洪 民憙 (Hong Minhee) :nonbinary:'s avatar

洪 民憙 (Hong Minhee) :nonbinary:

@hongminhee@hollo.social

1,116 following1,901 followers

An intersectionalist, feminist, and socialist living in Seoul (UTC+09:00). @tokolovesme's spouse. Who's behind @fedify, @hollo, and @botkit. Write some free software in , , , & . They/them.

서울에 사는 交叉女性主義者이자 社會主義者. 金剛兔(@tokolovesme)의 配偶者. @fedify, @hollo, @botkit 메인테이너. , , , 等으로 自由 소프트웨어 만듦.

()

Pinned

@hongminhee@hollo.social

Hello! I'm Hong Minhee (洪 民憙), an open source software engineer in my late 30s, living in Seoul, Korea. I'm bisexual and non-binary (they/them), and an enthusiastic advocate of free/open source software and the fediverse.

I work full-time on @fedify, an ActivityPub server framework in TypeScript, funded by @sovtechfund. I'm also the creator of @hollo, a single-user ActivityPub microblog; @botkit, an ActivityPub bot framework; Hackers' Pub, a fediverse platform for software developers; and LogTape, a logging library for JavaScript and TypeScript.

I have a long interest in East Asian languages (CJK) and Unicode. I post mostly in English here, though occasionally in Japanese or in mixed-script Korean (國漢文混用體), a traditional writing style that interleaves Chinese characters with the native Korean alphabet. Wanting to write in that style was actually one of the reasons I joined the fediverse. Feel free to talk to me in English, Korean, Japanese, or even Literary Chinese!

en.wikipedia.org

Korean mixed script - Wikipedia

Pinned

はじめまして!ソウル在住の30代後半のオープンソースソフトウェアエンジニア、洪 民憙ホン・ミンヒと申します。バイセクシュアル(bisexual)・ノンバイナリー(non-binary)で、自由・オープンソースソフトウェア(F/OSS)とフェディバース(fediverse)の熱烈な支持者です。

STF(@sovtechfund)の支援を受け、TypeScript用ActivityPubサーバーフレームワーク「@fedify」の開発に専念しています。他にも、おひとり様向けのActivityPubマイクロブログ「@hollo」、ActivityPubボットフレームワーク「@botkit」、ソフトウェア開発者向けフェディバースプラットフォームHackers' Pub、JavaScript・TypeScript用ロギングライブラリLogTapeなどの制作者でもあります。

東アジア言語(いわゆるCJK)とUnicodeにも興味があります。このアカウントでは主に英語で投稿していますが、時々日本語や国漢文混用体(漢字ハングル混じり文)の韓国語でも書いています。実はこの文体で書きたくてフェディバースを始めた、という経緯もあります。日本語、英語、韓国語、漢文でも気軽に話しかけてください!

speakerdeck.com

国漢文混用体からHolloまで

本発表では、韓国語の「国漢文混用体」(漢字ハングル混じり文)を自分のフェディバース投稿に実装したいという小さな目標から始まった旅路を共有します。 この目標を達成するために、ActivityPubのJSON-LDの複雑さやHTTP Signatures、WebFingerなどの仕様を理解する必要性に…

Pinned

安寧(안녕)하세요! 저는 서울에 살고 있는 30() 後半(후반)의 오픈 소스 소프트웨어 엔지니어 洪民憙(홍민희)입니다. 兩性愛者(양성애자)(bisexual)이자 논바이너리(non-binary)이며, 自由(자유)·오픈 소스 소프트웨어(F/OSS)와 聯合宇宙(연합우주)(fediverse)의 熱烈(열렬)支持者(지지자)이기도 합니다.

STF(@sovtechfund)의 支援(지원)을 받아 TypeScript() ActivityPub 서버 프레임워크 @fedify 開發(개발)專業(전업)으로 ()하고 있습니다. 그 ()에도 싱글 유저() ActivityPub 마이크로블로그 @hollo, ActivityPub 봇 프레임워크 @botkit, 소프트웨어 開發者(개발자)를 위한 聯合宇宙(연합우주) 플랫폼 Hackers' Pub, JavaScript·TypeScript() 로깅 라이브러리 LogTape ()製作者(제작자)이기도 합니다.

()아시아 言語(언어)(이른바 CJK)와 Unicode에도 關心(관심)이 많습니다. 이 計定(계정)에서는 ()英語(영어)로 포스팅하지만, 때때로 日本語(일본어)國漢文混用體(국한문 혼용체) 韓國語(한국어)로도 씁니다. 聯合宇宙(연합우주)에 오게 된 動機(동기) () 하나가 바로 國漢文混用體(국한문 혼용체)로 글을 쓰고 싶었기 때문이기도 하고요. 韓國語(한국어), 英語(영어), 日本語(일본어), 아니면 漢文(한문)으로도 말을 걸어주세요!

logtape.org

LogTape

Unobtrusive logging library with zero dependencies—library-first design for Deno, Node.js, Bun, browsers, and edge functions

@blog@tante.cc
Omarchy should not matter. But sadly it does. As a power grab. If you don't know what Omarchy is here's the short summary. David Heinemeier Hansson, creator of RubyOnRails, owner of a software business and millionaire, decided a few months ago to go all in on Linux and - because that's just his MO - thought that turning his setup into a project made sense. Omarchy is just that: A pretty standard Arch Linux distribution with a handful of configuration files, that Heinemeier Hansson (or DHH as […]

Omarchy should not matter. But sadly it does. As a power grab.

