSocket example with concurrent client support
The \examples/websockets\ location now provides a complete, runnable WebSocket demonstration. It includes a server (\main.rs\) that serves static assets, handles WebSocket upgrades, and manages concurrent send/receive tasks per connection, alongside a Rust-based stress-test client (\client.rs\) that opens multiple simultaneous connections. A browser-based client (\assets/index.html\ and \script.js\) is also included to demonstrate basic WebSocket interaction from a web page.
examples/websockets · high confidence
New \`serve\` API with connection limits and listener extensions
The \axum::serve\ function has been refactored to support generic listeners and IO types, allowing users to apply connection-level constraints and inspect connections before they are handled. Users can now limit the number of concurrent connections using \ListenerExt::limit\_connections\ and inspect or modify incoming IO streams via \ListenerExt::tap\_io\. Additionally, the new \Serve\ builder exposes \connection\_lifetime\_limits\ to bound the maximum age of individual connections, helping to prevent stale connection pools behind load balancers.
axum/src/serve · high confidence
New and updated extractors in axum-extra
The \axum-extra::extract\ module now includes several new extractor types: \Cached\ to memoize expensive extractor results within a single request, \JsonDeserializer\ for zero-copy JSON deserialization, \OptionalQuery\ to handle optional query parameters, and \WithRejection\ to customize error responses for other extractors. Additionally, the existing \Form\ and \Query\ extractors are now deprecated in favor of the core \axum\ equivalents, and the \Multipart\ extractor has been moved here with runtime-enforced field exclusivity.
axum-extra/src/extract · high confidence
New error-handling example demonstrating custom error conversion and logging
Added a new example in \examples/error-handling\ that demonstrates how to convert application errors into HTTP responses. The example shows how to create a custom JSON extractor (\AppJson\) to handle input validation errors, map third-party library errors (like \time\_library\) to a generic internal server error, and use middleware to log errors without exposing sensitive details to the client. It also illustrates how to integrate with \tower\_http::trace::TraceLayer\ for structured request logging.
examples/error-handling · high confidence
New example demonstrating WebSocket testing strategies
Added a new example in \examples/testing-websockets\ that shows two approaches for testing Axum WebSocket handlers: an integration test that runs the server and connects with a real client, and a unit test that mocks the socket using \Sink\ and \Stream\ traits via channels. This helps users understand how to verify WebSocket logic in their applications.
examples/testing-websockets · high confidence
New example demonstrating axum with hyper's low-level API
Added a new example (\examples/serve-with-hyper\) that shows how to run an axum application using hyper's low-level API directly, rather than relying on higher-level utilities. The example illustrates setting up a TCP listener, converting sockets using \TokioIo\, and serving connections via \hyper::server::conn::auto::Builder\, including a variant that exposes the remote client address via the \ConnectInfo\ extractor.
examples/serve-with-hyper · high confidence
New extractors for connection info, matched paths, and nested routing context
The \axum::extract\ module now includes several new extractors to provide deeper context about the request and routing. \ConnectInfo\ allows handlers to access client connection details (such as \SocketAddr\) when using \Router::into\_make\_service\_with\_connect\_info\, and includes a \MockConnectInfo\ layer for testing. \MatchedPath\ exposes the static route pattern (e.g., \/users/{id}\) that matched the request, while \NestedPath\ provides the specific path segment at which a router was nested (useful for redirects). Additionally, \OriginalUri\ ensures the full original request URI is available even when handlers are inside nested routers, where the standard \Uri\ extractor would return the stripped path.
axum/src/extract · high confidence
New handler chaining with \`HandlerCallWithExtractors\` and \`or\` fallback
The \axum-extra\ crate now provides a \HandlerCallWithExtractors\ trait and an \Or\ combinator that allows developers to chain multiple handlers together using the \.or()\ method. This feature enables fallback logic where the framework attempts to extract inputs for the first handler; if extraction fails (rejects), it automatically proceeds to the next handler in the chain, and so on, until one succeeds or all fail. This simplifies scenarios like role-based access control or flexible routing where multiple handler signatures might apply to a single route.
axum-extra/src/handler · high confidence
New in-memory key-value store example
Added a new example application demonstrating an in-memory key-value store built with Axum. The example showcases state management via the \State\ extractor, route composition using \Router\, and middleware integration including compression, request body limits, concurrency limiting, timeouts, and error handling. It also illustrates nested routing for admin endpoints with bearer token validation and structured logging setup.
