Mastra

Mastra

Open-source TypeScript AI framework for developers

Overview

Mastra provides an open-source TypeScript framework for building, deploying, and managing AI-powered applications and agents. It uses durable, graph-based workflows for orchestrating operations, retrieval-augmented generation (RAG) to pull in external knowledge, and strong observability for debugging. It is modular and TypeScript-native, supporting over 40 LLM providers, with a cloud product for deployment and scaling under an Apache 2.0 license. Its goal is to help JavaScript and TypeScript developers build production-ready AI apps without learning a new ecosystem, with customers like Plaid, Replit, and Adobe.

YC Company
Significant Headcount Growth

About Mastra

Simplify's Rating
Why Mastra is rated
C+
Rated B on Competitive Edge
Rated B on Growth Potential
Rated D+ on Differentiation

Industries

Data & Analytics

Enterprise Software

AI & Machine Learning

Company Size

51-200

Company Stage

Series A

Total Funding

$22.1M

Headquarters

San Francisco, California

Founded

2024

Get referred to Mastra

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Mastra's April 9, 2026 Series A raised $22 million, totaling $35 million.
  • Trace Intelligence beta, July 27, 2026, deepens observability with clustering.
  • September 2, 2026 sandbox computer tools expand agent capabilities beyond browsers.

What critics are saying

  • June 17, 2026 npm attackers republished 141 @mastra packages, exposing install-time backdoors.
  • The attack targeted LLM keys, CI secrets, and developer laptops, forcing rotations immediately.
  • A repeat supply-chain breach would freeze enterprise adoption and crush Mastra's platform revenue.

What makes Mastra unique

  • Mastra's TypeScript-native framework keeps JavaScript teams inside one ecosystem, not Python.
  • Agent Builder, launched May 28, 2026, lets non-developers publish governed agents.
  • Harness, launched Jun 18, 2026, persists threads, approvals, and modes across sessions.

Help us improve and share your feedback! Did you find this helpful?

Funding

Total Funding

$22.1M

Above

Industry Average

Funded Over

2 Rounds

Notable Investors:
Series A funding typically happens when a startup has a product and some customers, and now needs funding to scale. This money is usually used to grow the team, expand marketing, and improve the product. Venture capital firms are frequently the main investors here.
Series A Funding Comparison
Above Average

Industry standards

$15M
$8.2M
Discord
$15M
Canva
$22M
Mastra
$30M
Kalshi

Benefits

Remote Work Options

Growth & Insights and Company News

Headcount

6 month growth

↑ 14%

1 year growth

↑ 14%

2 year growth

↑ 30%
BambuUP
Sep 17th, 2026
Arcjet launches agent runtime security for production AI agents.

