0Pricing
tRPC End-to-End Type Safe APIs · Lesson

Integrating Zod in tRPC Procedures

Apply Zod schemas directly to your tRPC query and mutation inputs for automatic validation.

Integrating Zod in tRPC Procedures is a free tRPC End-to-End Type Safe APIs lesson on CoddyKit — lesson 3 of 4. You can read the complete lesson below for free — then practise it hands-on in the browser with a built-in code editor and a 24/7 AI tutor. It is part of the tRPC End-to-End Type Safe APIs learning path, one of 4 lessons in the course, and your progress syncs across the web and the CoddyKit app.

Zod for tRPC Inputs

Welcome! In this lesson, we'll learn how to integrate Zod schemas directly into your tRPC procedures. This powerful combination ensures your API inputs are always valid and type-safe from end-to-end.

You'll see how to apply Zod for both query and mutation procedures, making your backend more robust and developer-friendly.

Why Validate Inputs?

Input validation is a critical part of building secure and reliable APIs. It's like a quality check at the entrance of your backend.

  • Security: Prevents malicious or malformed data from reaching your server logic.
  • Data Integrity: Ensures your database only stores valid and expected data formats.
  • Predictability: Your backend logic can trust the shape of incoming data, reducing runtime errors.
  • Better DX: Developers get immediate feedback on incorrect inputs.

The `.input()` Method

tRPC makes integrating Zod incredibly simple. Each tRPC procedure (query, mutation, or subscription) has an .input() method.

This method accepts a Zod schema, which tRPC then uses to automatically validate any incoming data for that procedure. If the input doesn't match the schema, tRPC handles the error for you!

Query Input Validation

For queries, you often expect parameters like an ID or a search term. Zod helps ensure these inputs are of the correct type and format.

Let's look at an example where we want to fetch a user by their unique ID. We'll use Zod to ensure the userId is a valid UUID string.

Query Procedure Example

Here's how you define a tRPC query procedure that uses a Zod schema to validate its input:

import { initTRPC } from '@trpc/server';
import { z } from 'zod';

// Minimal tRPC context setup
const t = initTRPC.create();

// Define a query procedure with Zod input validation
const getUserById = t.procedure
  .input(z.object({
    userId: z.string().uuid("Invalid user ID format"),
  }))
  .query(({ input }) => {
    // In a real app, this would fetch from a database
    console.log(`Fetching user: ${input.userId}`);
    return { id: input.userId, name: "Alice" }; // Mock data
  });

// To use this, you'd add it to a tRPC router, e.g.:
// export const appRouter = t.router({ getUserById });

Mutation Input Validation

Mutations often involve creating or updating data, which means they typically accept more complex input objects. Zod is perfect for validating these structures.

Consider a scenario where you want to create a new blog post. We'll validate its title and optional content to ensure they meet certain criteria.

Mutation Procedure Example

Here's a mutation procedure that validates input for creating a new post using a Zod object schema:

import { initTRPC } from '@trpc/server';
import { z } from 'zod';

// Minimal tRPC context setup
const t = initTRPC.create();

// Define a mutation procedure with Zod input validation
const createPost = t.procedure
  .input(z.object({
    title: z.string().min(5, "Title must be at least 5 characters"),
    content: z.string().optional(),
    authorId: z.string().uuid("Invalid author ID"),
  }))
  .mutation(({ input }) => {
    // This would typically save data to a database
    console.log(`Creating post: "${input.title}" by ${input.authorId}`);
    return { id: "new-post-uuid", ...input, createdAt: new Date() }; // Mock
  });

// To use this, you'd add it to a tRPC router, e.g.:
// export const appRouter = t.router({ createPost });

Automatic Validation Errors

One of the biggest advantages of integrating Zod directly with tRPC is automatic error handling.

  • If a client sends input that doesn't match your Zod schema, tRPC will automatically catch the validation error.
  • It then sends a standardized BAD_REQUEST error response to the client, including details about why the validation failed.
  • This means you don't need to write manual try/catch blocks for basic input validation!

Benefits of Direct Integration

Combining Zod with tRPC's .input() method provides several powerful benefits:

  • End-to-End Type Safety: Your Zod schema defines the exact input type, which tRPC automatically infers and shares with your client.
  • Single Source of Truth: Define validation rules once, and they apply on both the server (runtime) and client (compile-time).
  • Reduced Boilerplate: No need for manual validation checks or separate DTOs (Data Transfer Objects).
  • Clear API Contracts: Your procedures clearly state their input requirements through their Zod schemas.

Quick Check: Zod in tRPC

You've learned how Zod schemas are integrated into tRPC procedures. Let's test your understanding!

Recap: Zod & tRPC Synergy

Great job! You've successfully learned how to integrate Zod schemas into your tRPC procedures.

  • We saw that the .input() method is key for applying Zod schemas to both queries and mutations.
  • This integration provides automatic validation, end-to-end type safety, and clear API contracts.
  • By leveraging Zod within tRPC, you build more robust, secure, and developer-friendly APIs with less effort.

Next up, we'll explore more advanced Zod schemas!

Frequently asked questions

Is the “Integrating Zod in tRPC Procedures” lesson free?

Yes — the full text of “Integrating Zod in tRPC Procedures” is free to read here on the web, and the tRPC End-to-End Type Safe APIs course includes 4 lessons in total. To practise it interactively (a built-in code editor and a 24/7 AI tutor) and unlock the rest of the tRPC End-to-End Type Safe APIs course, upgrade to CoddyKit PRO.

What will I learn in “Integrating Zod in tRPC Procedures”?

Apply Zod schemas directly to your tRPC query and mutation inputs for automatic validation. You practise tRPC End-to-End Type Safe APIs with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.

Do I need any experience to start tRPC End-to-End Type Safe APIs?

No prior experience is required. tRPC End-to-End Type Safe APIs on CoddyKit is structured for beginners through advanced learners; this is — lesson 3 of 4, so you can start here or from the beginning and move at your own pace.

How long does the “Integrating Zod in tRPC Procedures” lesson take?

Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.

Can I write and run code in this tRPC End-to-End Type Safe APIs lesson?

Yes. Every tRPC End-to-End Type Safe APIs lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.

All lessons in this course

  1. Introduction to Zod Schemas
  2. Defining Complex Zod Schemas
  3. Integrating Zod in tRPC Procedures
  4. Transforming and Refining Zod Data
← Back to tRPC End-to-End Type Safe APIs