examples/key-value-store · high confidence
New middleware utilities for request/response mapping and extractor-based validation
The \axum::middleware\ module now includes \from\_extractor\, \from\_fn\, \from\_fn\_with\_state\, \map\_request\, \map\_request\_with\_state\, \map\_response\, and \map\_response\_with\_state\ to create middleware from extractors or async functions, allowing request transformation, response mapping, and validation with optional state access. Additionally, \ResponseAxumBodyLayer\ is provided to map response bodies back to \axum::body::Body\, and \AddExtension\ is exported for adding extensions to requests.
axum/src/middleware · high confidence
New multipart file upload example
Added a new example demonstrating how to handle multipart form data uploads in Axum. The example provides a web interface for uploading multiple files and processes the incoming multipart stream, extracting field names, file names, content types, and byte data while enforcing a 250MB request body limit.
examples/multipart-form · high confidence
New response types and SSE improvements
Axum introduces \NoContent\ as a dedicated struct for 204 responses, replacing the implicit 200 status of the unit type \()\. The \Redirect\ type now supports \IntoResponseParts\, allowing it to be combined with bodies in tuples while correctly setting the status code and \Location\ header. Server-Sent Events (SSE) support has been enhanced with \Event::raw\ for custom payloads, stricter validation of event values, and improved handling of line endings and special characters in JSON data.
axum/src/response · high confidence
New response types for file attachments, streaming, and JSON
axum-extra introduces several new response types to simplify common HTTP patterns. The \Attachment\ type wraps a response body to force a file download via the \Content-Disposition\ header, including safe escaping of filenames to prevent header injection. \FileStream\ enables efficient streaming of large files with support for HTTP range requests. \ErasedJson\ allows returning JSON responses from handlers that do not know the concrete type at compile time, while \InternalServerError\ provides a safe way to return generic 500 errors without exposing internal details. Additionally, \MultipartForm\ allows building multipart/form-data responses, and new \JavaScript\, \Css\, and \Wasm\ response types automatically set the correct content types.
axum-extra/src/response · high confidence
New tracing-aka-logging example demonstrates TraceLayer configuration
Added a new example application that shows how to configure the \TraceLayer\ from \tower-http\ for HTTP requests. The example demonstrates setting up a custom span with matched paths, logging request start/end, body chunks, stream closure, and failures, while also configuring the tracing subscriber to log built-in rejections at the trace level.
examples/tracing-aka-logging · high confidence
New typed routing and resource helpers in axum-extra
The \axum-extra/src/routing\ module now provides \RouterExt\ with \typed\_get\, \typed\_post\, and other HTTP-method-specific routing methods that infer paths from structs implementing \TypedPath\, enabling compile-time verification of route definitions. It also introduces a \Resource\ helper for defining conventional CRUD routes (index, create, show, edit, update, destroy) and a \vpath!\ macro (on Rust 1.80+) to validate static paths at compile time, including checks for deprecated variable syntax.
axum-extra/src/routing · high confidence
Behavioural changes
Breaking changes to \#\[derive(FromRequest)\] and \#\[from\_request(via)\] behavior
The \\#\[from\_request(via(Extractor))\]\ attribute now uses the extractor's own rejection type instead of \axum::response::Response\, changing how errors are propagated. Additionally, \Option\<T\>\ fields in \\#\[derive(FromRequest)\]\ and \\#\[derive(FromRequestParts)\]\ now rely on \OptionalFromRequest\ / \OptionalFromRequestParts\ traits rather than silently converting all rejections to \None\ via \.ok()\, meaning extractors used with optional fields must implement these new traits to control when \None\ is returned versus an error.
axum-macros · high confidence
Graceful shutdown example now uses axum::serve
The graceful-shutdown example has been updated to use the \axum::serve\ API instead of the previous \Server\ builder. This change simplifies the server setup by removing the need for explicit re-exports and aligns the example with the current Axum serving mechanism, while retaining the graceful shutdown behavior that waits for in-flight requests to complete upon receiving a termination signal.
examples/graceful-shutdown · high confidence
Hello-world example updated to use new Router and serve API
The hello-world example has been updated to reflect recent API changes in the framework. It now uses the \Router::new().route()\ pattern instead of the previous routing DSL, and utilizes the new \axum::serve\ function for starting the server, replacing the older \Server\ re-export. This ensures the example remains compatible with the current library interface.
examples/hello-world · high confidence
Internal refactoring to support type-erased routing and new extraction traits
This change introduces internal infrastructure to support the new \FromRequestParts\ and \OptionalFromRequestParts\ extraction traits, which allow extractors to inspect request metadata (like headers) without consuming the body. The \Extension\ extractor now implements these traits to support optional extraction (\Option\<Extension\<T\>\>\) and acts as a \tower::Layer\ to inject state into request extensions. Additionally, a new \BoxedIntoRoute\ type-erased routing mechanism is added to optimize internal route handling, and the \ServiceExt\ trait is expanded to include a \handle\_error\ method for centralized error handling.