Arcjet launches agent runtime security for production AI agents. New product helps teams discover agent activity, apply controls before and after consequential actions, and preserve evidence for security reviews and compliance SAN FRANCISCO, Sept. 17, 2026 /PRNewswire/ - Arcjet, the security platform that ships in your AI code, today launched agent runtime security, a new product that helps engineering teams secure the AI agents they are building while giving security teams the governance and compliance evidence they need. Arcjet brings observability, enforcement, and audit capabilities across agent workflows so teams can discover which agents are running, control what they can do, and understand what happened and why. AI agents are moving beyond chat interfaces and into production workflows, where they can read and write to databases, respond to support tickets, refund payments, call tools and APIs, and take other actions on behalf of users. Those workflows can start from a chat interface, an email, a text message, a code commit, or another event, and can continue autonomously across multiple systems. As agents take on longer-running workflows, security teams need to answer three questions across the full sequence of activity, which agents are running, whether a particular action should be allowed, and what happened and why. Arcjet's agent runtime security addresses those questions through observe, enforce, and audit capabilities. Teams can discover agent activity and connect actions across sessions, apply deterministic security policies before and after calls to LLMs, tools, databases, and APIs, and preserve the execution context needed for security reviews and compliance. "Agents are now taking real actions inside production systems, which means security teams need to know which agents are operating and what they have done, and apply controls at machine speed," said David Mytton, CEO at Arcjet. "A risky outcome can develop across a series of steps that look perfectly reasonable on their own. Arcjet connects those steps and gives teams policy controls to detect them." Arcjet's agent runtime security centers on three parts of securing agents in production, observe, enforce, and audit. Observe: Discover all your agents Arcjet supports ingesting agent activity without application code changes or deploying another agent. Platform and security teams can use existing OpenTelemetry observability tooling to send activity directly to Arcjet for real-time visualization and analysis. For teams using Claude, Arcjet can also pull activity from the Claude Compliance API. Arcjet connects activity across sessions so teams can see an agent's sequence of actions as one workflow rather than a collection of unrelated events. Activity can include prompts, tool call parameters, session metadata, identity, security decisions, and other application context, giving teams a view of what each agent is doing across a run. Agent identity and inventory are part of that visibility. Arcjet gives teams an inventory of the agents and applications operating inside their environment, with activity and individual runs associated with each agent so teams can inspect actions and security decisions step by step. Enforce: Apply controls before and after every action Once teams can see their agents and activity across sessions, Arcjet lets security teams define controls for prompt injection detection, PII and sensitive information leak prevention and redaction, automation and bot detection, rate limits, and quota controls. Arcjet guards apply deterministic policies to tools, APIs, database calls, and other inputs and outputs. Powered by Rego and Open Policy Agent, teams can create versioned, immutable policies through Arcjet's web UI, API, CLI, or MCP without redeploying application code. Policies can define the actions an agent is allowed to take, such as restricting recipients or attachments in an email tool, setting acceptable bounds for refund values, or limiting web fetch tools to trusted API URLs. Arcjet returns a decision to the application before the action executes, allowing the application to stop the operation, request human approval, or return an explanation to the agent. Applied before and after calls to LLMs, tools, databases, and APIs, these controls can mitigate risk before consequential actions and verify results before the workflow continues. For enforcement, Arcjet has native integrations with major agent frameworks, including Claude Agents SDK, Claude Managed Agents, OpenAI Agents SDK, LangChain, LangFuse, Strands, Mastra, and Microsoft's Agent Framework. This in-code context allows Arcjet to track recorded actions, their inputs, and policy decisions across the workflow. Audit: Evidence and proof of compliance Arcjet collects the context of each execution so teams can reconstruct what happened, understand why a policy decision was made, and provide evidence for security reviews and compliance audits. Correlated traces preserve actions, inputs, security decisions, and policy evaluations across the work SOURCE Arcjet

Mastra
Sep 2nd, 2026
Introducing sandbox computer use for Mastra agents.

Introducing sandbox computer use for Mastra agents. Give your agents a computer to use, just like you do. Sep 2, 2026 Your Mastra agents can now control a real Linux desktop with computer tools. Browse the web, fill in forms, download files, take screenshots, and run programs from a terminal - all from the safety of a sandbox. Mastra is launching today with two providers: E2B Desktop and Daytona. Both expose 11 computer_* tools your agents can use: * Screenshot: computer_screenshot * Mouse: computer_click, computer_double_click, computer_right_click, computer_move_mouse, computer_drag, computer_scroll * Keyboard: computer_type, computer_press_key * Environment: computer_get_screen_info, computer_wait An alternative is to use Mastra's browser capabilities so your agents navigate the web, extract data, and pass it back for processing. But with computer tools, you can extend an agent's capabilities by giving it access to the whole sandbox operating system. Supported providers implement Mastra's SandboxComputer interface, which includes several helper methods: .getScreenSize, .getCursorPosition, and .streamUrl - to watch your agent live at work. Install the E2B Desktop provider: Requires @mastra/[email protected] or later, added in PR #21700. Attach an E2BDesktopSandbox to your agent's Workspace: Paul Scanlon Technical Product Marketing Manager Paul Scanlon sits between Developer Education and Product Marketing at Mastra. Previously, he was a Technical Product Marketing Manager at Neon and worked in Developer Relations at Gatsby, where he created educational content and developer experiences.

Mastra
Aug 10th, 2026
Introducing sensitive data redaction for Mastra observability.