If you don’t know what Omarchy is here’s the short summary. David Heinemeier Hansson, creator of RubyOnRails, owner of a software business and millionaire, decided a few months ago to go all in on Linux and – because that’s just his MO – thought that turning his setup into a project made sense. Omarchy is just that: A pretty standard Arch Linux distribution with a handful of configuration files, that Heinemeier Hansson (or DHH as he is often called) wrote, or vibed or whatever. There is nothing wrong with this, custom, opinionated special purpose distributions have been part of the Linux culture for a long time and provide a lot of value and experimentation that sometimes even flows back to the original project. In a way Ubuntu Linux is just that to the basis Debian.

There’s also nothing wrong in more opinionated software – quite the opposite. I do think that RubyOnRails and similar frameworks gained traction especially because they do have a clear idea of how they see the respective problem domain. There’s even the statement “There should be one – and preferably only one – obvious way to do it” in the Zen of Python. Having a strong point of view is not a bad thing in software or in general. The problem is the kind of points of view DHH has.

I don’t want to go into all the gritty details here, Brennan Kenneth Brown did a great job with their article “Normalized Fascism in Open Source: $12 Million Given to DHH“, but here’s the short version. DHH is a racist and a fascist. He recently wrote articles on how there are [Content Warning: massive racism] too many brown people in London these days. In July he wrote an [Content Warning: Racism, anti-romanism] article comparing Roma communities (using a slur for them) to “wolves” that should be “shot”. His X account is also know to be “edgy” in a similar way. A few days ago he posted sort of a manifesto for his set of config files:

Screenshot of an X post (url: https://x.com/dhh/status/2098043643395277095) from the account @dhh saying:
Unite the nerds
Hold the line
Have some fun
Beauty is truth
Heritage is duty
Command is service
Welcome the agents
Perfect the computer
Own the machine
You’re somebody now

There’s even a longer version on the website. Even without a strong background in antifascist literature or history this reads like a fascist creed. About unity and identity. About “holding the line” (against codes of conduct and the rights of marginalized people as the website explains). About how there always needs to be a strong leader who makes the decisions. Given DHH’s other writing this is not a misguided joke, this is how he thinks about the world.

I began this text writing “Omarchy should not matter” but I have not explained why it does. It’s surely not about user numbers (it’s a clunky distro aimed at people who love to cosplay hackers). But it is about power.

DHH has used his connection to CEO’s of tech corporations and his position as influencer to collect up to now above 18 million dollars of funding for Omarchy. He uses that money not for himself (he has enough of that) but to fund certain pieces of Software he uses in his distribution. Like for example the window manager hyprland whose main developer the Omarchy money now funds. What is “Vaxry” known for outside of a niche window manager? He runs a community based around LGBTQ discrimination and participates in that (see the short summary on Drew DeVault’s “Weird Little Guys of FOSS” list). His bigotry is so consistent that he was banned from participating in the Freedesktop.org community where all the other developers of window managers and the free software desktop stack collaborate. And it was long before DHH funded him.

One could see a world where a CEO using his connections to drum up some funding for free software projects would be a good thing. But that’s not the world we live in I am afraid. DHH got 3 million USD from Digital Ocean (a cloud provider) for Omarchy. Basically at the same time where Digital Ocean cancelled their support of Flathub and GNOME that amounted to a value of 50 USD per month.

DHH is using his position and his influence to accumulate donations that he then can distribute to projects that align with his fascist worldview and ambitions. And in a time where many important projects and infrastructures are strapped for cash running just on the goodwill of a handful of people that is increasingly dangerous. Not because its corporate money – a lot of funding for open source comes from corporations, they are after all who are sucking up all the surplus from people’s labor. It’s because this amount of money gives him power.

The Omarchy foundation will be where projects in desperate need of funding will be pointed. And will a project focused on human rights and social justice get funding from our fascist overlord? What kind of pressure can that exert on projects who have to decide to either die due to lack of funding or kill their code of conduct?

An open fascist is building one of the bigger sources of funding for open source fully under his individual control and sucks up a lot of money that otherwise might have gone to liberatory projects. Community projects. Antifascist projects.

And that is why Omarchy matters. Sadly. Not because of its technical merit (even though those fascists love to use the “merit” argument to fight human rights) but because of its leader, his connections and his ability to accumulate financial power. Without anyone in that ecosystem saying anything about how that leader operates and talks. And you might know the saying: If there’s a Nazi and 10 folks sitting together at a table and nobody says and does anything? There’s 11 Nazis at that table.

Omarchy got a lot of recognition recently. Not only by corporate donors but by Youtubers and other tech influencers who kept praising it and nudged people (who might not know about DHH’s exploits) towards testing it. To become “a hardcore linux user/dev” or whatever other chauvinist argument they made. This makes it dangerous.

Running Omarchy means contributing to this dynamic. It means willingly integrating oneself into a fascist community. Legitimizing it. Supporting it. Omarchy is a fascist project that normalizes fascist thinking for everyone entering that community (even unknowingly). The baseline has to be not to use that system. And as people who believe in human rights and dignity, in community and a tech world that can be better we need to oppose Omarchy. Need to make sure it gets no seat at any table. Support projects who actively refuse to collaborate. Support projects who care about human rights and flourishing. And do not do business with the companies who willingly support fascists.

