API Traffic Monitoring
Record and analyse API calls with detailed metrics — endpoint, method, response time, status code and headers — stored entirely in memory or on your filesystem.
Seven x2y tools remain free. Code Leak Detector is $29 as a one-time purchase.
View productsProfessional SDK for API Monitoring & Code Refactoring
A comprehensive solution for modern software development, combining powerful API monitoring capabilities with intelligent code refactoring. Designed for developers who want to improve their API integration practices and code quality through automated analysis and suggestions.
Free & open source — MIT licence. No account, no telemetry, no cloud dependency.
At a glance
Zero postinstall scripts, no native dependencies and no vendor endpoint — observable from your own process.
Overview
The x2y SDK is a comprehensive solution for modern software development, combining powerful API monitoring capabilities with intelligent code refactoring. It is designed for developers who want to improve their API integration practices and code quality through automated analysis and suggestions.
With support for both CommonJS and ES6 modules, the x2y SDK integrates seamlessly into any JavaScript or TypeScript project, providing real-time insights into API behaviour and actionable code improvement recommendations — all processed locally, with zero telemetry.
| Package | x2y-dev-tools-sdk |
|---|---|
| Version | v1.0.4 |
| Runtime | Node.js 18+ |
| Modules | ES6 + CommonJS |
| Types | TypeScript definitions included |
| Licence | MIT |
| Telemetry | 0 bytes |
Key features
Record and analyse API calls with detailed metrics — endpoint, method, response time, status code and headers — stored entirely in memory or on your filesystem.
Anticipate API failures before they happen. The SDK analyses recorded traffic patterns to surface risk levels, rate-limit proximity and suggested fallback endpoints.
Get intelligent, line-level suggestions to improve code quality — idiomatic patterns, performance fixes and modern async conversions — for strings or entire files.
Identify and fix performance bottlenecks like DOM queries inside loops, repeated allocations and unbatched operations. Suggestions include the corrected code, not just a warning.
Modernise legacy promise chains into clean async/await syntax. The SDK detects nested .then() patterns and produces the equivalent await-based rewrite.
Monitor x-ratelimit-remaining and related headers across every recorded call. Predict when a limit will be reached and receive proactive warnings before requests start failing.
Installation
npm install x2y-dev-tools-sdknpm install -g x2y-dev-tools-sdkgit clone https://github.com/x2yDevs/x2y-sdk.git cd x2y-sdk npm install npm run build
Import & setup
The SDK ships with both module formats and bundled TypeScript definitions. Import whichever style your project uses and initialise with a single constructor call.
Basic usage
API monitoring
Build a dataset by recording API traffic data for predictions. Each call captures endpoint, method, timestamp, response time, status code and headers — the raw material the prediction engine learns from.
The SDK analyses recorded traffic to predict potential problems — risk level, rate-limit proximity, suggested fallback endpoints and a confidence score — before the next call is made.
Customise SDK behaviour with two configuration objects — one for API monitoring, one for refactoring. Every value has a sensible default; override only what you need.
Code refactoring
Analyse any code snippet and receive structured improvement suggestions — type, description, original code, suggested replacement, line number and severity.
Point the SDK at a JavaScript or TypeScript file on disk and receive a full list of suggestions across the entire source — ready to feed into a review workflow or CI gate.
Identify performance issues like DOM queries inside loops. The SDK suggests hoisting the query outside the iteration and provides the rewritten code block.
Get recommendations for modern JavaScript and TypeScript idioms — replacing imperative loops with declarative array methods, eliminating var, and adopting optional chaining where appropriate.
Modernise legacy promise chains into clean async/await syntax. The SDK detects nested .then() structures and emits the equivalent await-based control flow.
Integration
Monkey-patch window.fetch (or the Node equivalent) to automatically record every outbound request, measure its duration, and run a prediction before returning the response. High-risk endpoints surface a console warning without interrupting the call.
X2Y_AUTO_REFACTOR=true to automatically apply high-severity refactoring suggestions during a build step. Use with caution in production pipelines — review the diff first.Specifications
| Package | x2y-dev-tools-sdk |
|---|---|
| Version | v1.0.4 |
| Runtime | Node.js 18+ |
| Module formats | ES6 + CommonJS |
| TypeScript | Bundled type definitions |
| API monitoring | Traffic recording, prediction, rate-limit detection |
| Refactoring | Strings, files, performance, idiom, async |
| Config | Two objects — API + refactoring |
| Auto-refactor | X2Y_AUTO_REFACTOR=true |
| Licence | MIT |
| Telemetry | 0 bytes — verified continuously |
| Account required | None — ever |
| Price | Free & open source |
| Developer | x2y Devs Tools Ltd, Nairobi, Kenya |
Support
For support and inquiries, contact the team directly. Bug reports and feature requests are welcome on GitHub — the SDK is MIT-licensed and contributions are encouraged.
Downloads
Security model
The x2y SDK is a library that runs inside your application. It does not make any network calls of its own — the only traffic it observes is the traffic your code already generates. Recorded API metrics stay in your process memory unless you explicitly persist them. Source code passed to refactorCode or refactorFile is analysed in-process and never leaves your machine. There is no analytics endpoint, no crash reporter, no licence check, no cloud inference tier. Verify with Wireshark, mitmproxy or your firewall logs — you will observe zero outbound connections attributable to the SDK itself.
| Telemetry | 0 bytes collected |
|---|---|
| Account | None required — ever |
| API traffic data | Your process memory or your filesystem |
| Source analysis | In-process, never transmitted |
| Refactoring engine | Local — no cloud inference |
| Network | Only your application's own calls |
| Licence | MIT — auditable source |
| Verification | Any network monitor |
Architecture
The SDK runs inside your application and makes no network requests of its own. There is no analytics host, no licence ping, no crash reporter and no cloud inference tier in the bundle — which means the only traffic it can ever observe is traffic your code already generates.
