Mastra
Mastra AI
Agent framework focused on composable workflows, tooling, and modern developer ergonomics.
Curated by Tiberiu ArvaStale
Strengths
- Apache 2.0 plus enterprise path
- Fast growth
- Modern DX
Practitioner note
Promising TypeScript-first framework for product teams that want modern developer ergonomics, but enterprise proof points are still earlier than older stacks.
Warning
Governance posture
Reviewed 2026-05-26Self-hosted framework; operator controls placement.
Sourcenpm-installed framework; no managed hosting for the OSS core. (self-hosted)
SourceNo built-in enterprise audit log; observability integrations, operator-configured.
SourceSelf-hosted library; SOC 2 applies to the operator's infrastructure, not the package.
Self-hosted library; ISO 27001 applies to the operator's ISMS, not the package.
Self-hosted library; ISO 42001 applies to the deploying organisation.
Developer component, not an AI system placed on the market; obligations rest with the deployer. (role: not-applicable)
Apache-2.0 core; ee/ paths under a proprietary Mastra Enterprise License (source-available). (medium)
SourceLicense history
Verified license transitions for Mastra, newest first. Relicensing is tracked as a first-class procurement risk — see the license-change feed for all tracked tools.
Mastra uses a dual-license model: most of the repo is Apache 2.0, while code under ee/ directories uses the Mastra Enterprise License.
- More restrictive
Apache 2.0 to Apache 2.0 core + EE paths
Introduced ee/ directories under the source-available Mastra Enterprise License; the core remains Apache 2.0. Origin of the current dual-license state.
mastra PR #13163: auth core, server RBAC, and adapter permission enforcement
EU AI Act obligations
Risk tier: Not applicable · as of 2026-08-23Source-backed information mapped from Mastra's tracked risk tier — not legal advice. Obligations depend on how your organisation deploys the system; see the full obligation reference and timeline.
This record's EU AI Act risk tier is marked not applicable, so no tier-specific obligations attach. Deployers embedding it in an AI system in scope of the Act should assess that system's own tier.
Change history
Source-backed and auto-detected events for this tool, newest first.
- ReleaseHigh impact
Mastra core 1.60.0 added durable execution for Agents API-created agents without redeployment and introduced a Cloudflare Sandbox provider for remote workspaces.
Release @mastra/core@1.60.0 · mastra-ai/mastra - ReleaseHigh impact
Mastra core 1.58.0 added file-based agent schedules, Oracle Database storage and vector support, an in-process QuickJS transport, and dynamic workflow APIs, with stored-workflow naming and channel-format breaking changes.
Release @mastra/core@1.58.0 · mastra-ai/mastra - Release
Mastra core 1.51.0 added durable agent crash recovery APIs and opt-in boot-time recovery for orphaned running runs.
Release @mastra/core@1.51.0 · mastra-ai/mastra - Release
Mastra 1.50.0 added a LiveKit package for realtime voice agents and workflow-backed voice turns.
Release @mastra/core@1.50.0 · mastra-ai/mastra - ReleaseHigh impact
Mastra 1.49.0 added opt-in storage retention policies and storage.prune() across core and supported storage backends.
Release @mastra/core@1.49.0 · mastra-ai/mastra - ReleaseHigh impact
Mastra 1.48.0 added cron-scheduled agent heartbeats, file-based agent and subagent auto-registration, durable suspended-run recovery, and stronger auth-context propagation across durable and Inngest execution paths.
Release @mastra/core@1.48.0 · mastra-ai/mastra - ReleaseHigh impact
Mastra 1.47.0 added AI SDK v7 model support, DurableAgent API parity for stream/resume/generate, gateway-first model discovery, AgentController routing, and eval quality gates.
Release @mastra/core@1.47.0 · mastra-ai/mastra - ReleaseHigh impact
Mastra 1.46.0 reworked Harness around isolated sessions with remote HTTP and JS-client control, enabling safer concurrent multi-user agent hosting and deterministic tool-mocked experiments.
Release @mastra/core@1.46.0 · mastra-ai/mastra - Release
Mastra 1.42.0 added trusted system-actor execution for background workflows, tool suspension primitives across agents, thread-state durability, and new observability/storage options for production agent operations.
June 12, 2026 · @mastra/core@1.42.0 · mastra-ai/mastra - ReleaseHigh impact
Mastra 1.32.0 introduced fine-grained authorization checks across agent runs, tool and workflow execution, memory thread access, server adapters, and MCP paths.
Release @mastra/core@1.32.0 · mastra-ai/mastra · GitHub - License changeHigh impactMastra adds source-available Enterprise License paths beside its Apache 2.0 core
Mastra introduced ee/ directories under the source-available Mastra Enterprise License alongside the Apache 2.0 core, moving the repo from a single permissive license to a dual-license model.
mastra PR #13163: auth core, server RBAC, and adapter permission enforcement - Auto-detectedgithubStars: 26894 → 27372
From snapshot diff 2026-08-04 → 2026-08-22.
- Auto-detectedlastRelease: 2026-07-31 → 2026-08-19
From snapshot diff 2026-08-04 → 2026-08-22.
- Auto-detectedversion: 1.55.0 → 1.60.0
From snapshot diff 2026-08-04 → 2026-08-22.
- Auto-detectedgithubStars: 26033 → 26894
From snapshot diff 2026-07-17 → 2026-08-04.
- Auto-detectedlastRelease: 2026-07-08 → 2026-07-31
From snapshot diff 2026-07-17 → 2026-08-04.
- Auto-detectedversion: 1.50.0 → 1.55.0
From snapshot diff 2026-07-17 → 2026-08-04.
- Auto-detectedgithubStars: 24843 → 26033
From snapshot diff 2026-06-07 → 2026-07-17.
- Auto-detectedlastRelease: 2026-05-27 → 2026-07-08
From snapshot diff 2026-06-07 → 2026-07-17.
- Auto-detectedversion: 1.37.0 → 1.50.0
From snapshot diff 2026-06-07 → 2026-07-17.
Explore the category
Compare this tool against the rest of its category and the cloud platform foundation layer.
Return to the category grid to compare governance posture across every tracked tool.
Review Microsoft Foundry, Amazon Bedrock, and Gemini Enterprise Agent Platform as the foundation layer.
Track releases, deprecations, license changes, and other market movements.