Siamo tutti antifascisti!

(Share this message about Omarchy [or some other similar post] around in the tech circles you frequent. Tell people about the background of this hyped Linux distribution and its fascist leader. Quit your 1password or Digital Ocean accounts and mention that it is because the support fascists.)

Liked it? Take a second to support tante on Patreon!
Become a patron at Patreon!

CC BY-SA 4.0 This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.

right person's palm
ALT text

right person's palm

Screenshot of an X post (url: https://x.com/dhh/status/2098043643395277095) from the account @dhh saying:
Unite the nerds
Hold the line
Have some fun
Beauty is truth
Heritage is duty
Command is service
Welcome the agents
Perfect the computer
Own the machine
You’re somebody now
ALT text

Screenshot of an X post (url: https://x.com/dhh/status/2098043643395277095) from the account @dhh saying: Unite the nerds Hold the line Have some fun Beauty is truth Heritage is duty Command is service Welcome the agents Perfect the computer Own the machine You’re somebody now

@hongminhee@hollo.social

Kagi Translate is the machine translation service I reach for most.

I've tried Google Translate, DeepL, Papago, and others over the years, and for the language pairs I mostly work with (Korean, English, Japanese, and Chinese) Kagi Translate has consistently come out ahead in quality. It's a little slow, but that's never bothered me: I don't copy-paste raw machine output and call it done, I always review and edit by hand, so the extra seconds don't matter.

I'd been recommending it to people for a while, until earlier this year it went from free to paid and got harder to suggest in good conscience.

Now it's free again. If you've never used anything but Google Translate, this is a good moment to give Kagi Translate a try.

blog.kagi.com

Kagi Translate is back

Kagi Translate is moving to a freemium model and launching a new standalone Individual subscription for $8/month. Anyone with a Kagi account can continue using Translate for free with a limited monthly allowance. For people...

@zeab@fosstodon.org

Another brilliant library by @hongminhee This time for email. Called . Very impressive.

For me, the support for already sold me. But the ability to have magic link mapping with transport... Fully testable!? 😍

hackers.pub/@hongminhee/2026/u

hackers.pub

Email, decoupled from where and how: A cross-runtime, cross-provider email library for JavaScript and TypeScript

@hongminhee@hackers.pub

There's already an answer to how you send email from Node.js. Node.js has Nodemailer, and it's been a solid choice for a long time. But the code people write today doesn't only run on Node.js anymore. It's common to see it running on Deno, Bun, or an edge runtime like Cloudflare Workers, and it's common to switch providers between development and production: send nothing locally, then use SES or Resend once deployed.

So I wanted to change the question a little. Not how do you send email from Node.js, but how does an application deliver email regardless of runtime or provider. That's the question Upyo started from.

Nodemailer is great; the landscape just got bigger

If you're sending email over SMTP from Node.js, Nodemailer is enough. Its SMTP implementation is mature, it supports OAuth 2.0, and it already handles DKIM signing and calendar invitations.

The catch is that Nodemailer runs on top of Node.js built-in modules like node:net, node:tls, and node:stream. That makes it hard to use on Cloudflare Workers, Vercel Edge Runtime, or Supabase Edge Functions. Its provider support centers on SMTP too, so using an HTTP API service like Resend or SendGrid means installing that service's own SDK or relying on a third-party transport. Switching providers usually means touching application code too.

The principle of universality

Upyo is built on web standard APIs like fetch(), Web Streams, and Web Crypto. Since it doesn't depend on Node.js specific modules, the same code runs unchanged on Node.js, Deno, Bun, and edge functions.

Every email service is handled through the same Transport interface: SMTP and JMAP, Resend, SendGrid, Mailgun, Amazon SES, Plunk, Lettermint. Swap out how the transport is constructed and the application code that sends mail stays the same, whether that's a local SMTP server or a mock transport in development, or SES in production.

Keeping dependencies minimal follows from the same goal. @upyo/ses implements AWS Signature v4 itself instead of pulling in the AWS SDK. The AWS SDK assumes Node.js, and using it as is would make the transport unusable on Deno, Bun, or an edge runtime.

Separating retry logic from application logic

The Transport interface itself is small. send() sends one message, sendMany() sends several, and cancellation goes through a standard AbortSignal.

How sendMany() is implemented differs by transport. The transport for a provider like Resend or SendGrid that exposes a batch endpoint calls that endpoint directly. SMTP, where reusing one connection for several messages is the natural approach, does that instead. A transport without either optimization might still run several send() calls concurrently instead of one after another, to cut down total time.

Because the interface is this small, the answer to where retry policy should live changes. Wrap a transport in RetryTransport and application code never needs its own retry logic.

That's possible because application code only knows the Transport interface type, not a concrete implementation. The function that sends mail takes a transport: Transport parameter, and the caller decides which transport gets injected.

