express vs hapi vs elysia vs koa
Backend Frameworks for Frontend Developers
expresshapielysiakoaSimilar Packages:

Backend Frameworks for Frontend Developers

express, koa, hapi, and elysia are all server-side frameworks for building APIs and web services in JavaScript and TypeScript. express is the industry standard with a massive ecosystem, using a request-response middleware model. koa is created by the same team but focuses on async/await and a cleaner context object. hapi emphasizes configuration over code with strong validation built-in. elysia is a modern, TypeScript-first framework optimized for the Bun runtime but compatible with Node, focusing on speed and type safety.

Npm Package Weekly Downloads Trend

3 Years

Github Stars Ranking

Stat Detail

Package
Downloads
Stars
Size
Issues
Publish
License
express109,881,74169,38075.4 kB2309 months agoMIT
hapi61,44714,792-568 years agoBSD-3-Clause
elysia018,9141.11 MB3682 months agoMIT
koa035,68865 kB433 months agoMIT

Express vs Koa vs Hapi vs Elysia: Architecture and DX Compared

Both express and koa are established Node.js frameworks, while hapi offers a configuration-heavy alternative, and elysia brings modern TypeScript features to the table. All four help you build servers, but they handle requests, errors, and types in very different ways. Let's compare how they tackle common engineering problems.

๐Ÿ› ๏ธ Request Handling Model

express uses the classic req and res objects passed through middleware.

  • You modify req to add data and res to send responses.
  • Middleware chains using next() to pass control.
// express: Classic req/res
app.use((req, res, next) => {
  req.user = { id: 1 };
  next();
});

app.get('/', (req, res) => {
  res.send(`Hello ${req.user.id}`);
});

koa uses a single ctx (context) object instead of separate req/res.

  • Properties like ctx.request and ctx.body live on one object.
  • Async/await is built-in, so no next() callback needed.
// koa: Context object
app.use(async (ctx, next) => {
  ctx.state.user = { id: 1 };
  await next();
});

app.use(async (ctx) => {
  ctx.body = `Hello ${ctx.state.user.id}`;
});

hapi separates the request object and the h response toolkit.

  • Handlers receive both as arguments.
  • You return values instead of calling send methods.
// hapi: Request and toolkit
server.route({
  method: 'GET',
  path: '/',
  handler: (request, h) => {
    return `Hello ${request.auth.credentials.id}`;
  }
});

elysia uses a single context object similar to Koa but with types.

  • You destructure what you need directly in the handler.
  • Returns data directly; the framework handles the response.
// elysia: Typed context
app.get('/', ({ user }) => {
  return `Hello ${user.id}`;
});

๐Ÿ—บ๏ธ Routing and Validation

express requires external packages for validation (like joi or zod).

  • Routes are defined directly on the app instance.
  • Validation logic is manual middleware.
// express: Manual validation
app.post('/user', (req, res, next) => {
  if (!req.body.name) return res.status(400).send('Missing name');
  res.send('OK');
});

koa also needs external routers and validation libraries.

  • Typically uses @koa/router for path handling.
  • Validation is added as middleware layers.
// koa: External router
router.post('/user', async (ctx) => {
  if (!ctx.request.body.name) {
    ctx.status = 400;
    return;
  }
  ctx.body = 'OK';
});

hapi has validation built into the route configuration.

  • You define schemas for params, query, and payload.
  • Requests are rejected automatically if validation fails.
// hapi: Built-in validation
server.route({
  method: 'POST',
  path: '/user',
  options: {
    validate: {
      payload: Joi.object({ name: Joi.string().required() })
    }
  },
  handler: (request) => 'OK'
});

elysia uses TypeScript types and plugins for validation.

  • Schemas are defined inline with the route.
  • Types are inferred automatically for end-to-end safety.
// elysia: Type-safe validation
app.post('/user', ({ body }) => 'OK', {
  body: t.Object({
    name: t.String()
  })
});

๐Ÿšจ Error Handling

express uses a special middleware function with four arguments.

  • You pass errors to next(err) to trigger it.
  • Easy to forget, leading to unhandled promises.
// express: Error middleware
app.use((err, req, res, next) => {
  res.status(500).send(err.message);
});

koa relies on standard try/catch blocks in async functions.

