Zod 4.5
Colin McDonnell··14 min read
Zod 4.5 is now available.
At a glance:
z.compile()— the flagship feature of Zod 4.5z.creditCard()— 12–19 digits plus Luhn checksumz.properties()— the multi-property counterpart toz.property()z.deepPartial()/.exactPartial()z.validate(): boolean— a fast-path to verify input validity without a full parse (up to 16x faster on invalid data)- 9x reduction in memory footprint
- New locales: Bengali (
bn), Central Kurdish (ckb), Hindi (hi), Kannada (kn), Norwegian Nynorsk (nn), Brazilian Portuguese (pt-BR), Slovak (sk), Turkmen (tk)
z.compile()
You can now pre-compile any Zod schema using z.compile(schema). This dramatically speeds up parsing performance.
A compiled schema can be used exactly like an uncompiled one. There are no special rules around compiled schemas. They're just faster.
On objects, arrays, and unions, this speeds up parsing by a factor of ~3–7. More complex schemas stand to benefit more than simpler ones.
Below are the Moltar benchmark results comparing Zod (compiled and uncompiled) against the Moltar ParseSafe bench.
And the equivalent results for the Moltar AssertLoose bench. Tested against the new z.validate(schema, input) function (detailed later in the post).
Zod's entire test suite runs twice—once normally and again with auto-compilation enabled globally—to ensure perfect fidelity.
import "zod/compile"
To compile every schema in an application, import zod/compile once at the top of your entry point. Every schema constructed after that import is automatically compiled the first time it's used to parse data.
It also works as a Node.js CLI flag, which guarantees it runs before any module defines a schema:
Or set preload in bunfig.toml or nub.jsonc.
All schemas benefit to varying degrees, though complex object/tuple/array schemas benefit more than simple scalar validators.
z.compile()z.creditCard()
A new string format: 12–19 digits, optionally separated by single spaces or hyphens, with a valid Luhn checksum. (#5931)
z.properties()
The multi-property counterpart to z.property(). (#5912)
z.deepPartial()
Back in functional form after being removed as a method in Zod 4. (#5928)
The result is still a ZodObject, so .shape and .extend() keep working.
.exactPartial()
Like .partial(), but wraps each field in z.exactOptional() instead of z.optional(): keys may be omitted, but an explicit undefined is rejected. This matches TypeScript's Partial<> under exactOptionalPropertyTypes. (#6065)
In Zod Mini it's a top-level function: z.exactPartial(Recipe).
z.validate()
Standalone boolean validation, in Zod, Zod Mini, and Zod Core. It answers "is this input valid?" without constructing a ZodError, which makes rejection cheap: on invalid input it is up to 16x faster than .safeParse().success. The return type is a guard on the schema's input type, and z.validateAsync() covers schemas with async refinements. (#6471)
z.input() / z.output()
Project a schema onto its input or output side. Useful for validating the two halves of a codec independently. (#5928)
This is a no-op on schemas not containing codecs/pipes.
z.toZod<T>()
A utility to define a Zod schema that agrees exactly with a static type, often one that is handwritten or externally defined. (#5913)
z.getDiscriminatedOption()
Extract a discriminated union member by discriminator value. (#5947)
Cyclical inputs
Zod recursive schemas now support cyclical data. For bundle size reasons, Zod Mini requires you to register a memoizer explicitly. (#6387, #6482)
9x reduction in schema memory footprint
In Zod 4.4 a bare z.string() retained 7.5kb of heap. In Zod 4.5 it retains 784 bytes.
In Zod 4.4 and earlier, all schema methods were automatically bound to the instance itself. This allowed users to pluck methods from schemas without causing issues due to this-binding.
A consequence of this is that each bound method allocates space on the heap; method implementations are not shared across all instances via prototype, as you'd expect. Zod 4.5 implements a method memoization pattern that avoids allocating bound methods until they are actually accessed.