Providers fail differently; what if that didn't matter?

import { MockTransport } from "@upyo/mock";
import { RetryTransport } from "@upyo/retry";

const provider = new MockTransport();

const transport = new RetryTransport(provider, {
  maxAttempts: 3,
  backoff: {
    baseDelayMilliseconds: 1000,
    maxDelayMilliseconds: 30000,
    factor: 2,
  },
});

RetryTransport implements the same Transport interface, so application code doesn't need to know whether it's talking to SMTP or SES, or whether retries are even happening. Wrap it in PoolTransport and a failing provider can fail over to the next one by priority, or traffic can be spread across several with round robin.

import { PoolTransport } from "@upyo/pool";

const pool = new PoolTransport({
  strategy: "priority",
  transports: [
    { transport: primaryProvider, priority: 100 },
    { transport: backupProvider, priority: 10 },
  ],
  maxRetries: 3,
});

The two can be stacked. Whether you retry per provider before failing over to the next, or retry the whole pool as a single operation, comes down to which one sits on the outside.

This composition works because every transport returns failures in the same shape. Upyo's Receipt is a discriminated union of success and failure, and a failure carries structured fields like retryable, category, and retryAfterMilliseconds. Once each transport translates a provider's error into these fields, RetryTransport can decide whether to retry a 429 from Resend or a transient SMTP error the same way.

The annoying part of building magic-link login was never the login itself. It was opening an inbox every time and waiting for the link to show up, when the link never needed to be delivered anywhere during development.

The function that sends mail was written to take a Transport from the start.

import { createMessage } from "@upyo/core";
import type { Transport } from "@upyo/core";

async function sendMagicLink(transport: Transport, email: string, link: string) {
  await transport.send(createMessage({
    from: "auth@example.com",
    to: email,
    subject: "Your login link",
    content: { text: `Click to log in: ${link}` },
  }));
}

@upyo/logtape wraps another transport and logs instead of sending. In development, that's what gets injected.

import { LogTapeTransport } from "@upyo/logtape";
import { SmtpTransport } from "@upyo/smtp";

const smtp = new SmtpTransport({
  host: "smtp.example.com",
  port: 587,
  auth: { user: "smtp-user", pass: "smtp-password" },
});

const transport = process.env.NODE_ENV === "development"
  ? new LogTapeTransport({ category: ["app", "email"] })
  : new LogTapeTransport({ transport: smtp, category: ["app", "email"] });

Copy the link straight out of the server log and paste it into the browser. No refreshing an inbox.

Automated tests use the same injection point. This time, sendMagicLink() gets @upyo/mock's MockTransport instead.

import { MockTransport } from "@upyo/mock";
import assert from "node:assert/strict";

const transport = new MockTransport();

await sendMagicLink(transport, "user@example.com", "https://example.com/verify?token=...");

const sent = await transport.waitForMessage(
  (msg) => msg.subject.includes("login link"),
  1000,
);

assert.equal(sent.recipients[0].address, "user@example.com");

sendMagicLink() itself never changed. Only the Transport handed to it did.

A small API that still holds the complexity

A small Transport interface doesn't mean the messy parts of email got skipped. The SMTP transport handles internationalized addresses through SMTPUTF8 and requests delivery status notifications through DSN. Attachments stream, so even large files don't sit in memory. The Message.calendar field turns a message into a meeting invitation or cancellation, and messageId, inReplyTo, and references let outgoing mail be part of a conversation rather than a one-off notice.

Getting started

To send over SMTP, install these packages.

npm add @upyo/core @upyo/smtp
import { createMessage } from "@upyo/core";
import { SmtpTransport } from "@upyo/smtp";

const transport = new SmtpTransport({
  host: "smtp.example.com",
  port: 587,
  auth: { user: "smtp-user", pass: "smtp-password" },
});

const message = createMessage({
  from: "sender@example.com",
  to: "recipient@example.com",
  subject: "Hello from Upyo",
  content: { text: "This is a test email." },
});

await transport.send(message);

Layer RetryTransport, PoolTransport, or LogTapeTransport on top as needed. Configuration for each transport is in the docs, the source is on GitHub, and packages are on npm and JSR.

That's the answer so far to the question I started with: how an application delivers email regardless of runtime or provider. There's still plenty to refine, so if something's broken or missing, an issue or a discussion is welcome.

jsr.io

@upyo/core - JSR

@upyo/core on JSR: Simple email sending library for Node.js, Deno, Bun, and edge functions

JavaScript/TypeScript向けの次世代メールライブラリ、Upyo 0.6.0のリリースに合わせて、Nodemailerのような定番のライブラリがある中でなぜUpyoを選ぶ価値があるのかを書きました。

https://zenn.dev/hongminhee/articles/87c258a39ab83a

zenn.dev

メールは、どこからどう送るかを問わない——複数のランタイムとメールサービスに対応した、JavaScript・TypeScript向けメールラ

JavaScript/TypeScript를 ()次世代(차세대) 이메일 라이브러리인 Upyo 0.6.0의 릴리스를 맞이하여, Nodemailer 같은 有力(유력)旣成(기성) 라이브러리를 두고 왜 Upyo를 쓰는 게 좋은지 說明(설명)하는 글을 써 보았습니다.

https://hackers.pub/@hongminhee/2026/upyo-email-decoupled-from-where-and-how/ko

@hongminhee@hackers.pub

There's already an answer to how you send email from Node.js. Node.js has Nodemailer, and it's been a solid choice for a long time. But the code people write today doesn't only run on Node.js anymore. It's common to see it running on Deno, Bun, or an edge runtime like Cloudflare Workers, and it's common to switch providers between development and production: send nothing locally, then use SES or Resend once deployed.