  • Errors bubble up automatically through the middleware chain.
  • More natural for modern JavaScript developers.
// koa: Try/catch
app.use(async (ctx, next) => {
  try {
    await next();
  } catch (err) {
    ctx.status = 500;
    ctx.body = err.message;
  }
});

hapi uses the boom library for HTTP errors.

  • You throw errors, and the framework maps them to status codes.
  • Consistent error response structure.
// hapi: Boom errors
handler: (request, h) => {
  throw Boom.badRequest('Invalid input');
}

elysia has dedicated error handling hooks.

  • You can catch specific error types globally.
  • Returns JSON errors by default.
// elysia: Error hook
app.onError(({ code, error }) => {
  return { message: error.message };
});

โšก Performance and Runtime

express runs on Node.js and is mature but slower than newer options.

  • Great stability but lacks modern runtime optimizations.
  • Works everywhere Node.js works.
// express: Node.js runtime
import express from 'express';
const app = express();
app.listen(3000);

koa runs on Node.js and is slightly lighter than Express.

  • No callback overhead improves performance slightly.
  • Still bound by Node.js event loop limits.
// koa: Node.js runtime
import Koa from 'koa';
const app = new Koa();
app.listen(3000);

hapi runs on Node.js with a focus on stability over speed.

  • Extra validation and abstraction layers add overhead.
  • Best for complex enterprise apps where speed is secondary.
// hapi: Node.js runtime
import { Server } from '@hapi/hapi';
const server = new Server({ port: 3000 });
await server.start();

elysia is optimized for Bun but supports Node.js.

  • Significantly faster on Bun due to runtime differences.
  • Best choice if you can deploy to Bun environments.
// elysia: Bun or Node runtime
import { Elysia } from 'elysia';
new Elysia().listen(3000);

๐Ÿค Similarities: Shared Ground

While the differences are clear, all four frameworks share core concepts for building web servers.

1. ๐ŸŒ HTTP Server Abstraction

  • All wrap the native Node.js http module (or Bun equivalent).
  • Handle incoming requests and outgoing responses.
// All frameworks ultimately listen on a port
app.listen(3000); // express, koa, elysia
server.start();   // hapi

2. ๐Ÿ”Œ Middleware Architecture

  • All support middleware to intercept requests.
  • Used for logging, auth, and parsing bodies.
// express
app.use(logger);
// koa
app.use(logger);
// hapi
server.ext('onRequest', logger);
// elysia
app.use(logger());

3. ๐Ÿ”’ Security Extensions

  • All rely on plugins for CORS, Helmet, and rate limiting.
  • None ship with every security feature enabled by default.
// express
app.use(cors());
// koa
app.use(cors());
// hapi
server.register(require('@hapi/cors'));
// elysia
app.use(cors());

4. ๐Ÿ“ฆ JSON Support

  • All parse JSON bodies automatically or via simple config.
  • Return JSON responses easily.
// express
app.use(express.json());
// koa
app.use(bodyparser.json());
// hapi
// Built-in payload parsing
// elysia
// Built-in JSON parsing

๐Ÿ“Š Summary: Key Differences

Featureexpresskoahapielysia
Runtime๐ŸŸข Node.js๐ŸŸข Node.js๐ŸŸข Node.js๐ŸŸฃ Bun (Primary) / Node
Style๐Ÿ“ Callback/Promiseโณ Async/Awaitโš™๏ธ Configuration๐Ÿ›ก๏ธ TypeScript First
Validation๐Ÿ”Œ External๐Ÿ”Œ Externalโœ… Built-inโœ… Built-in (Types)
Context๐Ÿ“ฆ req + res๐Ÿ“ฆ ctx๐Ÿ“ฆ request + h๐Ÿ“ฆ Typed Context
Learning Curve๐Ÿ“‰ Low๐Ÿ“‰ Low๐Ÿ“ˆ High๐Ÿ“‰ Low (for TS users)

๐Ÿ“Š Summary: Key Similarities

FeatureShared by All Four
Core Goal๐ŸŒ Build HTTP APIs
Middleware๐Ÿ”Œ Request interception
Ecosystem๐Ÿ“ฆ NPM Plugins
Language๐Ÿ’ป JavaScript/TypeScript
Deploymentโ˜๏ธ Container/Serverless

