Does this function exist in this exact npm or PyPI version?
Last updated:
Check the package name, exact version and symbol together before an agent writes the call: a real package can still lack that function in the version your lockfile selected. ExactGround reads the published npm or PyPI artifact without installing or executing it and returns exists: true, false, or null when static evidence cannot decide.
Facts and examples on this page were checked against the ExactGround API source, tests, README and linked package-format documentation on October 4, 2026.
The exact-version question
“Does this package exist?” and “does this function exist here?” are different checks. A package can be real while an agent uses an API added in a later release, removed in the pinned release, hidden behind an npm export boundary, or supplied dynamically at runtime.
Use the version resolved by your lockfile, not the newest documentation page. npm package specifications can be exact versions, ranges or dist-tags (npm package spec), while Node's exports field can expose only selected entry points and hide other package files (Node.js package entry points). PyPI's JSON API identifies the release artifacts available for a project and version (PyPI JSON API).
One request, one answer per symbol
curl -s https://dropin-apis--exactground-api.apify.actor/v1/symbols \
-H "Authorization: Bearer $APIFY_TOKEN" \
-H "Content-Type: application/json" \
-d '{"ecosystem":"pypi","package":"numpy","version":"2.1.0","symbols":["numpy.linalg.norm","numpy.asfarray"]}'The verified example returns:
{
"ecosystem": "pypi",
"package": "numpy",
"version": "2.1.0",
"packageExists": true,
"results": [
{
"symbol": "numpy.linalg.norm",
"exists": true,
"kind": "function",
"declaredIn": "numpy/linalg/_linalg.pyi"
},
{
"symbol": "numpy.asfarray",
"exists": false,
"missingAt": "numpy.asfarray",
"suggestions": ["array", "asarray", "NDArray", "ndarray", "recarray"]
}
]
}For npm, the tested React example reports react@18.2.0 useState as present and useActionState as absent. Its response identifies @types/react@18.3.31 (DefinitelyTyped) as the matching-major type source; that is evidence from the declaration fallback, not a claim that runtime implementation bytes were executed.
Interpret true, false and null differently
| Result | Meaning | Safe next action |
|---|---|---|
true | The resolved artifact's static public surface contains the symbol | Continue, then run your own tests |
false | The static surface establishes that the requested path is missing | Correct the call or version before editing |
null | Static analysis cannot know | Inspect runtime docs/source or test in an isolated environment; do not turn unknown into yes |
null is expected for cases such as a Python module with dynamic __getattr__, a compiled extension, or an npm package with no types. ExactGround does not guess in those cases.
What the checker reads
- npm: resolves the requested exact version, range or dist-tag, reads the tarball in memory, follows
exports,typesandtypesVersions, and uses the TypeScript resolver. A package without bundled types can use a matching-major@types/*fallback, disclosed intypesSource. - PyPI: reads a suitable wheel or source distribution in memory, prefers
.pyistubs, and statically follows ordinary re-exports,__all__, class members and base classes. - Neither ecosystem is executed: no install scripts and no Python imports. Archives are capped at 60 MB. Private registries are not supported by this hosted API.
Static package inspection answers availability, not safety, behavior or compatibility with the rest of your application. A present symbol can still be buggy, insecure, or misused.
Put it in an agent's decision loop
- Read the locked package and version from the project's lockfile.
- Call
check_packagesbefore any new install; a published name is not automatically trustworthy. - Call
check_symbolsfor an uncertain function, class or method before writing the call. - Treat
falseas a block andnullas an unresolved review item. - After editing, run project tests and require fresh completion evidence.
The MCP tool is check_symbols; the REST endpoint is POST /v1/symbols. Each symbol check costs $0.002. Invalid input and registry-unreachable requests are not charged, and a configured spending limit stops with HTTP 402 when reached.
FAQ
Can it check a function against the version in package-lock.json or poetry.lock?
Yes, after the agent or caller supplies the resolved package name and exact version from that lockfile. The endpoint does not read your local lockfile by itself.
Does exists: true prove the function works?
No. It proves the static published surface contains the symbol. You still need behavioral tests, compatibility checks and security review.
Why can exists be null?
Some APIs are created dynamically, implemented only in compiled code, or published without analyzable declarations. Returning unknown is more accurate than reporting a guessed yes or no.
Does the API install or import the package?
No. It reads bounded public package archives in memory and parses their static surface.