So I wanted to change the question a little. Not how do you send email from Node.js, but how does an application deliver email regardless of runtime or provider. That's the question Upyo started from.

Nodemailer is great; the landscape just got bigger

If you're sending email over SMTP from Node.js, Nodemailer is enough. Its SMTP implementation is mature, it supports OAuth 2.0, and it already handles DKIM signing and calendar invitations.

The catch is that Nodemailer runs on top of Node.js built-in modules like node:net, node:tls, and node:stream. That makes it hard to use on Cloudflare Workers, Vercel Edge Runtime, or Supabase Edge Functions. Its provider support centers on SMTP too, so using an HTTP API service like Resend or SendGrid means installing that service's own SDK or relying on a third-party transport. Switching providers usually means touching application code too.

The principle of universality

Upyo is built on web standard APIs like fetch(), Web Streams, and Web Crypto. Since it doesn't depend on Node.js specific modules, the same code runs unchanged on Node.js, Deno, Bun, and edge functions.

Every email service is handled through the same Transport interface: SMTP and JMAP, Resend, SendGrid, Mailgun, Amazon SES, Plunk, Lettermint. Swap out how the transport is constructed and the application code that sends mail stays the same, whether that's a local SMTP server or a mock transport in development, or SES in production.

Keeping dependencies minimal follows from the same goal. @upyo/ses implements AWS Signature v4 itself instead of pulling in the AWS SDK. The AWS SDK assumes Node.js, and using it as is would make the transport unusable on Deno, Bun, or an edge runtime.

Separating retry logic from application logic

The Transport interface itself is small. send() sends one message, sendMany() sends several, and cancellation goes through a standard AbortSignal.

How sendMany() is implemented differs by transport. The transport for a provider like Resend or SendGrid that exposes a batch endpoint calls that endpoint directly. SMTP, where reusing one connection for several messages is the natural approach, does that instead. A transport without either optimization might still run several send() calls concurrently instead of one after another, to cut down total time.

Because the interface is this small, the answer to where retry policy should live changes. Wrap a transport in RetryTransport and application code never needs its own retry logic.

That's possible because application code only knows the Transport interface type, not a concrete implementation. The function that sends mail takes a transport: Transport parameter, and the caller decides which transport gets injected.

Providers fail differently; what if that didn't matter?

import { MockTransport } from "@upyo/mock";
import { RetryTransport } from "@upyo/retry";

const provider = new MockTransport();

const transport = new RetryTransport(provider, {
  maxAttempts: 3,
  backoff: {
    baseDelayMilliseconds: 1000,
    maxDelayMilliseconds: 30000,
    factor: 2,
  },
});

RetryTransport implements the same Transport interface, so application code doesn't need to know whether it's talking to SMTP or SES, or whether retries are even happening. Wrap it in PoolTransport and a failing provider can fail over to the next one by priority, or traffic can be spread across several with round robin.

import { PoolTransport } from "@upyo/pool";

const pool = new PoolTransport({
  strategy: "priority",
  transports: [
    { transport: primaryProvider, priority: 100 },
    { transport: backupProvider, priority: 10 },
  ],
  maxRetries: 3,
});

The two can be stacked. Whether you retry per provider before failing over to the next, or retry the whole pool as a single operation, comes down to which one sits on the outside.

This composition works because every transport returns failures in the same shape. Upyo's Receipt is a discriminated union of success and failure, and a failure carries structured fields like retryable, category, and retryAfterMilliseconds. Once each transport translates a provider's error into these fields, RetryTransport can decide whether to retry a 429 from Resend or a transient SMTP error the same way.

The annoying part of building magic-link login was never the login itself. It was opening an inbox every time and waiting for the link to show up, when the link never needed to be delivered anywhere during development.

The function that sends mail was written to take a Transport from the start.

import { createMessage } from "@upyo/core";
import type { Transport } from "@upyo/core";

async function sendMagicLink(transport: Transport, email: string, link: string) {
  await transport.send(createMessage({
    from: "auth@example.com",
    to: email,
    subject: "Your login link",
    content: { text: `Click to log in: ${link}` },
  }));
}

@upyo/logtape wraps another transport and logs instead of sending. In development, that's what gets injected.

import { LogTapeTransport } from "@upyo/logtape";
import { SmtpTransport } from "@upyo/smtp";

const smtp = new SmtpTransport({
  host: "smtp.example.com",
  port: 587,
  auth: { user: "smtp-user", pass: "smtp-password" },
});

const transport = process.env.NODE_ENV === "development"
  ? new LogTapeTransport({ category: ["app", "email"] })
  : new LogTapeTransport({ transport: smtp, category: ["app", "email"] });

Copy the link straight out of the server log and paste it into the browser. No refreshing an inbox.

Automated tests use the same injection point. This time, sendMagicLink() gets @upyo/mock's MockTransport instead.

import { MockTransport } from "@upyo/mock";
import assert from "node:assert/strict";

const transport = new MockTransport();

await sendMagicLink(transport, "user@example.com", "https://example.com/verify?token=...");

const sent = await transport.waitForMessage(
  (msg) => msg.subject.includes("login link"),
  1000,
);

assert.equal(sent.recipients[0].address, "user@example.com");

sendMagicLink() itself never changed. Only the Transport handed to it did.

