Seven x2y tools remain free. Code Leak Detector is $29 as a one-time purchase.

View products

Professional SDK for API Monitoring & Code Refactoring

x2y SDK

v1.0.4MIT

A comprehensive solution for modern software development, combining powerful API monitoring capabilities with intelligent code refactoring. Designed for developers who want to improve their API integration practices and code quality through automated analysis and suggestions.

NODE.JS 18+ES6 + COMMONJSTYPESCRIPTZERO TELEMETRY

Free & open source — MIT licence. No account, no telemetry, no cloud dependency.

x2y-sdk · live examples
module: monitorruntime: node:22telemetry: 0 B

At a glance

  • Versionv1.0.4 · stable
  • Packagex2y-dev-tools-sdk
  • RuntimeNode.js 18+ · ESM + CJS
  • Modulesmonitor · refactor · secrets · audit
  • LicenceMIT — free & open source
  • Telemetry0 bytes

Zero postinstall scripts, no native dependencies and no vendor endpoint — observable from your own process.

Overview

API intelligence and code quality in one package

The x2y SDK is a comprehensive solution for modern software development, combining powerful API monitoring capabilities with intelligent code refactoring. It is designed for developers who want to improve their API integration practices and code quality through automated analysis and suggestions.

With support for both CommonJS and ES6 modules, the x2y SDK integrates seamlessly into any JavaScript or TypeScript project, providing real-time insights into API behaviour and actionable code improvement recommendations — all processed locally, with zero telemetry.

SDK at a glance
Packagex2y-dev-tools-sdk
Versionv1.0.4
RuntimeNode.js 18+
ModulesES6 + CommonJS
TypesTypeScript definitions included
LicenceMIT
Telemetry0 bytes

Key features

Six capabilities, one import

API Traffic Monitoring

Record and analyse API calls with detailed metrics — endpoint, method, response time, status code and headers — stored entirely in memory or on your filesystem.

Predictive Issue Analysis

Anticipate API failures before they happen. The SDK analyses recorded traffic patterns to surface risk levels, rate-limit proximity and suggested fallback endpoints.

Code Refactoring Suggestions

Get intelligent, line-level suggestions to improve code quality — idiomatic patterns, performance fixes and modern async conversions — for strings or entire files.

Performance Optimization

Identify and fix performance bottlenecks like DOM queries inside loops, repeated allocations and unbatched operations. Suggestions include the corrected code, not just a warning.

Async Pattern Improvements

Modernise legacy promise chains into clean async/await syntax. The SDK detects nested .then() patterns and produces the equivalent await-based rewrite.

Rate Limit Detection

Monitor x-ratelimit-remaining and related headers across every recorded call. Predict when a limit will be reached and receive proactive warnings before requests start failing.

Installation

Three ways to get started

npm install x2y-dev-tools-sdk
npm install -g x2y-dev-tools-sdk
git clone https://github.com/x2yDevs/x2y-sdk.git
cd x2y-sdk
npm install
npm run build

Import & setup

ES6 or CommonJS — your choice

The SDK ships with both module formats and bundled TypeScript definitions. Import whichever style your project uses and initialise with a single constructor call.

JavaScript// ES6 modules import { X2YSdk } from 'x2y-dev-tools-sdk'; // CommonJS (Node.js) const { X2YSdk } = require('x2y-dev-tools-sdk'); // Initialize the SDK const sdk = new X2YSdk();

Basic usage

Record, predict and refactor in one flow

JavaScriptimport { X2YSdk } from 'x2y-dev-tools-sdk'; const sdk = new X2YSdk(); // Record API traffic sdk.recordAPITraffic({ endpoint: '/api/users', method: 'GET', timestamp: Date.now(), responseTime: 200, statusCode: 200, headers: { 'x-ratelimit-remaining': '85' } }); // Predict issues const prediction = await sdk.predictAPIIssues('/api/users'); console.log(prediction); // Refactor code const suggestions = await sdk.refactorCode(` for (let i = 0; i < arr.length; i++) { console.log(arr[i]); } `); console.log(suggestions);

API monitoring

Record traffic, predict failures, configure thresholds

01

Recording API traffic

Build a dataset by recording API traffic data for predictions. Each call captures endpoint, method, timestamp, response time, status code and headers — the raw material the prediction engine learns from.

JavaScriptsdk.recordAPITraffic({ endpoint: '/api/users', method: 'POST', timestamp: Date.now(), responseTime: 250, statusCode: 201, headers: { 'x-ratelimit-remaining': '45', 'x-ratelimit-limit': '100', 'content-type': 'application/json' } });
02

Predicting API issues

The SDK analyses recorded traffic to predict potential problems — risk level, rate-limit proximity, suggested fallback endpoints and a confidence score — before the next call is made.

