DTOs and Validation Pipes
Implement Data Transfer Objects (DTOs) and use validation pipes to ensure incoming request data meets defined criteria.
DTOs and Validation Pipes is a free NestJS Enterprise Backend APIs lesson on CoddyKit — lesson 2 of 3. You can read the complete lesson below for free — then practise it hands-on in the browser with a built-in code editor and a 24/7 AI tutor. It is part of the NestJS Enterprise Backend APIs learning path, one of 3 lessons in the course, and your progress syncs across the web and the CoddyKit app.
Why Data Transfer Objects?
When building APIs, your application receives data from users. This data needs to be structured and safe.
Data Transfer Objects (DTOs) are plain classes that define the expected shape of the data coming into your application (e.g., from a request body) or going out (e.g., as a response).
Using DTOs helps with:
- Clarity: Clearly shows what data is expected.
- Consistency: Ensures data adheres to a specific format.
- Security: Prevents unexpected or malicious data from being processed.
Defining a Simple DTO
A DTO is essentially a TypeScript class with properties that match the data you expect. It's a blueprint for your data.
Here's a basic example for creating a new product:
export class CreateProductDto {
name: string;
description: string;
price: number;
}DTOs in NestJS Context
In a NestJS application, you'll typically create DTO files in a dto folder within your module (e.g., src/products/dto/create-product.dto.ts).
These classes are then used in your controllers to type the incoming request body.
import { Body, Controller, Post } from '@nestjs/common';
import { CreateProductDto } from './dto/create-product.dto';
@Controller('products')
export class ProductsController {
@Post()
create(@Body() createProductDto: CreateProductDto) {
// createProductDto will have 'name', 'description', 'price'
console.log(createProductDto);
return 'Product created!';
}
}Why Validate Input?
Just defining a DTO isn't enough. What if a user sends invalid data?
- A
namethat's too short? - A
pricethat's negative or not a number? - Missing required fields?
Without validation, your application could:
- Store bad data.
- Crash unexpectedly.
- Be vulnerable to security exploits.
This is where NestJS Validation Pipes come in!
Introducing Validation Pipes
A Validation Pipe is a special type of middleware in NestJS that automatically validates incoming request data against your DTO definitions.
If the data doesn't match the rules you've set, the pipe will automatically throw an error, preventing invalid data from reaching your controller logic.
The Validation Duo: `class-validator` & `class-transformer`
NestJS leverages two powerful libraries for DTO validation:
class-validator: Provides decorators (like@IsString(),@IsInt()) to define validation rules directly on your DTO properties.class-transformer: Helps convert plain JavaScript objects (from the request body) into instances of your DTO classes, which is crucial forclass-validatorto work correctly.
You'll need to install them:
npm i class-validator class-transformer
Decorating Your DTOs for Validation
Let's add some validation rules to our CreateProductDto using decorators from class-validator.
These decorators ensure that the incoming data meets specific criteria, like being a string, a number, or not empty.
import { IsString, IsNumber, IsNotEmpty, IsPositive } from 'class-validator';
export class CreateProductDto {
@IsString()
@IsNotEmpty()
name: string;
@IsString()
@IsNotEmpty()
description: string;
@IsNumber()
@IsPositive()
price: number;
}Applying `ValidationPipe` to a Route
Now that our DTO has validation decorators, we need to tell NestJS to use the ValidationPipe for a specific route.
You can apply it using the @UsePipes() decorator on your controller method. This makes the pipe active only for that particular route.
import { Controller, Post, Body, UsePipes, ValidationPipe } from '@nestjs/common';
import { CreateProductDto } from './dto/create-product.dto';
@Controller('products')
export class ProductsController {
@Post()
@UsePipes(new ValidationPipe()) // Apply pipe here
create(@Body() createProductDto: CreateProductDto) {
// If validation fails, this code won't run
return `Product '${createProductDto.name}' created!`;
}
}Global Validation Pipe
Applying @UsePipes(new ValidationPipe()) to every method can be repetitive. For consistency, you can register the ValidationPipe globally in your main.ts file.
This will apply the validation pipe to all incoming requests across your entire application, simplifying your code and ensuring consistent validation.
import { NestFactory } from '@nestjs/core';
import { AppModule } from './app.module';
import { ValidationPipe } from '@nestjs/common';
async function bootstrap() {
const app = await NestFactory.create(AppModule);
app.useGlobalPipes(new ValidationPipe()); // Apply pipe globally
await app.listen(3000);
}
bootstrap();Check Your Knowledge
Time to test what you've learned about DTOs and Validation Pipes!
Recap: DTOs & Validation Pipes
You've mastered DTOs and Validation Pipes!
- DTOs are TypeScript classes that define the structure of data for your API.
- They bring clarity, consistency, and security to your data handling.
- Validation Pipes automatically enforce rules defined by
class-validatordecorators. class-transformerensures incoming data is converted to DTO instances for validation.- Pipes can be applied per-route with
@UsePipes()or globally inmain.ts.
This ensures your NestJS API always receives and processes clean, valid data.
Frequently asked questions
Is the “DTOs and Validation Pipes” lesson free?
Yes — the full text of “DTOs and Validation Pipes” is free to read here on the web, and the NestJS Enterprise Backend APIs course includes 3 lessons in total. To practise it interactively (a built-in code editor and a 24/7 AI tutor) and unlock the rest of the NestJS Enterprise Backend APIs course, upgrade to CoddyKit PRO.
What will I learn in “DTOs and Validation Pipes”?
Implement Data Transfer Objects (DTOs) and use validation pipes to ensure incoming request data meets defined criteria. You practise NestJS Enterprise Backend APIs with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.
Do I need any experience to start NestJS Enterprise Backend APIs?
No prior experience is required. NestJS Enterprise Backend APIs on CoddyKit is structured for beginners through advanced learners; this is — lesson 2 of 3, so you can start here or from the beginning and move at your own pace.
How long does the “DTOs and Validation Pipes” lesson take?
Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.
Can I write and run code in this NestJS Enterprise Backend APIs lesson?
Yes. Every NestJS Enterprise Backend APIs lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.
All lessons in this course
- Dependency Injection Explained
- DTOs and Validation Pipes
- TypeORM Integration Basics