Faster failures
Zod .parse()/.safeParse() instantiates a JavaScript Error, which captures a stack trace. In the case of validation failures, this is often much slower than the parsing logic itself. When using .safeParse(), Zod no longer captures this stack trace, speeding up failure-path parses by a factor of ~7.5x. (#6316, #6450)
Symbol keys in z.object()
A shape can now declare a symbol key. TypeScript tracks it: a const symbol infers as unique symbol, so z.infer makes the key required and checks its value type. Undeclared symbol keys are still ignored. (#6448)
Bug fixes
All of these fix soundness issues, so a schema that relied on the old behavior may now reject input it used to accept.
⚠️ z.iso.datetime() requires seconds
RFC 3339 mandates seconds. z.iso.datetime() and z.iso.datetime({ offset: true }) no longer accept minute-precision input like 2020-01-01T06:15Z. local: true still admits 2020-01-01T06:15, since an unqualified datetime is outside RFC 3339 either way. (#6457)
To accept both forms, union the two precisions:
⚠️ String length counts code points
.min(), .max(), and .length() counted UTF-16 code units, so z.string().max(5) rejected five emoji. They now count Unicode code points, which is what every non-JS consumer of a length bound does (Postgres, MySQL, Go, Python, and the maxLength that z.toJSONSchema() emits). .max() only loosens; .min() and .length() tighten for astral input. Graphemes are unchanged — a ZWJ sequence is still several code points. (#6441)
Closes #3355.
⚠️ Record keys and intersections match TypeScript
A record's key schema now governs only the keys that match it, the way TypeScript treats an index signature. Intersecting an object with a pattern-keyed record no longer rejects the object's own keys. (#6412)
Separately, an unrecognized_keys issue no longer aborts the schema it came from, so a strict object with an extra key and a bad value now reports both issues instead of just the first. Closes #2200, #2573, #4017, #5663.
⚠️ __proto__ is always stripped
Object and record parsers now drop a __proto__ key whether it comes from the input, is declared by the schema, or is produced by a record key transform. A key that a record's key schema normalizes to __proto__ is dropped too. .strict() reports an own __proto__ input key as unrecognized_keys instead of silently swallowing it. Error formatters and both JSON Schema converters use own-property writes so a toString or constructor path segment can't walk onto Object.prototype (#6213, #6367, #6346). (#6386, #6354, #6355, #6221)
⚠️ Stricter string formats
z.ipv6()validated by handing the string tonew URL(), which let::@1\and::1\nthrough. It now checks the address alphabet directly (#6442).z.ulid()restricts the first character to0–7; anything higher overflows the 48-bit timestamp. A fixture that doesn't start with a real timestamp, such as one with a leading letter, is now rejected (#6095).z.httpUrl()enforces the RFC 1035 length limits on the host, matchingz.hostname()(#6035).z.emoji()no longer backtracks exponentially on a failed match (#6347).z.string().includes(sub, { position: N })emits a JSON Schema pattern that allows at least N leading characters, matchingString.prototype.includes(#6024).
Commits
Zod 4.5 rolls up 155 commits. Thanks to everyone who contributed: @dokson, @deepshekhardas, @zirkelc, @francisjohnjohnston-web, @MerlijnW70, @codinsonn, @oimo23, @JSap0914, @zelinewang, @abhishek-chaudhary2003, @spokodev, @Mohammad-Faiz-Cloud-Engineer, @hamed-bavar, @MGPOCKY, @ChiChuRita, @dinwwwh, @thristhart, @tsmartin9, @vedanshshetti, @belicam, @frastefanini, @andersk, @musaddiq-rafi, @tachmyratsaparmyradov, @arvindfroi, @KUMachine, @spidersouris, @catdalfonso, @mneetika, @gwagjiug, @MahinAnowar, @MaksZhukov, @emmayusufu, @agcty, @devareddy05, @Vish05, @yamcodes, @mattiasahlsen, @samchungy, @ozzyfromspace, @udohjeremiah, @patrickwehbe, @gajus, @Harm-Nullix, @thwbh, @IdanGonen, @irfanfandi, @JuerGenie, @marcalexiei, @itsahmedbilal, @DucMinhNe, @meliharik.