A small API that still holds the complexity

A small Transport interface doesn't mean the messy parts of email got skipped. The SMTP transport handles internationalized addresses through SMTPUTF8 and requests delivery status notifications through DSN. Attachments stream, so even large files don't sit in memory. The Message.calendar field turns a message into a meeting invitation or cancellation, and messageId, inReplyTo, and references let outgoing mail be part of a conversation rather than a one-off notice.

Getting started

To send over SMTP, install these packages.

npm add @upyo/core @upyo/smtp
import { createMessage } from "@upyo/core";
import { SmtpTransport } from "@upyo/smtp";

const transport = new SmtpTransport({
  host: "smtp.example.com",
  port: 587,
  auth: { user: "smtp-user", pass: "smtp-password" },
});

const message = createMessage({
  from: "sender@example.com",
  to: "recipient@example.com",
  subject: "Hello from Upyo",
  content: { text: "This is a test email." },
});

await transport.send(message);

Layer RetryTransport, PoolTransport, or LogTapeTransport on top as needed. Configuration for each transport is in the docs, the source is on GitHub, and packages are on npm and JSR.

That's the answer so far to the question I started with: how an application delivers email regardless of runtime or provider. There's still plenty to refine, so if something's broken or missing, an issue or a discussion is welcome.

jsr.io

@upyo/core - JSR

@upyo/core on JSR: Simple email sending library for Node.js, Deno, Bun, and edge functions

@hongminhee@hollo.social

To mark the release of Upyo 0.6.0, a next-generation email library for JavaScript/TypeScript, I wrote a post on why it's worth choosing over an established library like Nodemailer.

https://hackers.pub/@hongminhee/2026/upyo-email-decoupled-from-where-and-how

hackers.pub

Email, decoupled from where and how: A cross-runtime, cross-provider email library for JavaScript and TypeScript

@hongminhee@hackers.pub

There's already an answer to how you send email from Node.js. Node.js has Nodemailer, and it's been a solid choice for a long time. But the code people write today doesn't only run on Node.js anymore. It's common to see it running on Deno, Bun, or an edge runtime like Cloudflare Workers, and it's common to switch providers between development and production: send nothing locally, then use SES or Resend once deployed.

So I wanted to change the question a little. Not how do you send email from Node.js, but how does an application deliver email regardless of runtime or provider. That's the question Upyo started from.

Nodemailer is great; the landscape just got bigger

If you're sending email over SMTP from Node.js, Nodemailer is enough. Its SMTP implementation is mature, it supports OAuth 2.0, and it already handles DKIM signing and calendar invitations.

The catch is that Nodemailer runs on top of Node.js built-in modules like node:net, node:tls, and node:stream. That makes it hard to use on Cloudflare Workers, Vercel Edge Runtime, or Supabase Edge Functions. Its provider support centers on SMTP too, so using an HTTP API service like Resend or SendGrid means installing that service's own SDK or relying on a third-party transport. Switching providers usually means touching application code too.

The principle of universality

Upyo is built on web standard APIs like fetch(), Web Streams, and Web Crypto. Since it doesn't depend on Node.js specific modules, the same code runs unchanged on Node.js, Deno, Bun, and edge functions.

Every email service is handled through the same Transport interface: SMTP and JMAP, Resend, SendGrid, Mailgun, Amazon SES, Plunk, Lettermint. Swap out how the transport is constructed and the application code that sends mail stays the same, whether that's a local SMTP server or a mock transport in development, or SES in production.

Keeping dependencies minimal follows from the same goal. @upyo/ses implements AWS Signature v4 itself instead of pulling in the AWS SDK. The AWS SDK assumes Node.js, and using it as is would make the transport unusable on Deno, Bun, or an edge runtime.

Separating retry logic from application logic

The Transport interface itself is small. send() sends one message, sendMany() sends several, and cancellation goes through a standard AbortSignal.

How sendMany() is implemented differs by transport. The transport for a provider like Resend or SendGrid that exposes a batch endpoint calls that endpoint directly. SMTP, where reusing one connection for several messages is the natural approach, does that instead. A transport without either optimization might still run several send() calls concurrently instead of one after another, to cut down total time.

Because the interface is this small, the answer to where retry policy should live changes. Wrap a transport in RetryTransport and application code never needs its own retry logic.

That's possible because application code only knows the Transport interface type, not a concrete implementation. The function that sends mail takes a transport: Transport parameter, and the caller decides which transport gets injected.

Providers fail differently; what if that didn't matter?

import { MockTransport } from "@upyo/mock";
import { RetryTransport } from "@upyo/retry";

const provider = new MockTransport();

const transport = new RetryTransport(provider, {
  maxAttempts: 3,
  backoff: {
    baseDelayMilliseconds: 1000,
    maxDelayMilliseconds: 30000,
    factor: 2,
  },
});

RetryTransport implements the same Transport interface, so application code doesn't need to know whether it's talking to SMTP or SES, or whether retries are even happening. Wrap it in PoolTransport and a failing provider can fail over to the next one by priority, or traffic can be spread across several with round robin.

import { PoolTransport } from "@upyo/pool";

const pool = new PoolTransport({
  strategy: "priority",
  transports: [
    { transport: primaryProvider, priority: 100 },
    { transport: backupProvider, priority: 10 },
  ],
  maxRetries: 3,
});

The two can be stacked. Whether you retry per provider before failing over to the next, or retry the whole pool as a single operation, comes down to which one sits on the outside.

