# opensrc: giving coding agents the source code behind npm packages

> opensrc is a Rust CLI that downloads and caches package source from npm, PyPI, crates.io and GitHub so an agent can read real implementations instead of guessing from type signatures. It is small, useful, and thinner on documentation than its ambition suggests.

**vercel-labs/opensrc** — Fetch source code for npm packages to give AI coding agents deeper context

- Repository: https://github.com/vercel-labs/opensrc
- Website: https://opensrc.sh
- Stars: 3,005 · Forks: 194
- Language: Rust
- License: Apache-2.0
- Published: 2026-09-09 · Updated: 2026-09-09 · Language: en
- Canonical page: https://hysenlabs.com/projects/vercel-labs-opensrc

## The gap opensrc fills between type signatures and real code

An AI coding agent working in a Node project usually sees node_modules, which contains transpiled or bundled output, and it sees type declarations. Neither shows what a function actually does at runtime. The README states the goal plainly: give coding agents access to any package's source code. The tool is aimed at people running coding agents, not at people debugging a dependency by hand, although the CLI works the same way for both.

The design choice that matters is that opensrc resolves a package identifier to a filesystem path. It does not print source to stdout, does not build an index, and does not modify your project. The README's examples all follow the same shape: substitute the path into an existing Unix command such as rg, cat or find. That keeps the tool composable and keeps the agent's context window under your control, because the agent decides what to read rather than receiving a dump. It also means opensrc has no opinion about which registry you use. The README shows the same command against npm and against PyPI with a prefixed identifier.

## How opensrc path works: fetch on first use, then a cached path

The mechanism described in the README is a two-stage lookup. On first use, opensrc fetches the package source and stores it. On subsequent calls, opensrc path returns the cached path immediately. The README does not describe the cache directory layout, the eviction policy, or how a cached entry is invalidated when a package publishes a new version, so treat those as open questions rather than settled behaviour.

Registry selection is encoded in the identifier. A bare name such as zod resolves through npm. A prefixed name such as pypi:requests resolves through PyPI. The README's package table lists npm, PyPI, crates.io and GitHub as supported sources, which suggests the prefix scheme extends to the other two, but the README only demonstrates npm and pypi: forms. If you need crates.io or GitHub resolution, check the CLI readme in packages/opensrc before assuming a prefix.

The repository itself is a Turborepo monorepo managed with pnpm workspaces. The CLI lives under packages/opensrc/cli and is written in Rust, while the documentation site is a Next.js app under apps/docs. That split explains the tool's character: a fast native binary for the fetch-and-cache path, with the surrounding packaging handled by npm.

## Installing opensrc and reading your first package

The README gives a single global install command. It requires a Node toolchain on the machine even though the CLI itself is Rust, because the distribution path is npm.

```bash
npm install -g opensrc
```

After that, the first useful check is resolving a package you already know. The README uses zod as its example. The first call fetches; the documentation states that later calls return the cached path instantly, so a second invocation should be noticeably faster and should print the same directory.

```bash
opensrc path zod
```

With a path in hand, the README's pattern is to hand it to your existing search and read tools. This searches the fetched source for the string parse and prints matching lines, which is usually the fastest way to answer "how does this actually work" without loading whole files into an agent's context.

```bash
rg "parse" $(opensrc path zod)
```

The same substitution works for reading one file, and for other registries. The README shows a Python example using the pypi: prefix and find rather than rg. Note that the README does not document a way to pin a specific package version in the identifier, so if you need reproducible source for a pinned dependency, verify that against the CLI readme first.

## Where opensrc is the wrong tool

opensrc is a convenience layer, not a supply-chain control. The README does not document signature verification, provenance attestation, or a lockfile for fetched source. If your requirement is that every byte an agent reads is reproducible and auditable, this tool does not currently claim to give you that, and the README is silent on the subject.

The cache is the second limitation. "Fetches on first use, then returns the cached path instantly" is a good default for interactive work and a poor one if you are reasoning about a package that published a fix an hour ago. The README does not document a flag to force a refresh, a TTL, or a way to inspect what is cached. An agent that reads stale source will produce confidently wrong answers, and nothing in the described workflow warns it.

