# Kaneo API Technology Stack: Core Backend Technologies Explained

> Explore the Kaneo API technology stack, featuring Hono, PostgreSQL with Drizzle ORM, Better-Auth, and Valibot for efficient and type-safe backend development. Learn about our core technologies.

- Repository: [kaneo.app/kaneo](https://github.com/usekaneo/kaneo)
- Tags: internals
- Published: 2026-08-09

---

**The Kaneo API is built on a modern TypeScript stack centered around Hono for routing, PostgreSQL with Drizzle ORM for data persistence, Better-Auth for authentication, and Valibot for type-safe validation.**

The Kaneo project management platform relies on a fast, lightweight backend architecture designed for real-time collaboration and extensibility. Located in the `usekaneo/kaneo` repository, the API layer demonstrates how contemporary Node.js frameworks prioritize type safety, developer experience, and performance. This analysis examines the specific technologies powering the Kaneo API based on the actual source code implementation.

## Core Web Framework and Runtime

The foundation of the Kaneo API rests on **Hono**, a lightweight, edge-ready web framework for TypeScript. In [`apps/api/src/index.ts`](https://github.com/usekaneo/kaneo/blob/main/apps/api/src/index.ts), the application initializes a new Hono instance that handles the complete request-response lifecycle, including routing and middleware composition.

The server runtime combines `@hono/node-server` for HTTP request handling with `@hono/node-ws` to enable WebSocket connections for real-time features. This dual-capability approach allows the API to serve standard REST endpoints while simultaneously supporting persistent socket connections for live updates.

```typescript
// apps/api/src/index.ts
import { Hono } from "hono";
import { serve } from "@hono/node-server";
import { createNodeWebSocket } from "@hono/node-ws";

const app = new Hono<AppVariables>();

```

## Database Layer: PostgreSQL and Drizzle ORM

Data persistence relies on **PostgreSQL** accessed through the native `pg` driver and abstracted via **Drizzle ORM**. The database configuration in [`apps/api/src/database/index.ts`](https://github.com/usekaneo/kaneo/blob/main/apps/api/src/database/index.ts) establishes a connection pool and exports a type-safe Drizzle client configured with the project's schema definitions.

Drizzle provides compile-time type checking for SQL queries, ensuring that database operations align with the TypeScript interfaces defined in the schema. This approach eliminates runtime errors from malformed queries while maintaining the performance characteristics of raw SQL.

```typescript
// apps/api/src/database/index.ts
import { drizzle } from "drizzle-orm/node-postgres";
import { Pool } from "pg";

const pool = new Pool({ connectionString: process.env.DATABASE_URL });
export const db = drizzle(pool, { schema });

```

## Authentication and Authorization

User identity management leverages **Better-Auth**, a flexible authentication library that supports sessions, API keys, and OAuth flows. The authentication middleware mounts at the application level in [`apps/api/src/index.ts`](https://github.com/usekaneo/kaneo/blob/main/apps/api/src/index.ts), validating credentials before requests reach business logic handlers.

Workspace-level authorization implements additional access control through utilities like `validateWorkspaceAccess`, ensuring users can only interact with resources belonging to their assigned workspaces.

## Validation and API Documentation

The Kaneo API enforces strict input validation using **Valibot**, a schema declaration library with a small bundle size and strong TypeScript integration. Combined with **hono-openapi**, the system automatically generates OpenAPI specifications from route decorators and validation schemas.

This integration appears in controller files where routes define their expected request shapes using Valibot objects, which hono-openapi converts into interactive documentation.

```typescript
// Example route definition with validation
import { validator, describeRoute } from "hono-openapi";
import * as v from "valibot";

api.post(
  "/task",
  describeRoute({ operationId: "createTask", tags: ["Task"] }),
  validator("json", v.object({ 
    title: v.string(), 
    description: v.optional(v.string()) 
  })),
  async (c) => {
    const { title, description } = c.req.valid("json");
    return c.json({ success: true });
  }
);

```

## Background Processing and External Integrations

Beyond the core request handling, the Kaneo API integrates several specialized services:

- **Croner** ([`apps/api/package.json`](https://github.com/usekaneo/kaneo/blob/main/apps/api/package.json)) handles scheduled background jobs such as email reminders and data cleanup tasks
- **ioredis** provides Redis connectivity for Pub/Sub messaging, enabling WebSocket message broadcasting across multiple server instances
- **AWS SDK** (`@aws-sdk/client-s3` and `@aws-sdk/s3-request-presigner`) manages asset storage and presigned URL generation for file uploads
- **Octokit** (`@octokit/webhooks` and `octokit`) processes GitHub webhook events and facilitates API interactions for repository-linked projects
- **Sentry** captures and reports unexpected exceptions in production environments
- **@paralleldrive/cuid2** generates collision-resistant unique identifiers for database records

Error handling standardizes on `hono/http-exception` to ensure consistent HTTP status codes and error responses throughout the application.

## Summary

The Kaneo API architecture demonstrates a modern, type-safe approach to Node.js backend development:

- **Hono** provides the web framework foundation with native WebSocket support via `@hono/node-ws`
- **PostgreSQL** serves as the primary database, accessed through **Drizzle ORM** for type-safe query generation
- **Better-Auth** manages authentication flows including sessions and API keys
- **Valibot** and **hono-openapi** combine to deliver runtime validation and automatic API documentation
- **Redis**, **AWS S3**, **GitHub APIs**, and **Croner** extend core functionality for caching, file storage, integrations, and background processing

## Frequently Asked Questions

### What database does the Kaneo API use?

The Kaneo API uses **PostgreSQL** as its primary relational database, accessed through the native `pg` driver and abstracted via **Drizzle ORM** for type-safe query building. The database connection configuration resides in [`apps/api/src/database/index.ts`](https://github.com/usekaneo/kaneo/blob/main/apps/api/src/database/index.ts).

### How does the Kaneo API handle real-time communication?

The API implements WebSocket support through `@hono/node-ws`, which integrates with the Hono framework to enable persistent connections. For multi-instance deployments, **ioredis** provides Redis Pub/Sub capabilities to broadcast messages across all connected servers.

### What authentication methods does the Kaneo API support?

According to the source code in [`apps/api/src/index.ts`](https://github.com/usekaneo/kaneo/blob/main/apps/api/src/index.ts), the API uses **Better-Auth** to manage multiple authentication strategies including session-based login, API key authentication, and OAuth integrations. The system also implements workspace-level access control through custom middleware.

### How is API documentation generated in the Kaneo project?

The Kaneo API automatically generates OpenAPI documentation using **hono-openapi**, which introspects route definitions and **Valibot** validation schemas to produce interactive documentation. This eliminates the need for manual OpenAPI specification maintenance while ensuring the docs always match the actual implementation.