Introducing sensitive data redaction for Mastra observability. Automatically redact sensitive customer information from agent traces. Aug 10, 2026 With Mastra's new SensitiveDataFilter, you can automatically redact customer information from agent observability traces, or configure rules per-environment for application-specific fields. The SensitiveDataFilter is enabled by default and ships with 15 default value fields - including password, ssn, and auth. You can customize which fields to redact with the sensitiveFields array. Field matching normalizes case and separators, for example; api-key, api_key, and ApiKey would all match. You can also configure redaction styles, change the replacement token, and set different rules per-environment. E.g. partial for development, and full for production. Before the SensitiveDataFilter, keeping secrets and PII out of your agent traces meant writing a custom span processor to sanitize tool inputs. Now the SensitiveDataFilter is enabled by default, catching and redacting sensitive field names automatically. SensitiveDataFilter is a SpanOutputProcessor that recursively walks each span's attributes, metadata, input, output, and errorInfo - including nested objects, arrays, and JSON-encoded strings. To disable the functionality, set sensitiveDataFilter: false. Install @mastra/observability: Requires @mastra/[email protected] or later, added in PR #16234. A default Observability config automatically redacts the default values and replaces sensitive data with [REDACTED]. Additional configuration may be required to ensure all customer-specific sensitive data is redacted. Example output from default config: Define your own fields using the sensitiveFields array - this overrides the defaults, set the redactionStyle to full, and add a redactionToken. Use the configSelector to configure different rules per environment: NODE_ENV=development is the default, NODE_ENV=production selects production. Example output from extended config: Paul Scanlon Technical Product Marketing Manager Paul Scanlon sits between Developer Education and Product Marketing at Mastra. Previously, he was a Technical Product Marketing Manager at Neon and worked in Developer Relations at Gatsby, where he created educational content and developer experiences.

Mastra
Jul 27th, 2026
Announcing Trace Intelligence.

Announcing Trace Intelligence. Group traces into clusters. Jul 27, 2026 The hardest part of building an agent is ensuring it's accurate enough to ship into production. Teams can spend weeks or months reviewing user traces and turning them into agent fixes. That's why Mastra is excited to announce Trace Intelligence in beta today. Trace Intelligence is grouping traces into clusters so you can identify common goals, behaviors, sentiments, and outcomes across many runs. It's built into observability on the Mastra platform. While building its own agents, Trace Intelligence has helped Mastra prioritize fixes, select traces for evals, and verify that changes improve user experience. Trace Intelligence takes completed traces, extract a compact trace representation along with metadata, generates signals per trace including goal, sentiment, behavior, and outcome, embed each signal and cluster similar signals together. Mastra use UMAP for dimensionality reduction of signal embeddings and HDBSCAN for density-based clustering in the reduced space. Then, Mastra serve time-windowed views showing theme volume, trends, cross-signal flows, history, and representative traces. Trace intelligence is its second step towards agent learning. The full agent accuracy loop is something like: * review traces * create datasets * experiment with potential fixes; * ship fixes to prod Back in March, Mastra shipped Datasets and Experiments. Now, Trace Intelligence helps with the trace review and selection. After this, Mastra'll be working on automating the experiment flow by generating proposed fixes. Soon, you'll be able to automate the entire agent learning loop within Mastra.

BreachHistory
Jun 19th, 2026
Mastra npm attack: 141 packages backdoored via easy-day-js RAT.

