Library / SDK
rust-lang/crates.io avatar
rust-lang/crates.io

crates.io: Inside the Official Rust Package Registry

The Rust package registry

3,703 stars751 forksRustApache-2.0

At a glance

What is it?
crates.io is the official package registry for the Rust programming language, and this repository is its source code. The backend is written in Rust using the axum web framework and diesel for database access; the frontend is a SvelteKit application in TypeScript. Understanding how the registry is built is useful for contributors and for teams that need to run a private registry with the same architecture.
Who is it for?
This repository is for developers who want to contribute to crates.io, run a local development instance, or understand how the registry itself works. It is not the tool Rust developers use to publish or download crates: that is cargo, which calls the crates.io API.
Can I use it commercially?
Yes. Apache-2.0 is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 2 days ago.
What is it written in?
Mainly Rust, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 27, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What crates.io Is and Its Place in the Rust Ecosystem

crates.io serves as the central registry for sharing 'crates,' which are packages or libraries written in Rust. When a Rust developer runs `cargo add serde` or `cargo publish`, those operations hit the crates.io API. The registry stores the metadata and file contents of every published crate. The README describes it as serving the entire Rust ecosystem and being maintained by the crates.io team with support from the Rust Foundation. File hosting is donated by Amazon Web Services and CDN services by Fastly. This means the registry is not a simple static file host: it has a backend service, a database, a frontend web application, a background worker system, and a content delivery layer. The project is dual-licensed under MIT and Apache 2.0, consistent with Rust's own licensing approach. Contributions to the registry are community-driven, with governance through the named crates.io team and GitHub Discussions for feature proposals.

Backend Architecture: axum, diesel, and a Custom Background Worker

The backend of crates.io is written in Rust. The README identifies two primary libraries: axum as the web framework and diesel for database access. The repository's Cargo.toml shows a workspace structure with multiple crates under the crates/ directory. One notable component is what the README calls 'a custom-built background worker system' (crates/crates_io_worker), which handles asynchronous tasks that should not block API responses. The Cargo.toml workspace includes standard Rust tool configuration: strict clippy lints, warnings for unused imports, and opt-level tuning for specific crates in the test profile. The .env.sample file documents the expected runtime configuration. Two environment variables are required: DATABASE_URL pointing to a PostgreSQL instance and SESSION_KEY set to a long random string of at least 32 bytes. The .env.sample also includes optional configuration for TEST_DATABASE_URL, POSTGRES_BIN_DIR, AWS_ACCESS_KEY and AWS_SECRET_KEY for S3 uploads, S3_BUCKET, and S3_REGION. The project targets Rust's 2024 edition. The Cargo.toml records release builds with opt-level 2, and the dev profile applies optimizations to crypto and hashing crates to speed up database connection setup in the test suite.

Frontend: SvelteKit and TypeScript

The frontend is a SvelteKit application written in TypeScript, living in the svelte/ directory. The package.json at the root defines the browser targets (last 2 Chrome, last 1 Firefox, Firefox ESR, last 1 Safari, Edge, iOS, and UCAndroid), prettier configuration, and end-to-end test setup using Playwright with Percy for visual testing and MSW for request mocking. ESLint is configured with the unicorn and svelte plugins. The pnpm-workspace.yaml and pnpm-lock.yaml indicate the project uses pnpm for JavaScript dependency management. The frontend and backend are developed in the same repository, which is unusual for a large public web service but simplifies local development for contributors.

Setting Up a Local Development Environment

The README points to CONTRIBUTING.md and AGENTS.md for full setup instructions; AGENTS.md contains additional structured documentation specifically for AI-assisted contributors. The .env.sample file shows the minimum required variables: DATABASE_URL pointing to a PostgreSQL instance, WEB_ALLOWED_ORIGINS for CORS configuration (set to http://localhost:8888,http://localhost:4200 by default), and SESSION_KEY for cookie encryption. The sample also documents optional variables: DOMAIN_NAME for non-crates.io deployments, TEST_DATABASE_URL for the test suite, POSTGRES_BIN_DIR for specifying which PostgreSQL binary version to use, and AWS credentials for S3 integration. The project uses a Justfile for common development tasks and a mise.toml for managing tool versions, which ensures contributors use consistent versions of Rust, Node.js, pnpm, and other toolchain components. The Procfile indicates a Heroku-compatible process model. The end-to-end test suite uses Playwright and requires the Svelte frontend; the playwright.config.ts at the project root configures those tests. Percy integration provides visual regression tests as part of the CI pipeline.