9782f87cperf(v4): validate without building the output, and keep schemas out of dictionary mode (#6480) by @colinhacks773a4867refactor(v4): declare a trait's members on $constructor (#6478) by @colinhacks68fb3f13feat(v4): make z.compile() fall back instead of throwing (#6479) by @colinhacks37b01501feat(v4): add z.isValid and z.isValidAsync (#6471) by @colinhacks749f5452docs: add fullproduct.dev to v4 ecosystem page (#6001) by @codinsonn24cdb7fdperf(v4): close the fastpass bindings into the compiled parser (#6464) by @colinhacks8d896186fix(v4): stop emitting a multipleOf that JSON Schema rejects (#6468) by @colinhacks43f729dbfeat(v4): make a tuple's items optional with .partial() (#6465) by @colinhacks97edaf7dfix(v4): don't throw from safeParse on bigint multipleOf(0n) (#6466) by @colinhacks21a6f0cbfeat(v4): let z.nanoid() take a custom length (#4004) by @oimo239d5b20effix(v4): restrict the first ULID character to [0-7] (#6095) by @JSap09141cf9cd09docs: record that error maps run per parse, and how to translate at render by @colinhacks7ce3e77dfix(v4): run a wrapper's inner schema on its own payload (#6462) by @colinhacks7b612b53fix(v4): fold an intersection of object schemas into one object (#6461) by @colinhacks1c43b774docs(v4): record why the failure path is not worth compiling by @colinhacksbadf0b78fix(v4): build the catch context from the input that failed (#6192) by @zelinewanga87ac366fix(v4)!: distinguish number and bigint formats at the type level (#6052) by @abhishek-chaudhary20036726c1dddocs: record what z.input and z.output do with transforms and wrappers by @colinhacks7cfc0122fix(v4): keep a wrapper's stored value only on the side it belongs to by @colinhacksa825c1b0fix(v4): empty enums and literals match nothing (#6459) by @colinhacks7c070db9feat(v4): expose the function schema on .implement() results (#6267) by @deepshekhardas3a496968fix(v4): make record input keys optional when the value can fill them (#6460) by @colinhacks53cec2a0fix(v4): resolve z.input past a preprocess transform by @colinhacks2125d30cfix(v4): accept exact decimal multiples in multipleOf (#6223) by @spokodev168122fcfix(v4): carry a pipe's own checks through z.output by @colinhacks51a1368afix(v4): let the includes(position) pattern match at or after the offset (#6024) by @francisjohnjohnston-web72a05c4ffeat(v4): expose stringbool truthy/falsy/case via _zod.bag (#6357) by @hamed-bavar036b39f4fix(v4)!: require seconds once a datetime carries a Z or an offset (#6457) by @colinhacks5825605eperf(v4): skip the eager stack capture when building a ZodError (#6450) by @colinhacksd85472c4feat(v4): support declared symbol keys in z.object() (#6448) by @colinhacksd4108872fix(v4): correct the date/time format keywords in both JSON Schema directions (#6452) by @colinhacks555e5f46Add z.toZod helper (#5913) by @colinhackse0e51a55docs(v4): cut the compile comments down to what they explain (#6449) by @colinhacks6574e784fix(v4): stop catch resurrecting issues an optional already resolved (#6440) by @colinhacks937b5d01perf(v4): prefix issue paths in place in the object JIT failure path (#6445) by @colinhacksb63db248fix(v4): keep a memoized node's cached issues private to the cache (#6443) by @colinhacks6ec3d043fix(resolution): keep pnpm's own warnings out of the attw snapshot (#6446) by @colinhacks830ba314fix(v4): validate the address, and return the string that was validated (#6442) by @colinhacksf101d8caPreserve callsites in parse stack traces (#5910) by @colinhacks6c77d028feat: compact simple anyOf unions to type array in toJSONSchema (#6339) by @deepshekhardas28e1ebd8fix(v4): measure string length in Unicode code points (#6441) by @colinhacks060bc9f3refactor: share default when-clauses for size/length checks (#6394) by @zirkelc2848177ddocs: point the flattened/formatted error deprecations at a symbol that exists by @colinhacks3c2dee9eAdd properties checks for instanceof schemas (#5912) by @colinhacks87ffeb0ffix(v4): an absent key on the middle rung supplies nothing (#6434) by @colinhacks7785fc82feat(v4): add z.getDiscriminatedOption (#5947) by @dokson0135c85afeat(v4): allow passing extra args to apply() (#6337) by @deepshekhardasca246d26fix(v4): drop empty alternation branch from datetime pattern (#6439) by @colinhackse073d55bdocs: z.iso.datetime() accepts a subset of ISO 8601, not all of it by @colinhacksd6ca12aefix(v4): infer recursive getter options in discriminatedUnion (#6422) by @colinhacksdc51404bAdd shorn to Zod Utilities (#6398) by @ChiChuRita580111dadocs: mark AOT compilation as canary-only by @colinhacks6b0dae79docs: note that a catch callback is not islanded by @colinhacks898c4461refactor(v4): give the runtime and compiled code one URL implementation by @colinhacks260e5d4bfix(v4): stop islanding a catch callback, which diverged silently by @colinhacks11c9268brevert(core): drop the exactOptional parse prototype from #6432 (#6438) by @colinhacksa38ab4a8fix(core): an omittable discriminator claims undefined (#6432) by @colinhacksc9ec89e0perf(core): drop the seal and the per-key WeakSet from the lazy internals (#6435) by @colinhacks3c9ca1d9feat(json-schema): emit a root $ref when the root schema has an id (#6029) by @dinwwwhfa77a4d7feat(v4): z.compile — ahead-of-time schema compilation (#6085) by @colinhacksf300476dfix(v4): let a schema's error map cover its own checks' issues (#6426) by @colinhacks9f0a3d81fix(core): restore defineLazy semantics lost in the internals move (#6429) by @colinhacks604464c3fix(locales): da/nn/no/sv called an IP address a range (#6430) by @colinhacks7378e7cdfix(locales): backfill the mac and Sizable.map gaps, and pin dictionary parity (#6427) by @colinhacksb1077f05perf(memory): install derived internals on a per-constructor prototype (#6415) by @colinhacksccc15144fix(locales): add the credit_card key to the seven locales missing it (#6424) by @colinhacks73bacbbbfix(from-json-schema): drop redundant inclusive bound for draft-04 exclusive ranges (#6022) by @francisjohnjohnston-web86b2e6dadocs: list el and hr in the supported locales (#6423) by @colinhacks45fdeda5fix(v4): refine optin into a three-rung ladder, retire the fallback payload flag (#6419) by @colinhacks5b34c0ceImprove Portuguese localization and add Brazilian Portuguese (pt-BR) (#6076) by @thristhartdc1a40a5fix(locales): improve french translation (#6120) by @tsmartin90175a043feat(locales): add Hindi and Kannada locale support (#6315) by @vedanshshetti536ee3b0Locales: added Slovak (sk) language (#6041) by @belicam07b0c3d8fix: preserve explicit superRefine issue input (#6053) by @frastefaniniba98071cfeat: add .exactPartial() to ZodObject (#6065) by @andersk234c407dfeat(lang): Added Bengali locale (#5974) by @musaddiq-rafi377cd9d7feat(locales): add turkmen (tk) locale (#6168) by @tachmyratsaparmyradov69b6bb08feat(locales): add