docs RestermScript
Overview
What RestermScript is, when to use it and where it runs.
RestermScript (or RTS which you will see quite often throughout the docs) is Resterm's built in expression language for templates, directives, and reusable modules. It is designed to be small, bounded, and easy to review inside request files. JavaScript via Goja is still available, but RestermScript is the preferred option when you want predictable behavior, clear errors, and safe execution.
Why this even exists
- RTS is bounded and predictable because expressions run with strict step limits, cannot perform network operations or file writes, and only read files via
json.filewhen file access is enabled. - RTS is safe because it avoids arbitrary evaluation and does not expose system APIs.
- RTS is clear because the syntax is small and purpose built for request files.
- RTS is debuggable because errors include file, line, and column information along with a call stack.
When to use it
Use RestermScript when you need small, safe logic for request evaluation and control flow.
- Template values such as
{{= expr }}are a good fit when you want computed headers, URLs, or JSON bodies. - Request and workflow control directives such as
@when,@skip-if,@if,@switch, and@for-eachcan be driven by RestermScript expressions. - Assertions using
@assertare readable and produce clear failures. - Reusable
.rtsmodules imported with@uselet you share logic across requests without bringing in JavaScript.
Use JavaScript only when you need full language features or when porting existing logic is not worth the rewrite.
Where it runs
- Templates
Authorization: Bearer {{= vars.get("auth.token") ?? env.get("auth.token") }}Templates evaluate expressions and insert their string results into request fields. They are read only and should not cause side effects.
- Directives
# @when env.has("feature")
# @assert response.statusCode == 200Directives evaluate expressions to decide whether a request runs or whether an assertion passes. They are read only and should not mutate request state.
- Modules
# @use ./rts/helpers.rts
# @use ./rts/helpers.rts as helpersModules are compiled once and expose only exported names through the alias (explicit or module name). Modules execute with rts; stdlib remains as a deprecated alias. When the host provides a request object it is available (read-only outside pre-request scripts). Modules do not automatically see env, vars, last, response, trace, or stream, so pass values into module functions explicitly.
- Apply patches
# @apply {headers: {"X-Test": "1"}}Apply patches evaluate a single RestermScript expression that returns a patch dict and applies it to the outgoing request. They run before pre-request scripts and use read-only request and vars objects.
- Pre request scripts
# @rts pre-requestPre-request scripts run full RestermScript blocks and can mutate the outgoing request and variables. They run before JavaScript pre-request blocks. The full # @script pre-request lang=rts form remains supported. Use @assert for RestermScript response checks.