This composition works because every transport returns failures in the same shape. Upyo's Receipt is a discriminated union of success and failure, and a failure carries structured fields like retryable, category, and retryAfterMilliseconds. Once each transport translates a provider's error into these fields, RetryTransport can decide whether to retry a 429 from Resend or a transient SMTP error the same way.

The annoying part of building magic-link login was never the login itself. It was opening an inbox every time and waiting for the link to show up, when the link never needed to be delivered anywhere during development.

The function that sends mail was written to take a Transport from the start.

import { createMessage } from "@upyo/core";
import type { Transport } from "@upyo/core";

async function sendMagicLink(transport: Transport, email: string, link: string) {
  await transport.send(createMessage({
    from: "auth@example.com",
    to: email,
    subject: "Your login link",
    content: { text: `Click to log in: ${link}` },
  }));
}

@upyo/logtape wraps another transport and logs instead of sending. In development, that's what gets injected.

import { LogTapeTransport } from "@upyo/logtape";
import { SmtpTransport } from "@upyo/smtp";

const smtp = new SmtpTransport({
  host: "smtp.example.com",
  port: 587,
  auth: { user: "smtp-user", pass: "smtp-password" },
});

const transport = process.env.NODE_ENV === "development"
  ? new LogTapeTransport({ category: ["app", "email"] })
  : new LogTapeTransport({ transport: smtp, category: ["app", "email"] });

Copy the link straight out of the server log and paste it into the browser. No refreshing an inbox.

Automated tests use the same injection point. This time, sendMagicLink() gets @upyo/mock's MockTransport instead.

import { MockTransport } from "@upyo/mock";
import assert from "node:assert/strict";

const transport = new MockTransport();

await sendMagicLink(transport, "user@example.com", "https://example.com/verify?token=...");

const sent = await transport.waitForMessage(
  (msg) => msg.subject.includes("login link"),
  1000,
);

assert.equal(sent.recipients[0].address, "user@example.com");

sendMagicLink() itself never changed. Only the Transport handed to it did.

A small API that still holds the complexity

A small Transport interface doesn't mean the messy parts of email got skipped. The SMTP transport handles internationalized addresses through SMTPUTF8 and requests delivery status notifications through DSN. Attachments stream, so even large files don't sit in memory. The Message.calendar field turns a message into a meeting invitation or cancellation, and messageId, inReplyTo, and references let outgoing mail be part of a conversation rather than a one-off notice.

Getting started

To send over SMTP, install these packages.

npm add @upyo/core @upyo/smtp
import { createMessage } from "@upyo/core";
import { SmtpTransport } from "@upyo/smtp";

const transport = new SmtpTransport({
  host: "smtp.example.com",
  port: 587,
  auth: { user: "smtp-user", pass: "smtp-password" },
});

const message = createMessage({
  from: "sender@example.com",
  to: "recipient@example.com",
  subject: "Hello from Upyo",
  content: { text: "This is a test email." },
});

await transport.send(message);

Layer RetryTransport, PoolTransport, or LogTapeTransport on top as needed. Configuration for each transport is in the docs, the source is on GitHub, and packages are on npm and JSR.

That's the answer so far to the question I started with: how an application delivers email regardless of runtime or provider. There's still plenty to refine, so if something's broken or missing, an issue or a discussion is welcome.

jsr.io

@upyo/core - JSR

@upyo/core on JSR: Simple email sending library for Node.js, Deno, Bun, and edge functions

@nnanananami@planet.moe
@hongminhee@hollo.social

I've released Upyo 0.6.0, an email library for JavaScript and TypeScript that works across Node.js, Deno, Bun, and edge runtimes.

This version adds MIME composition without sending, streaming attachments over SMTP, and calendar invitations. You can also set message identifiers for tracking replies and check SMTP or JMAP configuration without sending a test email.

There are new Maileroo and Mailtrap transports, plus a LogTape integration for logging delivery or trying out email workflows locally.

https://github.com/dahlia/upyo/discussions/75

github.com

Upyo 0.6.0: MIME composition, streaming attachments, and calendar invitations · dahlia/upyo · Discussion #75

Upyo is a cross-runtime email library for JavaScript that provides a unified API for sending email across Node.js, Deno, Bun, and edge functions. It supports SMTP, JMAP, and HTTP email providers th...

