DEV Community

Nishant Paudel
Nishant Paudel

Posted on

IKAREM: a zero-dependency Python ASGI framework with built-in MCP tools (looking for people to break it)

Hi, I'm Nishant Paudel, a developer from Nepal. I've been building IKAREM, an ASGI web framework whose core imports only the standard library, so pip install ikarem installs nothing else. Uvicorn, asyncpg, Jinja2 and the rest are optional extras.

What My Project Does

It's a FastAPI-style framework with the pieces you'd expect: dependency injection, typed validation, OpenAPI and Swagger docs, JWT/RBAC, signed-cookie sessions with CSRF, plugins, blueprints, a durable task queue, cron, migrations, and a cookie-jar TestClient so you can test without a server.

Two things that might be new to you:

ikarem mcp myapp:app serves every route as an MCP tool for LLM agents, with your validation schemas becoming the tool schemas.
ikarem check statically audits your handlers (dependency cycles, duplicate routes, auth gaps) so you can gate deploys on it.
python
from ikarem import Ikarem

app = Ikarem()

@app.get("/users/{uid:int}")
async def get_user(req, uid: int):
return {"uid": uid} # dicts become JSON

Target Audience

Side projects, internal tools, and small-to-medium services, and anyone who wants to minimize dependencies or expose an API to LLM agents. It is not yet a "bet your company on it" framework (see below).

Comparison

Compared with FastAPI and Litestar, IKAREM trades ecosystem size and Pydantic for a stdlib-only core and MCP built in. Compared with Flask, it's async-first with explicit req parameters instead of global proxies. On trivial routes it's slower than a bare-bones framework, and my benchmarks say so openly.

What's unproven (please read this first)

It hasn't run under real production traffic. My benchmarks are in-process, plus a ~75k-request load test over uvicorn against my own demo app.
The auth, session and static-file code has not had an independent security review.
Postgres/MySQL/SQL Server are less proven than SQLite, and it's a one-person project.

What I'm asking for: try it on something small and tell me what breaks. If you enjoy reading security-sensitive code, auth.py, session.py and static.py are the ones I most want a second pair of eyes on.

GitHub: https://github.com/nishantXnova/IKAREM
Guide (zero to production, every snippet runs in CI): in the repo under docs/

Top comments (0)