FlowiseAI/Flowise · error · Error

Failed to parse Zod schema

Error message

Failed to parse Zod schema: ${error.message}

What it means

parseZodSchema is the single public entry of SecureZodSchemaParser. Its try-block runs cleanSchemaString -> parseSchemaStructure -> buildZodSchema; any error is caught and rethrown as 'Failed to parse Zod schema: <error.message>'. This nests the inner message (which is itself one of errors 608-619) and discards the original stack, hiding the precise throw site. To find the real cause, read the suffix after the colon.

Solutions

  1. Read the suffix after 'Failed to parse Zod schema: ' to identify the underlying error (608-619) and fix that.
  2. Simplify the schema to the supported subset: top-level z.object, base types in ALLOWED_TYPES, modifiers in ALLOWED_TYPES.
  3. As a maintainer: preserve the original error via 'throw new Error(msg, { cause: error })' so the stack survives.

Example fix

// before: caller loses the underlying cause
try { SecureZodSchemaParser.parseZodSchema(str) } catch (e) { console.log(e.message) }
// -> 'Failed to parse Zod schema: Unsupported type: bigint'  (read the suffix)

// fix the schema: replace unsupported type
// before: 'z.object({ id: z.bigint() })'
// after:  'z.object({ id: z.string() })'
Defensive patterns

Strategy: try-catch

Validate before calling

// Validate shape before parsing using the same rules the parser enforces.
function looksParsable(s: string): boolean {
  const c = s.replace(/\/\/.*$/gm, '').replace(/\/\*[\s\S]*?\*\//g, '').replace(/\s+/g, ' ').trim()
  return c.startsWith('z.object(') && /z\.object\(\s*\{[\s\S]*\}\s*\)/.test(c)
}

Type guard

const isZodSchemaString = (s: unknown): s is string =>
  typeof s === 'string' && s.replace(/\s+/g, ' ').trim().startsWith('z.object(')

Try / catch

try {
  return SecureZodSchemaParser.parseZodSchema(schemaString)
} catch (e) {
  // the suffix after 'Failed to parse Zod schema: ' is the real cause
  const cause = (e as Error).message.replace(/^Failed to parse Zod schema: /, '')
  throw new Error(`Schema rejected (${cause})`, { cause: e })
}

Prevention

When it happens

Trigger: Any malformed or unsupported schema string passed to SecureZodSchemaParser.parseZodSchema — the specific reason is the suffix (e.g. '... Schema must start with z.object()', '... Unsupported type: bigint').

Common situations: User-defined tool/input schema stored as a string and parsed at runtime; schema written against full Zod but the secure parser only supports a subset; copy-pasting a Zod schema from docs that uses unsupported types/modifiers.

Understand the failure class

Related errors


AI-assisted analysis of FlowiseAI/Flowise@abe4a8601a (2026-08-12). Data as JSON: /api/errors/d0ca7e66665fd696. Report an issue: GitHub.

Appendix: source

Thrown at packages/components/src/secureZodParser.ts:40

    /**
     * Safely parse a Zod schema string into a Zod schema object
     * @param schemaString The Zod schema as a string (e.g., "z.object({name: z.string()})")
     * @returns A Zod schema object
     * @throws Error if the schema is invalid or contains unsafe patterns
     */
    static parseZodSchema(schemaString: string): z.ZodTypeAny {
        try {
            // Remove comments and normalize whitespace
            const cleanedSchema = this.cleanSchemaString(schemaString)

            // Parse the schema structure
            const parsed = this.parseSchemaStructure(cleanedSchema)

            // Build the Zod schema securely
            return this.buildZodSchema(parsed)
        } catch (error) {
            throw new Error(`Failed to parse Zod schema: ${error.message}`)
        }
    }

    private static cleanSchemaString(schema: string): string {
        // Remove single-line comments
        schema = schema.replace(/\/\/.*$/gm, '')

        // Remove multi-line comments
        schema = schema.replace(/\/\*[\s\S]*?\*\//g, '')

        // Normalize whitespace
        schema = schema.replace(/\s+/g, ' ').trim()

        return schema
    }

    private static parseSchemaStructure(schema: string): any {
        // This is a simplified parser that handles common Zod patterns safely

View on GitHub (pinned to abe4a8601a)