@hongminhee@hollo.social · Reply to 花飛蒜頭貓

@Yoxem 在韓語中,【死語】似乎也同時具備這兩種含義。現代韓語詞彙受日語影響很深,所以我認為這可能是受了日語的影響。

順帶一提,在《標準國語大辭典》中,【死語】被定義為「過去曾使用但現在已不再使用的語言。或指這類單詞。例如古希臘語、古拉丁語等」。

@Yoxem@g0v.social

死語不指extinct language而指obsolete vocabulary應該是受日語影響?日語有時候稱詞為語

@hongminhee@hollo.social

今週(금주) 日曜日(일요일)(6())에 瑞草驛(서초역) 近處(근처)位置(위치)오픈업 센터(네이버地圖(지도), 카카오맵)에서 @fedify 寄與(기여)()한 모임이 열립니다. 午前(오전) 10()에서 午後(오후) 6()까지 進行(진행)되니, 關心(관심) 있는 분들은 自由(자유)롭게 오셔서 參與(참여) 바랍니다! (10()에서 18() 사이에 아무 때나 오셔서 아무 때나 가셔도 됩니다!)

place.map.kakao.com

오픈업

서울 서초구 서초대로40길 83 2층

@AltKomae@mastodon.social

都庁前に総勢22名のDJら集結、関東大震災朝鮮人犠牲者へ追悼文を送らない小池都知事に抗議 - 音楽ナタリー
natalie.mu/music/news/687676

「社会は新しい未来を生み出すのではなく、古い暴力をリミックスし続けている。2026年現在ガザで続いている虐殺も、植民地主義という同じループの変奏に他ならない。」

"사회는 새로운 미래를 만들어내는 대신, 낡은 폭력을 계속해서 리믹스하고 있다. 2026년 현재까지도 계속되고 있는 가자 지구의 학살은 바로 이 식민주의라는 동일한 루프의 또 다른 변주에 다름 아니다."

"Rather than generating a new future, society keeps remixing old violence. The massacre still unfolding in Gaza as of 2026 is nothing other than another variation on this same loop of colonialism."

@hongminhee@hollo.social · Reply to Kenji Rikitake

@jj1bdx.tokyo 私も同じ感覚です。韓国語でもこの意味の変化が起きたのは、やはりこの10年ぐらいからだと思います。日本語の漢語は韓国語でもそのまま漢字語として受け入れられやすいせいか、こういう言葉の変化が連動して起きることが結構多い気がします。

ja.wikipedia.org

漢字語 (朝鮮語) - Wikipedia

@hongminhee@hollo.social

本来「課金する」という言葉は「料金を課す」という意味だが、近年モバイルゲームなどの影響で「料金を払う」という意味にまで拡大しているという趣旨の日本語記事。ちなみに韓国語でも(おそらく日本のモバイルゲーム、あるいはその影響を受けた韓国・中国のモバイルゲームの影響で)「課金(グァグム)하다(ハダ)」という言葉が「料金を払う」という意味まで含むようになる現象が同じく起きている。

https://salon.mainichi-kotoba.jp/archives/280630

salon.mainichi-kotoba.jp

定着するか 新しい「課金」

お金を支払うことについて「課金」を使うか。回答は「使う/使わない」がほぼ半々に分かれました。新聞では紛らわしいとして、支払うことについては「課金」を使わないようにしていますが、辞書には新しい意味として載せるものもあります。

@nnanananami@planet.moe
@hongminhee@hollo.social

LogTapeを日本語で紹介する記事が公開されました。「ライブラリの中では黙って待つ」という設計思想を軸に、configure()を呼ぶまでログが一切出力されない仕組みや、ゼロ依存・5.3KBでNode.js・Deno・Bun・ブラウザ・エッジランタイムを横断して動く点、階層的カテゴリや構造化ログの実践的な使い方まで、実際に動かせるサンプル付きで解説してくださっています。設計の背景まで汲み取ってもらえて嬉しいです。

https://easegis.jp/blog/logtape/

easegis.jp

ライブラリの中では黙って待つ、LogTapeというロギング設計

ゼロ依存でNode.js・Deno・Bun・ブラウザ・Edge Runtimeすべてに対応するロギングライブラリ、LogTapeの基本から実践的な使い方まで解説します。

@hongminhee@hollo.social

After almost fifteen years, I'm done with @1password. I just read through the email exchange @mvsde posted, where 1Password's support team defended the company's patronage of DHH's Omacom Foundation with the usual “we're funding the foundation, not the individual” line. That distinction doesn't hold up when the money still legitimizes him and everyone his politics attract. I've trusted 1Password with my passwords for longer than most of my relationships have lasted, and that's exactly why this matters: loyalty like that shouldn't be free. Migration starts this week.

@mvsde@mastodon.social
Screenshot of an email to 1Password support:

Hi,

I'm concerned about 1Password sponsoring Omarchy and DHH.

1Password has positioned itself in support of diversity and inclusion. DHH on the other hand is strongly opposed to such values and has become increasingly far right.

https://jakelazaroff.com/words/dhh-is-way-worse-than-i-thought/

As a 1Password customer who is also queer and such the target of DHH's anti-DEI crusade, I have to think about whether I still want 1Password to receive my money. Since it's apparently directly funneled to far right white supremacists as DHH.

Regards,
Fynn Ellie Becker
ALT text

Screenshot of an email to 1Password support: Hi, I'm concerned about 1Password sponsoring Omarchy and DHH. 1Password has positioned itself in support of diversity and inclusion. DHH on the other hand is strongly opposed to such values and has become increasingly far right. https://jakelazaroff.com/words/dhh-is-way-worse-than-i-thought/ As a 1Password customer who is also queer and such the target of DHH's anti-DEI crusade, I have to think about whether I still want 1Password to receive my money. Since it's apparently directly funneled to far right white supremacists as DHH. Regards, Fynn Ellie Becker