Skip to content

Build1 publisher3 min readPublished

Google's pkg.go.dev API reaches v1 with eight JSON endpoints aimed at coding agents

Google has moved the pkg.go.dev API from v1beta to v1, giving Go tools and coding agents eight stateless JSON endpoints for package data. Programs that scraped the site's HTML can now build against a contract Google says it designed for agents and LLMs.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Google's pkg.go.dev API reaches v1 with eight JSON endpoints aimed at coding agents
Generated illustration

What happened

  • The endpoints cover package and module metadata, versions, symbols, importers, search and vulnerabilities.
  • Google's announcement says structured API access "has been one of the most highly requested features for pkg.go.dev for a while now."
  • Go 1.27, out in August, tags go test -json output lines with an OutputType field such as error, error-continue or frame.
  • On ax-go v0.6.0, the finfocus CLI advertised 37 MCP tools to agents, and four kinds of them were traps.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • decision With a v1 contract and an OpenAPI spec, Go tools that parse pkg.go.dev pages can generate a client and pin it, and keeping a scraper becomes a choice to maintain it against markup changes.
  • capability A coding agent can check a module's importers and vulnerabilities with one stateless request each before it proposes adding the dependency.
  • constraint Exact package data does not stop a model from calling standard library symbols newer than the module's go directive, so the default stdversion check in Go 1.27 stays necessary.
  • exposure Every command in a CLI's MCP schema is callable by an agent, so authors now maintain an agent-facing tool list separate from what --help shows humans.

The call is a plain GET with the version in the path. Running `curl https://pkg.go.dev/v1/package/github.com/rshade/ax-go` returns JSON with the module path, the latest version and the package synopsis [7]. Symbols and versions sit behind their own endpoints [7]. All eight endpoints are stateless [2]. A client holds no session, so each lookup fits in a single agent tool call.

That example comes from a dev.to post by the author of ax-go, a library that gives Go CLIs a `__schema` command returning their commands, flags and types as JSON [9]. For years before June, a program that wanted package facts had to scrape pkg.go.dev's HTML and hope the markup held [1][2]. The part I would build on is the `/v1/` prefix. The API comes with an OpenAPI spec [3] and has moved from v1beta to v1 [4]. Its reference client, pkgsite-cli, is a Go command-line tool over the JSON API [3][8]. The post points out that this is the shape ax-go standardizes, and declines to call it a coincidence [8].

Google states the intended consumer outright. "LLMs and agents need precise context. This API provides the data required for agents and models to reason deterministically about Go packages," the announcement says, as quoted in the post [6]. The first sentence is right. The second is a claim about the model, and an endpoint controls only what it returns. Version 1 guarantees typed fields from a published contract. Whether a model reasons deterministically over those fields depends on the model.

The post ties the API to Go 1.27, which shipped in August [10]. `go test` now runs the `stdversion` vet check by default, flagging uses of standard library symbols newer than the module's `go` directive [12]. "Humans rarely make that mistake. Models trained on newer code make it constantly," the author wrote [13]. `go fix` gained four more modernizers, which apply mechanical migrations deterministically [15]. The author also notes that the 1.27 release notes never use the word "agent" [14].

The same post documents what breaks on the tool side once agents read the schema. The trouble on ax-go v0.6.0 was in what finfocus, the author's FinOps CLI, advertised through `__schema --as=mcp` [16]. Dispatch is serialized, so one call to a blocking command stalls every call queued behind it [17]. The only lever was `Hidden`, and it was the wrong one: it pruned the whole subtree and dropped the command from `--help` for humans as well [18]. Version 0.7.0, released September 24, skips command groups and `help` automatically and adds `mcp.Exclude(cmd)` to mark one command as not-a-tool [19][20].

For a Go CLI that looks up module versions or importers, I'd move to the v1 endpoints now. Before calling them from an agent's inner loop, I'd want the rate limits, and the post does not cover them.

What to watch

  • Google publishing rate limits or authentication terms for the v1 endpoints, which decide whether agents can call them in a loop.
  • Whether gopls or the go command starts calling the v1 API for module and importer lookups.
  • Whether agent runtimes ship a default pkg.go.dev tool generated from the OpenAPI spec.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories