Agent skill

Sasjs Server

by sasjs in sasjs/core

Installing, configuring, and running @sasjs/server - the open-source NodeJS wrapper around the SAS binary that provides a REST API, filesystem (SASjs Drive), Stored Program execution, and web app…

MITAuto-check: notesBackend & APIs

Install Sasjs Server

skills CLI
$ npx skills add sasjs/core --skill sasjs-server -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sasjs/core sasjs-server --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sasjs/core.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/sasjs-server .claude/skills/sasjs-server && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sasjs-server
GitHub stars
132
Token cost
~2.4k tokens
SKILL.md length
1,142 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

Installing, configuring, and running @sasjs/server - the open-source NodeJS wrapper around the SAS binary that provides a REST API, filesystem (SASjs Drive), Stored Program execution, and web app…

  • Troubleshooting
  • SKILL.md covers Modes, Installation, Configuration via environment… and Developing against the API, plus 2 more sections
  • Calls curl and npx; reaches github.com; needs PRIVATE_KEY and LDAP_BIND_PASSWORD
  • Developing against sasjs/server

What it does

Sasjs Server is an agent skill from sasjs/core. Installing, configuring, and running @sasjs/server - the open-source NodeJS wrapper around the SAS binary that provides a REST API, filesystem (SASjs Drive), Stored Program execution, and web app streaming. Covers desktop vs server modes, runtimes (SAS/JS/Python/R), env vars, auth (tokens, LDAP), and mock servers. Use when deploying, troubleshooting, or developing against sasjs/server.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering REST APIs. It works with Python and Node.js. The repository describes itself as: Macros for SAS® App Developers. The licence is MIT.

When your agent uses it

  • Troubleshooting
  • Developing against sasjs/server

Example prompts

  • “/sasjs-server”

Requirements

  • Node.js
  • Docker
  • A credential in PRIVATE_KEY

What it can do on your machine

Read from SKILL.md and the folder at commit b13a83f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • PRIVATE_KEY
    • LDAP_BIND_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sasjs Server loads about 2.4k tokens when it runs. Until then it costs about 100 tokens; SKILL.md has 1,142 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~100
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:37
    rted, prepended to the command, or in a `.env` file alongside the executable. Key variables:

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sasjs/core at commit b13a83f, republished under its MIT licence (© sasjs). 1,142 words, ~2,436 tokens.

Download SKILL.mdSave it as .claude/skills/sasjs-server/SKILL.md (or your agent's skills folder).
name
sasjs-server
description
Installing, configuring, and running @sasjs/server - the open-source NodeJS wrapper around the SAS binary that provides a REST API, filesystem (SASjs Drive), Stored Program execution, and web app streaming. Covers desktop vs server modes, runtimes (SAS/JS/Python/R), env vars, auth (tokens, LDAP), and mock servers. Use when deploying, troubleshooting, or developing against sasjs/server.

@sasjs/server

SASjs Server is an open-source NodeJS wrapper for calling the SAS binary executable. It runs on a real SAS server or a local desktop and provides:

  • A filesystem (SASjs Drive) for storing SAS programs and content
  • Execution of Stored Programs from a URL (equivalent to SAS 9 Stored Processes / Viya Jobs)
  • Web app streaming (serve frontend apps straight from SAS content)
  • A REST API with Swagger docs
  • Portability: apps built for SASjs Server deploy unchanged to SAS 9 / Viya via @sasjs/cli

Modes

  • Desktop mode (MODE=desktop, default): single-user, no authentication, no database. CORS enabled by default.
  • Server mode (MODE=server): multi-user with authentication, requires a database (DB_CONNECT, DB_TYPE=mongodb|cosmos_mongodb). CORS disabled by default - configure WHITELIST if enabling.

Installation

Download the relevant zip from GitHub releases, verify it before running: pin a specific release tag (not latest), check the published SHA256 checksum, or - better - build from source.

bash
curl -L https://github.com/sasjs/server/releases/download/R/<asset>.zip > <asset>.zip   # replace R with the pinned release tag
sha256sum <asset>.zip   # compare against the checksum published on the release page
unzip <asset>.zip && ./api-linux

[Curl-pipe-bash and blind latest downloads are supply-chain risks. Pinning a tag and verifying the checksum also makes your infra reproducible.]

On first run it prompts (unless set as env vars) for the SAS executable path and the filesystem location for Stored Programs/temp files. Docker is also supported (DockerfileApi, docker-compose files in the repo).

Configuration via environment variables

Set in /etc/environment, exported, prepended to the command, or in a .env file alongside the executable. Key variables:

VariablePurpose
MODEdesktop (default) or server
SAS_PATHPath to sas.exe / sas.sh
RUN_TIMESComma-separated runtime priority, e.g. sas,js,py - options: sas, js, py, r. Each needs its path: SAS_PATH, NODE_PATH, PYTHON_PATH, R_PATH
SASJS_ROOTWorking directory: SAS WORK, staged files, drive, config
DRIVE_LOCATIONLocation for files, sasjs packages, appStreamConfig.json
PROTOCOL / PORThttp (default) or https (needs PRIVATE_KEY, CERT_CHAIN, optional CA_ROOT); default port 5000
SAS_OPTIONS / SASV9_OPTIONSExtra SAS system options auto-applied to sessions (Windows vs Unix), e.g. -NOXCMD
DB_CONNECT / DB_TYPEMongoDB connection string / type - required for server mode
AUTH_PROVIDERS + LDAP_*LDAP auth: LDAP_URL, LDAP_BIND_DN, LDAP_BIND_PASSWORD, LDAP_USERS_BASE_DN, LDAP_GROUPS_BASE_DN
CORS / WHITELISTCORS is only applied when CORS=enable, and only origins in WHITELIST (space-separated) receive Access-Control-Allow-Origin - an empty whitelist means NO cross-origin calls work
MOCK_SERVERTYPE / STATIC_MOCK_LOCATIONEmulate sas9/sasviya API responses for frontend testing against a sasjs server (static canned files only - no logic)

Developing against the API

  • Server type for @sasjs/adapter / CLI targets is SASJS (serverType: 'SASJS'); auth is token-based.
  • The REST API is self-documented via Swagger on the running instance.
  • Server-side execution uses ms_* macros from @sasjs/core (e.g. ms_createfile, ms_adduser2group) - services/jobs deployed by the CLI work as on other platforms.
  • Repo layout (for contributors): api/ (Express/TypeScript backend: controllers, routes, middlewares, model), web/ (frontend), restClient/ (REST examples), mongo-seed/ (server-mode DB seed).

Mock services with the JS runtime (no SAS required)

With RUN_TIMES=js (and NODE_PATH set), any .js file on SASjs Drive is an executable Stored Program - this is how react-seed-app / Data Controller provide mock backends for frontend development. This is full server-side code execution by design. Treat JS runtime as a privilege boundary:

  • Only ever enable js in a trusted, local/desktop context (no shared tenancy, no public exposure)
  • Restrict Drive write/upload to trusted authors; the auth providers (AUTH_PROVIDERS, LDAP) and desktop-only mode (MODE=desktop, default) are the guardrails that keep this safe
  • Do NOT enable the js runtime on a multi-user production server unless Drive auth and upload are locked down

Desktop mode (MODE=desktop) has no auth, which makes local mocking trivial - and the lack of auth is exactly why the default JS-runtime trust assumptions hold there.

Writing a JS stored program (docs: https://server.sasjs.io/storedprograms/#js-programs):

  • The runtime template predeclares const fs = require('fs'), _program, weboutPath, _SASJS_TOKENFILE, _SASJS_WEBOUT_HEADERS, _SASJS_USERNAME / _SASJS_USERID / _SASJS_DISPLAYNAME, _METAPERSON, _METAUSER, SASJSPROCESSMODE. Do NOT redeclare fs - const fs = require('fs') in your program crashes it with Identifier 'fs' has already been declared.
  • Output: assign a JSON string to _webout (e.g. _webout = JSON.stringify({...})); it is written back only if non-empty. console.log() output is returned in the response log (like a SAS log). Custom response headers can be written as lines to the _SASJS_WEBOUT_HEADERS file.
  • Mimic real services by including the standard SASjs automatic fields in the JSON: _PROGRAM (from _program), SYSDATE / SYSTIME (format DDMMMYY / HH:mm), _METAUSER, SASJSPROCESSMODE.
  • URL/body parameters arrive as const <name> = \<value>`` strings.
  • Input tables (the sasjs_tables mechanism) arrive either as an inline CSV const or - when the adapter sends multipart - as an uploaded <name>.csv file in the session folder, referenced by generated module-scope consts (handle BOTH):
    • _WEBIN_FILE_COUNT (always created), _WEBIN_NAME<n> (table/field name), _WEBIN_FILENAME<n> (original filename), _WEBIN_FILEREF<n> (file contents, a Buffer from fs.readFileSync - call .toString('utf8'))
    • these consts are not on globalThis - read them via this['+name+'] (avoid dynamic code evaluation where possible; treat any dynamic code evaluation on attacker-influenced content as a red flag) or a typeof guard in module scope (server-side JS, no CSP)
    • adapter CSV quirks: header row is space-separated name:format. entries (e.g. rootdir:$char256.) - strip the :format suffix; lines end CRLF; values containing special characters are wrapped in double quotes with "" escaping
  • Adapter response shape: sasjs.request() resolves with the webout JSON already unwrapped - output tables are arrays of row objects directly on the response (res.mytable[0].COL). A table named result is perfectly fine (res.result is then that array); do NOT add your own res.result-unwrapping layer, it breaks exactly that case.
  • Third-party npm packages are NOT resolvable at runtime - bundle the service first (e.g. npx webpack --mode none --target node --entry <file> --output-path sasjsbuild/... --output-filename <name>.js), then sasjs build / sasjs deploy.
Show full SKILL.md (271 more words)Show less

Deploying mocks:

  • sasjs fs sync does NOT work on a JS-only server (it generates and runs SAS code to hash remote files). Upload files directly via the Drive API instead: DELETE then POST /SASjsApi/drive/file?_filePath=<appLoc>/services/<folder>/<name>.js (multipart file field). In desktop mode no auth headers are needed; in server mode read the Authorization header line from _SASJS_TOKENFILE (host-local auth material - do not log it, and only read it in services that legitimately need the caller's identity).
  • Mocks can be stateful with the predeclared fs. Prefer real locations over /tmp: the SASjs Drive root is derivable from weboutPath (<root>/sessions/<id>/webout.txt -> path.resolve(weboutPath, '..', '..', '..', 'drive')), and a mock configure-style service can treat a configured folder as a real local path (the server IS local). require('path') and other core modules work (only fs is predeclared).
  • A JS program can even call the server's own REST API (http://127.0.0.1:$PORT/SASjsApi/...) - e.g. to rewrite a streamed index.html on the Drive (GET + PATCH /SASjsApi/drive/file).

Gotchas:

  • The packaged binaries (api-linux etc.) reject some globally-exported NODE_OPTIONS (e.g. --network-family-autoselection) - start with NODE_OPTIONS="" ./api-linux.
  • AppStream URLs redirect to a trailing slash (/AppStream/MyApp -> 301 -> /AppStream/MyApp/) - test/automation scripts should use the trailing-slash URL directly.

Limitations

This skill is a static reference for SASjs Server - it provides guidance on installing, configuring, and running the server. It does not execute code, run shell commands, access the filesystem, connect to databases, or make network requests. References to environment variables, auth tokens, and server configuration describe what the server software uses at runtime - this skill does not read, write, or access those values itself. Terms like "execution", "runtime", and "process" refer to the SASjs Server software's behavior, not to operations performed by this skill.

© sasjs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/sasjs-server of sasjs/core.

Open the folder on GitHubat commit b13a83f

Compare with similar skills

Sasjs Server next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sasjs Server compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sasjs Server this skillsasjs/core132—~2.4kAutomated safety check: NotesMIT
Cloudflare Email Servicehodgef/apiker1273 repos~2kAutomated safety check: PassMIT
Nxvutensils/nxv136—~7.9kAutomated safety check: NotesMIT
Senior Backenddavila7/claude-code-templates32k1 repos~1.1kAutomated safety check: NotesMIT
Proxy6VKirill/claude-lane-stack122—~3.6kAutomated safety check: PassMIT
Nodejs Backend Patternsever-works/ever-works15817 repos~4kAutomated safety check: PassAGPL-3.0

Similar skills

  • Send and receive transactional emails with Cloudflare Email Service (Email Sending + Email Routing).

    127 GitHub starsUsed in 3 repos~2k tokens
    Backend & APIsAuto-check passed
  • Nxv

    utensils/nxv

    Find any version of any Nix package across nixpkgs git history using the nxv CLI or HTTP API.

    136 GitHub stars~7.9k tokensUpdated 1 mo ago
    Backend & APIsAuto-check: notes
  • Senior Backend

    davila7/claude-code-templates

    Comprehensive backend development skill for building scalable backend systems using NodeJS, Express, Go, Python, Postgres, GraphQL, REST APIs.

    32k GitHub starsUsed in 1 repo~1.1k tokens
    Backend & APIsAuto-check: notes
  • Proxy6

    VKirill/claude-lane-stack

    [RU: интеграция proxy6.net — покупка/продление прокси, пул, ipauth, scraping] proxy6.net REST API — RU proxy provider for IPv4/IPv4 Shared/IPv6/MTproto.

    122 GitHub stars~3.6k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Nodejs Backend Patterns

    ever-works/ever-works

    Build production-ready Node.js backend services with Express/Fastify, implementing middleware patterns, error handling, authentication, database integration, and API design best practices.

    158 GitHub starsUsed in 17 repos~4k tokens
    Backend & APIsAuto-check passed
  • Zhihu Search

    itwanger/toBeBetterJavaer

    Search Zhihu for content using the searchv3 API. An agent skill from itwanger/toBeBetterJavaer.

    18k GitHub stars~1.5k tokensUpdated today
    Backend & APIsAuto-check passed

More from sasjs/core

  • Sas

    sasjs/core

    Expert guidance for the SAS programming language - DATA step, PROC SQL, macro language, formats, ODS, and common procedures.

    132 GitHub stars~3.1k tokensUpdated 3 days ago
    Auto-check passed
  • Sasjs Adapter

    sasjs/core

    Frontend/Node integration with SAS backends using @sasjs/adapter - configuring the SASjs class, the exact request() inputs and response shape, authentication, file upload, and session management.

    132 GitHub stars~2.6k tokensUpdated 3 days ago
    Auto-check passed
  • Sasjs CLI

    sasjs/core

    Using the SASjs CLI (@sasjs/cli) to create, compile, build, deploy, run, and test SASjs projects against SAS 9, Viya, and SASjs server targets.

    132 GitHub stars~3.6k tokensUpdated 3 days ago
    Auto-check: notes
  • Sasjs Core

    sasjs/core

    Standards and conventions for the @sasjs/core SAS macro library (mf, mp, mm, ms, mv macros).

    132 GitHub stars~1.2k tokensUpdated 3 days ago
    Auto-check passed
  • Sasjs Framework

    sasjs/core

    Building full SASjs applications - project structure, sasjsconfig.json, services/jobs/macros folders, multi-target (SAS 9 / Viya / SASjs server) configuration, streaming frontends, mocks and tests.

    132 GitHub stars~2.4k tokensUpdated 3 days ago
    Auto-check passed

Works with

Categories

Questions about Sasjs Server

What does Sasjs Server do?

Installing, configuring, and running @sasjs/server - the open-source NodeJS wrapper around the SAS binary that provides a REST API, filesystem (SASjs Drive), Stored Program execution, and web app…. Sasjs Server is an agent skill from sasjs/core. Installing, configuring, and running @sasjs/server - the open-source NodeJS wrapper around the SAS binary that provides a REST API, filesystem (SASjs Drive), Stored Program execution, and web app streaming.

When should I use Sasjs Server?

Sasjs Server fits situations like: troubleshooting; developing against sasjs/server.

How do I install Sasjs Server in Claude Code?

Run `npx skills add sasjs/core --skill sasjs-server -a claude-code`. Or copy the skill folder (.agents/skills/sasjs-server in sasjs/core) into .claude/skills/sasjs-server in your project. Claude Code loads it when a task matches its description.

How do I install Sasjs Server in Codex?

Run `npx skills add sasjs/core --skill sasjs-server -a codex`. Or copy the skill folder (.agents/skills/sasjs-server in sasjs/core) into .agents/skills/sasjs-server in your project. Codex loads it when a task matches its description.

Can I use Sasjs Server in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sasjs/core --skill sasjs-server -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sasjs-server, .gemini/skills/sasjs-server, .github/skills/sasjs-server and .opencode/skills/sasjs-server in your project.

What does Sasjs Server need to run?

Going by SKILL.md and its folder, Sasjs Server needs the command-line tools its instructions call (curl and npx) and credentials named PRIVATE_KEY and LDAP_BIND_PASSWORD. Our summary lists: Node.js; Docker; A credential in PRIVATE_KEY.

Does Sasjs Server access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Sasjs Server safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Sasjs Server use?

Sasjs Server is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sasjs Server use?

About 2.4k tokens (SKILL.md is roughly 9.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sasjs Server?

Skills that share tags, products or a category with Sasjs Server: Cloudflare Email Service (hodgef/apiker, 127 stars), Nxv (utensils/nxv, 136 stars), Senior Backend (davila7/claude-code-templates, 32k stars) and Proxy6 (VKirill/claude-lane-stack, 122 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sasjs Server?

sasjs (a GitHub organization) maintains it in sasjs/core, which has 132 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 5, 2026.

Source: sasjs/core on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.