axum/src · high confidence
New request body size limiting and extractor infrastructure in axum-core
The \axum-core/src/extract\ module now includes a \DefaultBodyLimit\ layer that allows you to configure the maximum size of request bodies (defaulting to 2 MB) for extractors like \Bytes\, \String\, \Json\, and \Form\, with the ability to disable or customize this limit per route. This change also introduces the \FromRef\ trait for extracting sub-states, \OptionalFromRequest\ traits for handling optional extractor results, and new \FromRequest\ implementations for \BytesMut\ and \Extensions\, while ensuring that body-limiting is applied consistently via \into\_limited\_body\.
axum-core/src/extract · high confidence
New routing module with method filtering and service composition
The \axum/src/routing\ module has been restructured into distinct components to support method-based routing and service composition. This includes the introduction of \MethodFilter\ for matching HTTP methods (including CONNECT and QUERY), a new \MethodRouter\ for chaining handlers and services by method, and a \Router\ type that uses \Arc\ for efficient cloning. The routing logic now relies on \PathRouter\ for path matching via \matchit\, with dedicated files for handling futures (\future.rs\), making services (\into\_make\_service.rs\), and stripping prefixes for nested routes (\strip\_prefix.rs\).
axum/src/routing · high confidence
Refactor \#\[derive(FromRequest)\] to support custom via extractors and state inference
The \\#\[derive(FromRequest)\]\ macro has been refactored to allow users to specify a custom extractor via the \via\ attribute, enabling more flexible request extraction logic. Additionally, the macro now supports inferring the state type from field types and attributes, reducing the need for explicit state declarations, while still allowing manual override via the \state\ attribute. This change improves usability and flexibility for users defining custom extractors.
_axum-macros/src/from\request · high confidence
Refactored handler execution into dedicated future and service types
The handler module has been restructured to improve type safety and clarity. A new \future.rs\ module introduces specific future types (\IntoServiceFuture\ and \LayeredFuture\) to handle the asynchronous execution of handlers, separating the response mapping logic from the core handler trait. The \service.rs\ module now explicitly defines \HandlerService\, which implements the \tower::Service\ trait to bridge handlers with the request lifecycle. This change consolidates how handlers are converted into services via \into\_service\ and \with\_state\, ensuring that the underlying future types correctly map handler outputs to \Response\ objects while maintaining compatibility with existing routing and middleware layers.
axum/src/handler · high confidence
Removal of legacy \`App\` and \`RouteBuilder\` routing API
The \src/lib.rs\ file containing the original \App\, \RouteBuilder\, and \Handler\ traits has been deleted. This removes the previous routing API where applications were constructed via \app().at(...).get(...)\, replacing it with the newer \Router\-based approach (likely introduced in other parts of this change set). Users must migrate to the new routing DSL to define routes and handlers.
src · high confidence
Test coverage
Add form handling example with tests; Add testing example demonstrating in-process and live server testing; Added compile-fail tests for \\#\[debug\_handler\]\ macro; Added compile-fail tests for \\#\[derive(FromRequest)\]\ validation rules; Added compile-time validation tests for TypedPath macro errors; Added comprehensive test coverage for routing behavior; Added test for panic location in overlapping method routes; Added tests for debug\_middleware macro validation; Added tests for the \\#\[derive(FromRef)\]\ macro; Added tests for typed path macro capabilities; Expanded compile-time tests for \\#\[derive(FromRequest)\]\ and \\#\[derive(FromRequestParts)\]\; Expanded test coverage for \\#\[debug\_handler\]\ macro validation; New internal test helpers for state cloning, request building, and tracing capture.