JavaScriptconst prediction = await sdk.predictAPIIssues('/api/users'); console.log(prediction);
/* Output: { endpoint: '/api/users', riskLevel: 'medium', predictedFailure: false, rateLimitApproaching: true, suggestedAlternatives: ['/api/v2/users', '/api/users?cached=true'], confidence: 85 } */
03

Configuration options

Customise SDK behaviour with two configuration objects — one for API monitoring, one for refactoring. Every value has a sensible default; override only what you need.

JavaScriptconst sdk = new X2YSdk( { // API monitoring config rateLimitThreshold: 80, // Percentage before warning predictionWindow: 60000, // Time window in ms apiUrl: 'https://api.example.com' }, { // Refactoring config targetLanguage: 'typescript', rules: ['performance', 'idiom', 'async'] } );

Code refactoring

From strings to files — five ways to improve your code

01

Refactoring code strings

Analyse any code snippet and receive structured improvement suggestions — type, description, original code, suggested replacement, line number and severity.

JavaScriptconst suggestions = await sdk.refactorCode(` for (let i = 0; i < arr.length; i++) { console.log(arr[i]); } `); console.log(suggestions);
/* Output: [ { type: 'idiom', description: 'Use array methods like forEach() for better readability', originalCode: 'for (let i = 0; i < arr.length; i++) { ... }', suggestedCode: 'arr.forEach(item => console.log(item));', line: 2, severity: 'medium' } ] */
02

Refactoring entire files

Point the SDK at a JavaScript or TypeScript file on disk and receive a full list of suggestions across the entire source — ready to feed into a review workflow or CI gate.

JavaScriptconst fileSuggestions = await sdk.refactorFile('./src/example.js'); console.log(`${fileSuggestions.length} suggestions found`);
03

Performance suggestions

Identify performance issues like DOM queries inside loops. The SDK suggests hoisting the query outside the iteration and provides the rewritten code block.

JavaScriptconst performanceCode = ` for (let i = 0; i < items.length; i++) { document.getElementById('myElement').innerHTML += items[i]; } `; const suggestions = await sdk.refactorCode(performanceCode); // Will suggest caching the DOM query outside the loop
04

Idiom suggestions

Get recommendations for modern JavaScript and TypeScript idioms — replacing imperative loops with declarative array methods, eliminating var, and adopting optional chaining where appropriate.

JavaScriptconst oldCode = ` var result = []; for (var i = 0; i < items.length; i++) { if (items[i].active) { result.push(items[i].name); } } `; const suggestions = await sdk.refactorCode(oldCode); // Will suggest: items.filter(item => item.active).map(item => item.name)
05

Async pattern improvements

Modernise legacy promise chains into clean async/await syntax. The SDK detects nested .then() structures and emits the equivalent await-based control flow.

JavaScriptconst oldAsyncCode = ` fetch('/api/data') .then(response => response.json()) .then(data => console.log(data)) .catch(error => console.error(error)); `; const suggestions = await sdk.refactorCode(oldAsyncCode); // Will suggest using async/await instead of promise chains

Integration

Wrap fetch once, monitor everything

Monkey-patch window.fetch (or the Node equivalent) to automatically record every outbound request, measure its duration, and run a prediction before returning the response. High-risk endpoints surface a console warning without interrupting the call.

Auto-refactoring. Set the environment variable X2Y_AUTO_REFACTOR=true to automatically apply high-severity refactoring suggestions during a build step. Use with caution in production pipelines — review the diff first.
JavaScriptconst originalFetch = window.fetch; window.fetch = async (...args) => { const start = Date.now(); const response = await originalFetch(...args); const duration = Date.now() - start; // Record the traffic sdk.recordAPITraffic({ endpoint: args[0].toString(), method: 'GET', timestamp: Date.now(), responseTime: duration, statusCode: response.status, headers: Object.fromEntries(response.headers.entries()) }); // Predict if next calls might fail const prediction = await sdk.predictAPIIssues(args[0].toString()); if (prediction.riskLevel === 'high') { console.warn('High risk detected for:', args[0]); } return response; };

Specifications

Technical details

x2y SDK specifications
Packagex2y-dev-tools-sdk
Versionv1.0.4
RuntimeNode.js 18+
Module formatsES6 + CommonJS
TypeScriptBundled type definitions
API monitoringTraffic recording, prediction, rate-limit detection
RefactoringStrings, files, performance, idiom, async
ConfigTwo objects — API + refactoring
Auto-refactorX2Y_AUTO_REFACTOR=true
LicenceMIT
Telemetry0 bytes — verified continuously
Account requiredNone — ever
PriceFree & open source
Developerx2y Devs Tools Ltd, Nairobi, Kenya

Support

Need help?

For support and inquiries, contact the team directly. Bug reports and feature requests are welcome on GitHub — the SDK is MIT-licensed and contributions are encouraged.