Norwegian Nynorsk (nn) locale (#6092) by @arvindfroi33d82e6bAdd Central Kurdish (ckb) locale (#6078) by @KUMachine06666fe2fix(fr): remove hyphen in "non-optionnel" (#5999) by @spidersouris79cfedeafeat(v4): expose the owning schema on check-originated issues (#6420) by @colinhacks436b5da8docs: propose compiled constructor graph by @colinhackseb4682c9fix(json-schema): resolve tuple minItems past transform and catch in input mode (#6418) by @colinhacks4d6b5cd3fix(json-schema): route unrepresentable default values throughunrepresentableby @colinhacks2abc9e05docs: note that the JSON Schema emitter reads static optin (#6417) by @colinhacks578e1cd0feat(v4): support format: "hostname" in fromJSONSchema (#6305) by @catdalfonso942bf8cbfeat(v4): parse input containing reference cycles (#6387) by @colinhacks78b523f0fix(json-schema): keep preprocess object properties required in input mode (#6133) by @MerlijnW70973b1b44fix(v4): strip output-typed catch values from the input JSON Schema (#6409) by @colinhacks5e608851feat(v4): add z.deepPartial and runtime z.input / z.output (#5928) by @dokson4e1720c8fix(v4): align record keys and intersection strictness with TypeScript (#6412) by @colinhacks4cc4053dfix: honor loose mode for closed record key schemas (#6157) by @pullfrog[bot]69be843ffix(v4): stop the object JIT fastpass keeping a swallowed issue's value (#6407) by @colinhacksb899cd17perf(json-schema): make toJSONSchema(registry) linear in registry size (#6408) by @colinhacks6074828efix(v4): make fromJSONSchema propertyNames compose with the other object keywords (#6411) by @colinhacksd7b209f3docs: point the Web URLs callout at z.httpUrl() (#6410) by @colinhacks611bd762fix(mini): make merge() take an object schema, matching classic (#6404) by @colinhacksb53e53ccfix(v4): use exact flag in English locale too_small/too_big messages (#6177) by @pullfrog[bot]421cc9a5fix(json-schema): unescape JSON Pointer tokens when resolving $ref (#6402) by @colinhacks4c27fe87fix(v4): give z.xor() a distinct error when multiple options match (#6376) by @colinhacksa106fbe7fix(v4): make fromJSONSchema tuples open-ended by default (#6020) by @mneetikae8034ebafix(v4): make prefixItems/draft-7 items respect minItems in fromJSONSchema (#6201) by @pullfrog[bot]784e5c26fix(v4): let bundlers tree-shake locales out of the default import (#6384) by @colinhacks97edd70afix(toJSONSchema): constrain closed tuple length (#6194) by @pullfrog[bot]f150020dfix(v4): escape non-string enum values in template literal patterns (#5934) by @gwagjiugfaf33a28fix: surface @deprecated on re-exported compat aliases (#6072) by @MahinAnowar3956224adocs: state that metadata wins over generated JSON Schema keywords (#6401) by @colinhacksa1904fc2fix(v4): report date origin for numeric min/max bounds (#6129) by @MerlijnW70bd18314cfix: escape JSON Pointer reserved characters in toJSONSchema $ref (closes #6027) (#6144) by @MaksZhukov2a5164f5fix(v4): enforce RFC 1035 length limits in regexes.domain (#6035) by @emmayusufu0e5bc4b1fix(v4): respect additionalProperties:false with patternProperties in fromJSONSchema (#6199) by @pullfrog[bot]c8f06d36fix(v4): clarify infinite number errors (#5906) by @colinhacks9a7ecc35fix(json-schema): accept RFC 3339 numeric offsets in date-time format (#6298) by @agcty0a76f3d7feat(v4): add z.creditCard() string format (#5931) by @doksonbd6619c0feat(json-schema): accept a