Skip to content

Trusted Applications

Understanding trusted applications helps you work with single-spa confidently. Here you will learn the core ideas behind trusted applications, see working code, and pick up best practices used on real teams.

Trusted Applications Overview

Trusted Applications is a building block you will reach for often in single-spa. It keeps related logic together and makes your intent obvious to reviewers and future maintainers.

When you learn trusted applications properly, you avoid the guesswork that leads to bugs and rework. The example below shows the shape you will use in most real single-spa projects.

import { registerApplication, start } from 'single-spa';

registerApplication({
  name: '@org/app',
  app: () => System.import('@org/app'),
  activeWhen: ['/app'],
});

start();

single-spa orchestrates multiple framework apps on one page through a root config.

Trusted Applications Example

registerApplication({
  name: '@org/app',
  app: () => System.import('@org/app'),
  activeWhen: ['/app'],
});
start();
  • Start from a minimal Trusted Applications example and grow it only as needed.
  • Keep configuration explicit so Trusted Applications behaves the same in every environment.
  • Name things clearly so teammates understand your Trusted Applications at a glance.
  • Add tests around Trusted Applications early to lock in expected behaviour.

Single-SPA Cheatsheet

Core single-spa APIs related to trusted applications.

API Example Purpose
registerApplication registerApplication({ name, app, activeWhen }) Register a micro frontend
activeWhen activeWhen: ['/checkout'] Route ownership
start start() Begin routing
bootstrap export async function bootstrap() One-time setup
mount export async function mount(props) Render the app
unmount export async function unmount(props) Clean up the app
import map systemjs-importmap Locate app bundles

How Trusted Applications Works in Single-SPA

Trusted Applications is part of how single-spa lets multiple applications — even in different frameworks — coexist on one page. A root config registers each app and controls when it is active.

single-spa orchestrates multiple framework apps on one page through a root config.

  • A root config registers apps and calls start().
  • Each app exports bootstrap, mount, and unmount lifecycles.
  • activeWhen decides which routes each app owns.
  • Import maps resolve each app's bundle at runtime.

Practical Guidance for Trusted Applications

For reliable micro frontends, trusted applications should isolate failures and keep shared state minimal. Let each team own its app end to end while agreeing on a few shared contracts.

Concern Recommendation
Isolation One app's crash should not break others
Shared state Prefer shared utility modules over globals
Routing Keep activeWhen rules explicit and non-overlapping
Deployment Release via import-map updates per app

Common Mistakes

  • Skipping error handling and edge cases when wiring up trusted applications.
  • Leaving trusted applications untested, so regressions slip into production.
  • Over-engineering trusted applications before you actually need the extra flexibility.
  • Ignoring documentation, which makes trusted applications hard for the next developer to change.

Key Takeaways

  • Trusted Applications is a core part of working effectively with single-spa.
  • Start small and keep trusted applications focused on a single responsibility.
  • Apply consistent patterns so trusted applications scales across your project.
  • Test and document trusted applications to keep it maintainable over time.

Pro Tip

Pair trusted applications with automated tests from day one. It is far cheaper to catch single-spa regressions in CI than in production.