Downloads

Get x2y SDK v1.0.4

Free and open source. The x2y SDK is published under the MIT licence. Install from npm, clone from GitHub, or vendor the source directly into your project. No account, no key, no telemetry.

Security model

Your code and API data never leave your process

Data policy. Telemetry: 0 bytes collected. Account required: none, ever. API traffic data: held in your process memory or written to paths you control. Source code analysed: read from paths you provide, never transmitted. Refactoring engine: runs locally, no cloud inference. Network connections: only the API calls your own application makes. Licence: MIT.

The x2y SDK is a library that runs inside your application. It does not make any network calls of its own — the only traffic it observes is the traffic your code already generates. Recorded API metrics stay in your process memory unless you explicitly persist them. Source code passed to refactorCode or refactorFile is analysed in-process and never leaves your machine. There is no analytics endpoint, no crash reporter, no licence check, no cloud inference tier. Verify with Wireshark, mitmproxy or your firewall logs — you will observe zero outbound connections attributable to the SDK itself.

Security manifest
Telemetry0 bytes collected
AccountNone required — ever
API traffic dataYour process memory or your filesystem
Source analysisIn-process, never transmitted
Refactoring engineLocal — no cloud inference
NetworkOnly your application's own calls
LicenceMIT — auditable source
VerificationAny network monitor

Architecture

A library that observes your process instead of phoning home

Nothing to call, nothing to leak

The SDK runs inside your application and makes no network requests of its own. There is no analytics host, no licence ping, no crash reporter and no cloud inference tier in the bundle — which means the only traffic it can ever observe is traffic your code already generates.

That constraint is the product. A hosted APM agent is a data-egress decision disguised as a dependency: your request bodies, headers and identifiers leave your process on a schedule set by someone else. Here, recorded metrics stay in memory or on paths you choose.

Monitoring without a collector

recordAPITraffic takes endpoint, method, timestamp, response time, status code and the headers you decide to capture. predictAPIIssues reads that local history for the shapes that precede failure: latency creeping toward a timeout, 429 responses approaching a limit, error-rate drift on a single route.

Alerting thresholds are values in your config, not rules in a vendor's UI. The output is data your own logging, dashboards or on-call tooling can consume — which is why the package has no opinion about where the numbers ultimately go.

Refactoring as an analysis pass, not a chat window

refactorCode and refactorFile return suggestions for performance, idiom and async patterns: loops that should be map or forEach, sequential await calls that could run concurrently, missing rate-limit handling, callback shapes that want promises.

It is static analysis of a syntax tree, executed in-process. Source never leaves your machine, and there is no model to send it to. Suggestions are advisory by design — you review and apply them; the SDK does not rewrite a file behind your back.

Secrets and audit, from the same engines

The secrets module exposes the local rule set that powers Code Leak Detector for scans of a working tree, and audit covers dependency integrity, licence compliance and supply-chain checks — including the question every install should ask, whether a package ships install scripts.

That is the actual reason this SDK exists: the engines behind our desktop tools are useful in CI, so they ship as plain Node.js modules with first-class TypeScript types and no runtime requirement to talk to us.

Supply chain, stated in numbers

One package. Zero postinstall scripts. No native dependencies, so no build toolchain on the target and no prebuilt binary to trust. MIT licensed, so the source you install is the source you can read, fork and audit.

Add npm audit, a lockfile and your own registry policy and the install path is as boring as a dependency should be. Boring is the goal: a monitoring library that itself needs monitoring is a bad trade.

How it works

Install, wrap, observe — no account to register

01

Install and import

npm install x2y-dev-tools-sdk. ES6 import and CommonJS require both work, and TypeScript definitions ship inside the package — no @types fetch, no separate release cadence to track.

02

Wrap the boundary

Wrap fetch or your HTTP client once. Every call that crosses that boundary becomes a record: endpoint, method, duration, status, and the headers you explicitly opted in to capture.

03

Set thresholds locally

Configure rate-limit headroom, prediction window and your API base URL in code or config. Values stay in your process; the behaviour of the module is fully determined by what you pass it.

04

Act in your own pipeline

Ask for predictions before a deploy, run refactoring suggestions in a lint step, scan for secrets before release and pipe the results into whatever reports, gates or dashboards you already run.

Technical summary
monitorTraffic records, latency and status history, alert probes
refactorAST suggestions for performance, idiom and async patterns
secretsOffline rule pack, the same engine as Code Leak Detector
auditDependency integrity, licence compliance, supply-chain checks
typesTypeScript definitions bundled in the package
runtimeNode.js 18 and above, including current LTS lines
Confirm the claim in five minutes: run your app under mitmproxy, tshark or your own egress policy and observe zero outbound connections attributable to the SDK. A library that claims silence should be able to prove it, and this one is built so you can.