What This Repository Is and Is Not

A common point of confusion: this repository is the source code of the crates.io web service, not the client-side tooling for using crates. Rust developers who want to install or publish crates use `cargo`, which is part of the Rust toolchain and lives in a separate repository. This repository is relevant to developers who want to contribute to the registry's web interface, fix bugs in the API, or understand how the registry handles crate publication and search. It is also relevant to organizations that want to run a private registry with the same codebase, though the README does not document a supported self-hosting path: it describes a contribution and development workflow, not an operator guide. The repository includes database migrations under migrations/, which shows the full schema evolution of the registry. The top-level Cargo.lock file pins all Rust dependencies to exact versions, consistent with how application-level Rust projects are expected to manage lockfiles.

Security, Usage Policy, and Governance

The README links to a Usage Policy at crates.io/policies and a security disclosure process at crates.io/policies/security. The crates.io team is listed as a governance body under Rust's team structure, with a support channel on Zulip at #t-crates-io and an email address at [email protected]. The Code of Conduct refers to the broader Rust community Code of Conduct. For feature requests and general discussions, the README directs users to GitHub Discussions rather than the issue tracker, which is reserved for bugs and technical problems. This governance model matches other Rust project infrastructure: community-driven, with a named team responsible for maintenance and a foundation supporting infrastructure costs.

crates.io vs lib.rs

lib.rs is an independent alternative index for Rust crates that presents the same underlying registry data in a different way. It adds a curated quality ranking, categorizes crates differently from the official taxonomy, and offers a more opinionated search experience. crates.io is the authoritative source: all crates must be published there, and lib.rs reads from the same index. A developer who publishes a crate does not choose between them; crates.io is the publication endpoint, and lib.rs is an optional discovery layer on top. The difference is discovery UX, not functionality: cargo always resolves crates through the official crates.io index regardless of how a developer found the crate.

Editorial conclusion

This repository is for developers who want to contribute to crates.io, run a local development instance, or understand how the registry itself works. It is not the tool Rust developers use to publish or download crates: that is cargo, which calls the crates.io API. The source code is dual-licensed MIT and Apache 2.0. Before contributing, check the CONTRIBUTING.md and AGENTS.md files, which contain the structured local environment setup instructions and the project's conventions for both human contributors and AI agents.

Frequently asked questions

What is crates.io?

crates.io is the official package registry for the Rust programming language, where developers publish and find crates (Rust packages). This repository contains the source code of the registry itself, not the cargo client tool used to interact with it.

How do I install a Rust crate?

Rust crates are installed using cargo, which is part of the official Rust toolchain. Running `cargo add serde` adds a dependency to your project; `cargo install` installs a binary crate. These commands use the crates.io registry by default.

How does crates.io compare to lib.rs?

crates.io is the authoritative registry that all Rust crates must be published to. lib.rs is an independent index that reads the same data but applies its own ranking and categorization. Publishing always targets crates.io; lib.rs is an alternative discovery interface.

Is crates.io safe to use?

crates.io is the official Rust package registry maintained by the crates.io team under the Rust Foundation. It has a usage policy at crates.io/policies and a security disclosure process at crates.io/policies/security. As with any public package registry, individual crates are published by community members, so reviewing a crate's source code and its dependency chain is advisable before use.

Official sources

  1. Issues
  2. License: Apache-2.0
  3. Project website
  4. README
  5. rust-lang/crates.io on GitHub
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/rust-lang-crates-io.svg)](https://hysenlabs.com/projects/rust-lang-crates-io)