๐Ÿ’ก The Big Picture

express is the reliable workhorse ๐Ÿด โ€” it runs everything, has a plugin for anything, and every host supports it. Ideal for legacy projects, quick prototypes, or teams that need maximum hiring pool compatibility.

koa is the modernized Express ๐Ÿงน โ€” same team, cleaner code, no callback hell. Best for teams who want Express flexibility but prefer modern async/await syntax without the baggage.

hapi is the enterprise vault ๐Ÿฆ โ€” strict, configurable, and secure by default. Perfect for large organizations where configuration rules and validation matter more than setup speed.

elysia is the speed racer ๐ŸŽ๏ธ โ€” built for today's TypeScript and Bun ecosystem. Choose this for new greenfield projects where performance and type safety are top priorities.

Final Thought: All four frameworks can build robust APIs. Your choice depends on whether you value ecosystem size (express), code cleanliness (koa), configuration strictness (hapi), or modern performance (elysia).

How to Choose: express vs hapi vs elysia vs koa

  • express:

    Choose express if you need maximum compatibility with existing tutorials, plugins, and hosting providers. It is the safest bet for teams that want a vast library of middleware and don't mind managing callback-style middleware patterns.

  • hapi:

    Choose hapi if you need strict input validation and a configuration-driven architecture out of the box. It suits enterprise environments where security policies and detailed request schemas are more important than raw speed or minimal setup.

  • elysia:

    Choose elysia if you are starting a new project and want the best TypeScript experience with high performance. It is perfect for teams adopting the Bun runtime or those who want end-to-end type safety without extra code generation tools.

  • koa:

    Choose koa if you want a lighter foundation than Express with modern async/await support without the baggage of older patterns. It is ideal for teams that prefer building their own middleware stack from scratch rather than relying on a massive ecosystem.

README for express

Express Logo

Fast, unopinionated, minimalist web framework for Node.js.

This project has a Code of Conduct.

Table of contents

NPM Version NPM Downloads Linux Build Test Coverage OpenSSF Scorecard Badge

import express from 'express'

const app = express()

app.get('/', (req, res) => {
  res.send('Hello World')
})

app.listen(3000, () => {
  console.log('Server is running on http://localhost:3000')
})

Installation

This is a Node.js module available through the npm registry.

Before installing, download and install Node.js. Node.js 18 or higher is required.

If this is a brand new project, make sure to create a package.json first with the npm init command.

Installation is done using the npm install command:

npm install express

Follow our installing guide for more information.

Features

  • Robust routing
  • Focus on high performance
  • Super-high test coverage
  • HTTP helpers (redirection, caching, etc)
  • View system supporting 14+ template engines
  • Content negotiation
  • Executable for generating applications quickly

Docs & Community

PROTIP Be sure to read the migration guide to v5

Quick Start

The quickest way to get started with express is to utilize the executable express(1) to generate an application as shown below:

Install the executable. The executable's major version will match Express's:

npm install -g express-generator@4

Create the app:

express /tmp/foo && cd /tmp/foo

Install dependencies:

npm install

Start the server:

npm start

View the website at: http://localhost:3000

Philosophy

The Express philosophy is to provide small, robust tooling for HTTP servers, making it a great solution for single page applications, websites, hybrids, or public HTTP APIs.

Express does not force you to use any specific ORM or template engine. With support for over 14 template engines via @ladjs/consolidate, you can quickly craft your perfect framework.

Examples

To view the examples, clone the Express repository:

git clone https://github.com/expressjs/express.git --depth 1 && cd express

Then install the dependencies:

npm install

Then run whichever example you want:

node examples/content-negotiation

Contributing

The Express.js project welcomes all constructive contributions. Contributions take many forms, from code for bug fixes and enhancements, to additions and fixes to documentation, additional tests, triaging incoming pull requests and issues, and more!

See the Contributing Guide for more technical details on contributing.

Security Issues

If you discover a security vulnerability in Express, please see Security Policies and Procedures.

Running Tests

To run the test suite, first install the dependencies:

npm install

Then run npm test:

npm test

Current project team members

For information about the governance of the express.js project, see GOVERNANCE.md.

The original author of Express is TJ Holowaychuk

List of all contributors

TC (Technical Committee)

TC emeriti members

TC emeriti members

Triagers

Triagers emeriti members

Emeritus Triagers

License

MIT