Who it is for

Where a local, embeddable engine beats a hosted agent

Teams that cannot send payloads out

Health, fintech, government and defence workloads where request bodies are protected data and an agent is a policy exception you have to renew.

Performance and reliability work

Latency drift and rate-limit headroom on your own endpoints, without standing up an APM stack for one service.

CI pipelines and release gates

Secret scanning plus dependency audit as fast, deterministic steps with exit codes and JSON output.

Air-gapped and on-prem installs

Software you ship to a customer's isolated network can include analysis that never needs a vendor endpoint.

Code review automation

Refactoring suggestions in a lint step — the advice is repeatable, because it is a syntax-tree pass and not a model call.

Library authors and tooling teams

A programmatic interface to the same engines our desktop apps use, with a documented API surface at sdk.x2ydevs.xyz.

Requirements

What the package expects from your environment

x2y SDK runtime and toolchain requirements
RequirementMinimumNotes
RuntimeNode.js 18+Tested against current LTS lines; the README of the package states supported versions
Package managernpmWorks with yarn and pnpm through the same registry metadata
Install scriptsNone requiredThe package ships with zero postinstall scripts
Native dependenciesNoneNo build toolchain or prebuilt binaries on the target
Network at runtimeNoneThe modules never contact a vendor endpoint
TypeScriptOptionalType definitions are bundled in the package itself
LicenceMITUse, fork and audit freely; the licence text ships with the source
Module systemES6 or CommonJSBoth entry points are supported from the same version
Pin it like any dependency. Add the package to your lockfile, review the release diff, and treat version bumps as code review. MIT licensing means you can read the exact tag you install — and if a version matters to you, that reading takes minutes, not a support ticket.

Context

In-process SDK versus hosted APM versus hand-rolled logging

Comparison of SDK monitoring, hosted APM and DIY logging
Concernx2y SDKHosted APM agentCustom middleware logging
Where data landsYour process, your sinksVendor ingest and retention policiesYour logs, your format
SetupOne import, no accountAgent, keys, dashboards, sampling configWrite and maintain it yourself
Offline and air-gappedFully functionalUsually noFully functional
Predictive analysisLocal thresholds over recorded historyVendor models and alert rulesNone, by definition
Code-quality passRefactoring suggestions in the same packageNot in scopeSeparate linters, separate config
Cost modelMIT, freePer-host or per-seat, always scalingEngineering time
Exit pathDelete a dependencyExport, renegotiate, rebuild dashboardsNothing to leave

Questions

Evaluation notes from the people who file the issues

No. It is a library that runs inside your application and makes no network calls of its own. Recorded metrics stay in process memory unless you explicitly persist them, and there is no analytics endpoint, crash reporter or licence check compiled into the package. Verify it under a network monitor if you would rather not take the claim on faith.
None. Install it from the public npm registry, import it, and it works. There is no free tier to hit, no seat count to report and no activation request to allow through your firewall.
Node.js 18 and above. The package targets the LTS support matrix rather than pinning a single minor version, so an upgrade of your runtime does not require an upgrade of your analysis tooling.
Both. ES6 import and CommonJS require are supported from the same version, with the module and configuration examples on this page showing both styles. TypeScript definitions ship in the package, so there is no separate @types dependency to track.
Yes — that is the intended use. secrets and audit scan paths you provide and emit structured results; nothing is uploaded. Deterministic local analysis is precisely why these modules exist as a library rather than as a hosted scan.
The monitoring path records values into in-memory structures; it performs no network I/O of its own and no cloud lookups. Cost is dominated by how much you choose to capture — record a status code and a duration rather than whole bodies and you will struggle to measure the difference.
No. Suggestions are returned for you to review and apply, whether interactively or in a lint step. Automatic rewriting of source you did not approve would be a very different tool.
It overlaps deliberately. The SDK bundles our own offline rule set — the same engine as Code Leak Detector — plus monitoring and refactoring in one dependency, with a single programmatic API and no separate binary to install on CI images. If you already run and love a dedicated tool, keep it; this is the version that fits inside a Node process.
Open an issue on the GitHub repository or email support@x2ydevs.xyz; security disclosures go to security@x2ydevs.xyz and are triaged first. The full API reference lives at sdk.x2ydevs.xyz.

Documentation

References, source and the release record

Read the specification section before you wire it up. Technical details on this page lists the module surface, runtime and licensing in one table, and Integration patterns shows the fetch-wrapper approach that keeps instrumentation to a single boundary.

Ready to build

Install x2y SDK — monitor APIs and refactor code in one import

Free, MIT-licensed, zero telemetry. One npm install gives you predictive API monitoring and intelligent code refactoring — running entirely inside your own process.

Summary
Versionv1.0.4
RuntimeNode.js 18+
LicenceMIT — free & open source
Telemetry0 bytes