function forunrepresentable(#6380) by @colinhacks9d20fdc3fix(v4): preserve z.preprocess input narrowing (#5967) by @devareddy053063993aperf(v4): cut per-schema memory ~90% by moving methods to the prototype (#6318) by @zirkelcfd074106feat(json-schema): runoverridebefore the unrepresentable error (#6391) by @colinhacks2715c12efix(v4): preserve default English locale across tree-shaken bundles (#5959) by @colinhacks81d9fc6cdocs: add zod-form-action to ecosystem (#6314) by @Vish05d86df5e0docs: add ArkEnv to ecosystem page (#6203) by @yamcodes18b4ff99docs(ecosystem): add zodql to API Libraries (#6227) by @mattiasahlsen479d6f51shill oxlint (#6196) by @samchungy85dba7e1docs: document that any/unknown object keys are required (#6388) by @colinhacksd24fb4c3fix: consistently strip proto from parsed objects (#6386) by @colinhacks7708d447perf(v4): lazy ZodError construction (#6316) by @zirkelc8ac9ae51fix(docs-v3): serve the docsify SPA fallback on Vercel (#6378) by @colinhacks31384464fix(v4): complete reserved-key hardening (#6371) by @colinhacks600c6909docs: add Attaform to ecosystem (#6188) by @ozzyfromspace37c05fa5docs(ecosystem): rename zod-to-mongo-schema to zod-mongo-schema (#6178) by @udohjeremiahbadfdf08docs: update keyof() ZodEnum type to the v4 form (#6124) by @patrickwehbee25b68e1perf(v4): let three dead declarations tree-shake under esbuild (#6381) by @colinhacks53397351docs(ecosystem): Add zod-mongoose list item in Zod To X (#6062) by @Harm-Nullixdfa0deb1docs: add tauri-typegen to ecosystem (#6032) by @thwbh9c914ee8docs: add dynamic error message and combined refinement examples for refine() (#6002) by @IdanGonen921649defix(v4): formatError and treeifyError handle inherited-name path elements (#6367) by @deepshekhardase7029aa4fix(v4): report own proto key under .strict() (#6221) by @pullfrog[bot]9c540db8fix(v4): re-check the record key after the key schema runs (#6355) by @colinhacks8bb89ea4docs: add .nonempty() to Strings, Arrays, Sets, and Maps sections (#6056) by @pullfrog[bot]599c0e41docs(ecosystem): Add@chrock-studio/overloadand@chrock-studio/zod-utils(#6040) by @JuerGenie27a9036adocs(ecosystem):eslint-plugin-zodiseslint-zodnow (#5975) by @marcalexieie177a0eedocs(v4): document coerce missing-key breaking change (#5957) (#5964) by @dokson66fba964docs: show z.instanceof with built-in classes (#6059) by @itsahmedbilal2d90846afix(docs): make the prefault example runnable (#6063) by @DucMinhNeead9fcb3fix(v4): write a declared proto key as an own property (#6354) by @colinhacksc58764c5docs: fix UUID helper list in v4 introduction (#6214) by @meliharikf238fbd2fix: remove exponential backtracking from the emoji regex (#6347) by @colinhackse6c213ecfix(json-schema): keep proto keys as own properties in schema conversion (#6346) by @colinhacks573fcb75fix(errors): use own-property semantics in every error-tree walker (#6213) by @pullfrog[bot]6f5e99fdfix(docs-v3): rename README.md to home.md so Vercel serves it by @colinhacksbbc68f99docs: soften Zod 3 EOL callouts to informational tone by @colinhacks3fc9b25fdocs: reframe library-authors page Zod-4-first; note Zod 3 EOL by @colinhacksf29f2a6dfix(v4): cidrv6 JSON schema pattern matches runtime (#5945) by @doksondfd8766bfix(v4): break circular import between classic schemas and iso (#5275) (#5926) by @doksonfbe8ad1bfix(v4): allow dynamic.catch()underunrepresentable: "any"(#5273) (#5925) by @dokson