Mastra npm attack: 141 packages backdoored via easy-day-js RAT. Fri Jun 19 Searching for Mastra npm hack, easy-day-js malware, or @mastra supply chain attack June 2026? On June 17, 2026, attackers republished 141 packages in the npm @mastra scope overnight - without touching Mastra's GitHub source. The payload rode in on a single swapped dependency: typosquatted easy-day-js instead of legitimate dayjs. Breaking - June 17, 2026: Security vendors including Socket, StepSecurity, and OX Security disclosed a coordinated npm supply-chain attack against Mastra - an open-source AI agent framework with millions of monthly downloads. BreachHistory indexes every compromised package version at pkg-npm-mastra-easy-day-js-202606. What happened. The attacker did not modify Mastra application source in Git. Instead they: * Published typosquatted easy-day-js - mirroring dayjs metadata (author, homepage, repo URL, version numbering) to pass casual review. * Shipped a clean bait version [email protected] on June 16, then weaponized 1.11.22 with a malicious postinstall hook (node setup.cjs). * Compromised dormant former contributor account ehindero and mass-republished 141 @mastra packages between roughly 01:12-02:39 UTC on June 17, each declaring "easy-day-js": "^1.11.21" so npm resolved the caret range to the malicious dropper. Account sergey2016 uploaded the malicious npm package; reporting ties both accounts to tutamail.com email substitution consistent with takeover. Legitimate prior @mastra releases carried GitHub OIDC provenance; compromised versions published from ehindero lacked SLSA attestations - a red flag teams can enforce in policy. Payload: two-stage RAT, not a simple stealer. Stage 1 is setup.cjs - roughly 4.5 KB of heavily obfuscated JavaScript run at install time. It disables TLS verification, beacons install paths, fetches stage 2 from 23.254.164.92:8000, spawns a detached background process pointed at C2 23.254.164.123:443, then deletes itself from disk. Stage 2 is a cross-platform Node.js remote access trojan (~41 KB) that: * Installs OS-level persistence (Windows Run key, macOS LaunchAgent, Linux systemd user unit) - surviving npm uninstall * Inventories 166 cryptocurrency wallet browser extensions and harvests browser history from Chrome, Brave, and Edge * Exfiltrates host, process, and environment reconnaissance - including high-value LLM API keys and cloud/CI credentials common in AI dev stacks * Polls for operator commands to download and execute arbitrary follow-on modules Socket flagged easy-day-js within six minutes of publication; StepSecurity demonstrated blocking the outbound C2 prevented stage-2 download entirely. There is no CVE - CVE scanners had no detection surface during active exploitation. Scale and who is at risk. OX Security cited ~8 million combined weekly downloads and ~29 million monthly across affected packages; @mastra/core alone exceeds 900,000 weekly installs. Anyone who ran npm install on a @mastra package during the June 17 exposure window - developer laptops, CI runners, cloud build agents - is in scope. Mastra targets AI agent workflows, so compromised hosts often hold OpenAI, Anthropic, and Google API keys alongside npm and GitHub tokens. Representative compromised versions. * @mastra/[email protected] (prior clean: 1.42.0) * @mastra/[email protected], @mastra/[email protected], @mastra/[email protected] * [email protected], [email protected] * Malicious dependency: [email protected] Immediate action checklist. * Audit dependency trees: npm ls easy-day-js across repos and CI images. * Pin or downgrade every @mastra package to the last provenance-verified release before June 17, 2026. * Treat affected hosts as compromised - do not assume uninstalling node_modules is sufficient. * Rotate secrets: LLM API keys, cloud credentials, npm tokens, GitHub PATs, SSH keys, and database URLs present on infected machines. * Hunt persistence: Windows HKCU\Run (NvmProtocal), macOS ~/Library/NodePackages/protocal.cjs, Linux ~/.config/systemd/nvmconf/. * Block egress to 23.254.164.92 and 23.254.164.123 at firewall/proxy. * Review CI logs for npm install steps between 01:00-03:00 UTC June 17, 2026. Why dependency-only attacks are hard to spot. This campaign highlights a structural gap: package tarballs looked like normal semver bumps from a known maintainer handle, and only one dependency field changed. Typosquats copied dayjs metadata so npm audit and visual lockfile review often showed nothing alarming. Install-time scripts execute before your application imports any @mastra code - so runtime SAST never runs. Teams should enforce provenance attestation requirements, block postinstall scripts in CI where feasible, and monitor registry publishes on scoped packages they depend on. Faq. Did Mastra confirm the incident? Third-party researchers and npm security vendors published detailed analyses June 17; check Mastra's official channels for vendor statements as they emerge. Is this related to Shai-Hulud or node-ipc? No - distinct campaign, distinct payload (easy-day-js typosquat), and distinct access vector (dormant @mastra maintainer token rather than atool or node-ipc maintainer abuse). Can I just delete easy-day-js from node_modules? Not safely. The RAT installs OS persistence outside node_modules; assume full host compromise until forensics clears the machine. Updated 2026-06-19.

Recently Posted Jobs

Sign up to get curated job recommendations

Mastra is Hiring for 1 Jobs on Simplify!

Find jobs on Simplify and start your career today

Don't see your dream role? Check out thousands of other roles on Simplify. Browse all jobs →