That constraint is the product. A hosted APM agent is a data-egress decision disguised as a dependency: your request bodies, headers and identifiers leave your process on a schedule set by someone else. Here, recorded metrics stay in memory or on paths you choose.
recordAPITraffic takes endpoint, method, timestamp, response time, status code and the headers you decide to capture. predictAPIIssues reads that local history for the shapes that precede failure: latency creeping toward a timeout, 429 responses approaching a limit, error-rate drift on a single route.
Alerting thresholds are values in your config, not rules in a vendor's UI. The output is data your own logging, dashboards or on-call tooling can consume — which is why the package has no opinion about where the numbers ultimately go.
refactorCode and refactorFile return suggestions for performance, idiom and async patterns: loops that should be map or forEach, sequential await calls that could run concurrently, missing rate-limit handling, callback shapes that want promises.
It is static analysis of a syntax tree, executed in-process. Source never leaves your machine, and there is no model to send it to. Suggestions are advisory by design — you review and apply them; the SDK does not rewrite a file behind your back.
The secrets module exposes the local rule set that powers Code Leak Detector for scans of a working tree, and audit covers dependency integrity, licence compliance and supply-chain checks — including the question every install should ask, whether a package ships install scripts.
That is the actual reason this SDK exists: the engines behind our desktop tools are useful in CI, so they ship as plain Node.js modules with first-class TypeScript types and no runtime requirement to talk to us.
One package. Zero postinstall scripts. No native dependencies, so no build toolchain on the target and no prebuilt binary to trust. MIT licensed, so the source you install is the source you can read, fork and audit.
Add npm audit, a lockfile and your own registry policy and the install path is as boring as a dependency should be. Boring is the goal: a monitoring library that itself needs monitoring is a bad trade.
How it works
npm install x2y-dev-tools-sdk. ES6 import and CommonJS require both work, and TypeScript definitions ship inside the package — no @types fetch, no separate release cadence to track.
Wrap fetch or your HTTP client once. Every call that crosses that boundary becomes a record: endpoint, method, duration, status, and the headers you explicitly opted in to capture.
Configure rate-limit headroom, prediction window and your API base URL in code or config. Values stay in your process; the behaviour of the module is fully determined by what you pass it.
Ask for predictions before a deploy, run refactoring suggestions in a lint step, scan for secrets before release and pipe the results into whatever reports, gates or dashboards you already run.
| monitor | Traffic records, latency and status history, alert probes |
|---|---|
| refactor | AST suggestions for performance, idiom and async patterns |
| secrets | Offline rule pack, the same engine as Code Leak Detector |
| audit | Dependency integrity, licence compliance, supply-chain checks |
| types | TypeScript definitions bundled in the package |
| runtime | Node.js 18 and above, including current LTS lines |
mitmproxy, tshark or your own egress policy and observe zero outbound connections attributable to the SDK. A library that claims silence should be able to prove it, and this one is built so you can.Who it is for
Health, fintech, government and defence workloads where request bodies are protected data and an agent is a policy exception you have to renew.
Latency drift and rate-limit headroom on your own endpoints, without standing up an APM stack for one service.
Secret scanning plus dependency audit as fast, deterministic steps with exit codes and JSON output.
Software you ship to a customer's isolated network can include analysis that never needs a vendor endpoint.
Refactoring suggestions in a lint step — the advice is repeatable, because it is a syntax-tree pass and not a model call.
A programmatic interface to the same engines our desktop apps use, with a documented API surface at sdk.x2ydevs.xyz.
Requirements
| Requirement | Minimum | Notes |
|---|---|---|
| Runtime | Node.js 18+ | Tested against current LTS lines; the README of the package states supported versions |
| Package manager | npm | Works with yarn and pnpm through the same registry metadata |
| Install scripts | None required | The package ships with zero postinstall scripts |
| Native dependencies | None | No build toolchain or prebuilt binaries on the target |
| Network at runtime | None | The modules never contact a vendor endpoint |
| TypeScript | Optional | Type definitions are bundled in the package itself |
| Licence | MIT | Use, fork and audit freely; the licence text ships with the source |
| Module system | ES6 or CommonJS | Both entry points are supported from the same version |
Context
| Concern | x2y SDK | Hosted APM agent | Custom middleware logging |
|---|---|---|---|
| Where data lands | Your process, your sinks | Vendor ingest and retention policies | Your logs, your format |
| Setup | One import, no account | Agent, keys, dashboards, sampling config | Write and maintain it yourself |
| Offline and air-gapped | Fully functional | Usually no | Fully functional |
| Predictive analysis | Local thresholds over recorded history | Vendor models and alert rules | None, by definition |
| Code-quality pass | Refactoring suggestions in the same package | Not in scope | Separate linters, separate config |
| Cost model | MIT, free | Per-host or per-seat, always scaling | Engineering time |
| Exit path | Delete a dependency | Export, renegotiate, rebuild dashboards | Nothing to leave |
Questions
import and CommonJS require are supported from the same version, with the module and configuration examples on this page showing both styles. TypeScript definitions ship in the package, so there is no separate @types dependency to track.secrets and audit scan paths you provide and emit structured results; nothing is uploaded. Deterministic local analysis is precisely why these modules exist as a library rather than as a hosted scan.sdk.x2ydevs.xyz.Documentation
Ready to build
Free, MIT-licensed, zero telemetry. One npm install gives you predictive API monitoring and intelligent code refactoring — running entirely inside your own process.
| Version | v1.0.4 |
|---|---|
| Runtime | Node.js 18+ |
| Licence | MIT — free & open source |
| Telemetry | 0 bytes |