Dependencies
Axum 0.8.9 release with updated dependencies
This update releases axum 0.8.9, axum-core 0.5.6, and axum-extra 0.12.6, along with axum-macros 0.5.1. The release includes dependency upgrades such as updating the \bytes\ crate to 1.7, \matchit\ to 0.9.2, and \tower-http\ to 0.6.8. Example projects have also been updated to use newer versions of their respective dependencies, including \askama\ 0.16, \diesel-async\ 0.9, and \jsonwebtoken\ 11.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 23 → 60 (+37.1)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 94 (-5.7)
- Architecture 99 (new)
- Maturity 51 → 54 (+2.8)
- Readiness 20 → 55 (+34.6)
- Security 3 → 60 (+56.7)
Resolved (44)
- Dimension evaluation failed
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 24 more
New (116)
- Boundary-crossing change coupling: form.rs ↔ query.rs (axum-extra/src/extract/form.rs)
- Change coupling: private.rs ↔ signed.rs (axum-extra/src/extract/cookie/private.rs)
- ClassTooLong: MethodRouter (axum/src/routing/method_routing.rs)
- Dependency advisory scan runs only on code events
- Dependency hygiene PARTLY measured — Cargo dependencies read, dependency currency not (crates.io unreachable)
- Duplicate functionality across crates. Both axum and axum_extra expose a Query extractor with an identical try_from_uri method. This suggests axum_extra is re-exporting or duplicating core functionality that should likely be unified or clearly distinguished (e.g., one being the standard and the other being a legacy/compatibility shim).
- Duplicated block (12 lines × 2) (axum-macros/src/attr_parsing.rs)
- Duplicated block (13–14 lines × 2) (axum-extra/src/extract/json_deserializer.rs)
- Duplicated block (15 lines × 2) (axum-macros/src/typed_path.rs)
- Duplicated block (16 lines × 2) (axum/src/routing/mod.rs)
- Duplicated block (17 lines × 2) (axum-macros/src/typed_path.rs)
- Duplicated block (20 lines × 2) (axum-extra/src/extract/multipart.rs)
- Duplicated block (20 lines × 2) (axum-macros/src/debug_handler.rs)
- Duplicated block (29 lines × 2) (axum-macros/src/typed_path.rs)
- Duplicated block (5 lines × 4) (axum-macros/src/attr_parsing.rs)
- Duplicated block (6 lines × 2) (axum-core/src/body.rs)
- Duplicated block (6 lines × 2) (axum-extra/src/extract/multipart.rs)
- Duplicated block (7 lines × 2) (axum-extra/src/extract/cookie/private.rs)
- Duplicated block (7 lines × 3) (axum/src/middleware/from_fn.rs)
- Duplicated block (8 lines × 2) (axum-macros/src/from_request/mod.rs)
- …and 96 more
Changes since last survey
- 33 commits — 31 feature/other, 2 fixes
By area
- .github/workflows — 12 commits
- axum/src — 7 commits
- axum/CHANGELOG.md — 4 commits
- axum-extra/src — 3 commits
- examples/Cargo.lock — 2 commits
- (root) — 1 commit
- axum/Cargo.toml — 1 commit
- examples/request-id — 1 commit
- examples/tracing-aka-logging — 1 commit
- examples/validator — 1 commit
Notable commits
- fix: fix(axum-extra): handle missing optional typed headers (#3886)
- fix: fix(axum-extra): preserve protobuf body buffering rejections (#3881)
- change: Adding way to SSE Event (and Buffer) test for equality (#3872)
- change: Avoid shared shutdown waiter contention (#3867)
- change: axum-extra: avoid multipart boundary collisions (#3804)
- change: axum: add suggested must_use
- change: axum: don't enable tokio/macros feature (#3864)
- change: axum: remove v07 path checks (#3889)
- change: axum: treat CRLF as a single SSE line ending (#3870)
- change: chore(deps): bump crate-ci/typos from 1.48.0 to 1.49.0 (#3862)
- change: chore(deps): bump crate-ci/typos from 1.49.0 to 1.50.0 (#3876)
- change: chore(deps): bump crate-ci/typos from 1.50.0 to 1.50.1 (#3883)
- change: chore(deps): bump crate-ci/typos from 1.50.1 to 1.50.2 (#3899)
- change: chore(deps): bump dtolnay/rust-toolchain from 2c7215f132e9ebf062739d9130488b56d53c060c to 6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 (#3868)
- change: chore(deps): bump dtolnay/rust-toolchain from 6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 to 02cb101ec7c40f2c49e1d9714d64511d8e1b74de (#3900)
- change: chore(deps): bump dtolnay/rust-toolchain from fa04a1451ff1842e2626ccb99004d0195b455a88 to 2c7215f132e9ebf062739d9130488b56d53c060c (#3839)
- change: chore(deps): bump release-plz/action from 0.5.131 to 0.5.133 (#3884)
- change: chore(deps): bump release-plz/action from 0.5.133 to 0.5.136 (#3893)
- change: chore(deps): bump release-plz/action from 0.5.136 to 0.5.139 (#3901)
- change: chore(deps): bump taiki-e/cache-cargo-install-action from 3.0.7 to 3.0.8 (#3861)
- …and 13 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
tokio-rs/axum was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 27 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit bc8d4912435204a4a073cea70355ae0328d263fe — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-7c1cb6328e11.