There is also a scope mismatch worth naming. If your agent already has the package installed and the published artifact ships readable source, node_modules may be sufficient and opensrc adds a second copy on disk. The tool earns its place when the published artifact is bundled or minified, when you are reading a package that is not a dependency of the current project, or when you are working across registries in one session.

## opensrc compared with reading node_modules or vendoring source

The obvious alternative is to point the agent at node_modules. The difference is what is actually in there. Published npm packages frequently ship compiled JavaScript, and the original TypeScript or Rust is either absent or present only as declarations. opensrc fetches source, which is a different artifact from what the runtime executes, and that distinction cuts both ways: you get readable implementation, but you may be reading code that does not exactly match the shipped build.

A second alternative is vendoring: clone the repository into your project and let the agent read it. That gives you version control, a pinned commit, and a diff you can review. It also means every package you care about becomes a directory you maintain, and cross-registry work turns into a pile of clones. opensrc trades that control for a one-line lookup. The trade is reasonable for exploratory agent work and weaker for anything you need to reproduce later.

A third option is documentation retrieval: feeding the agent the project's docs site instead of its code. That is cheaper in tokens and usually more stable, but it cannot answer questions the docs never addressed, which is exactly the situation where an agent starts inventing APIs.

## Licence, maintenance and what upgrading costs

The repository is Apache-2.0, and the README repeats that identifier in its License section. Apache-2.0 includes an explicit patent grant and requires that notices be preserved, which matters if you redistribute the CLI inside a product. Fetching a third-party package's source does not change that package's own licence, and opensrc does not appear to surface licence metadata for what it fetches. If your agent reads GPL-licensed source and reproduces it into your codebase, opensrc has not done anything wrong, but it has also not warned you. This is not legal advice; check with counsel if that scenario is realistic for your team.

The last push to the default branch was on 2026-06-23, which is under three months before today, and the most recent release is v0.7.3 from the same date. The version history shows v0.7.1 on 2026-04-09 and v0.7.2 on 2026-04-18, so the project has been shipping point releases at a moderate pace rather than sitting still. Nothing in the repository indicates an LTS branch or a compatibility promise, so treat upgrades as cheap but not risk-free: the CLI surface shown in the README is small, which limits the blast radius of a breaking change.

## Conclusion

Adopt opensrc if your coding agent keeps inventing APIs and you want it reading the actual implementation from npm, PyPI, crates.io or GitHub. Skip it if you need deterministic, offline, auditable dependency resolution, because the README does not document cache invalidation, provenance or rollback. Before rolling it out, run opensrc path zod on a package you know well and check whether the returned directory is the published artifact or a repository checkout.

## FAQ

### What is the opensrc open source project?

It is a CLI from vercel-labs that fetches and caches package source code so coding agents can read it. The README describes it as giving coding agents access to any package's source code, with npm, PyPI, crates.io and GitHub listed as sources.

### How do you use opensrc?

Install it globally with npm install -g opensrc, then call opensrc path with a package name to get a directory you can pass to rg, cat or find. The README notes that the first call fetches and later calls return the cached path instantly.

### Does opensrc work with registries other than npm?

Yes. The README's package table lists npm, PyPI, crates.io and GitHub, and it demonstrates a PyPI lookup using the pypi: prefix. Only the npm and pypi: forms appear in the README examples.

### Can you pin a specific package version with opensrc?

The README does not document version pinning in the package identifier, and it does not describe cache invalidation or a refresh flag. Check the CLI readme under packages/opensrc if reproducible versions matter to you.

### What language is opensrc written in?

The CLI is Rust and lives at packages/opensrc/cli, with build and test commands run through Cargo. The surrounding monorepo is a Turborepo workspace managed with pnpm, and the documentation site is a Next.js app.

### What licence does opensrc use?

The repository is licensed under Apache-2.0, and the README's License section states the same. That covers opensrc itself, not the third-party source it fetches.

## Sources

- [License: Apache-2.0](https://github.com/vercel-labs/opensrc/blob/main/LICENSE)
- [Project website](https://opensrc.sh)
- [README](https://github.com/vercel-labs/opensrc/blob/main/README.md)
- [Releases](https://github.com/vercel-labs/opensrc/releases)
- [vercel-labs/opensrc on GitHub](https://github.com/vercel-labs/opensrc)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/vercel-labs-opensrc
