Ecko use cases

Thirty-two workloads where typed AI, deterministic tests, exact decimals, capability grants, and one binary for web, CLI, and SaaS backends actually matter. These are the places where you need to ship, not just demo.

Data pipelines and migrations

Moving a lot of records, once, correctly

A billion-row backfill

It runs once, against real records, and it has to finish. Enrichment fetched ahead of the transform kept the hot loop from blocking on lookups.

Enrichment that runs ahead of the row · Arithmetic that will not be quietly wrong · Nothing to install on the box

Background processing

Work that runs unattended, on a schedule

Customer support triage

Mock mode is deterministic and schema-valid, so routing logic has real CI tests with no API key and no flakiness.

Deterministic mock mode · Typed labels · One binary on the worker

Fast APIs

Request paths with no warmup and no pause

Multi-tenant AI features

Per-tenant keys, tokens() and cost() to price each request, and a JSONL trace of every call - so inference spend is attributable without a separate metering microservice.

Built-in metering · Trace per request · Provider config per env

Web apps

Server-rendered apps and static sites

Server-rendered SaaS apps

The webkit package gives you auto-escaping templates, signed sessions, and security middleware on top of std.web: one language from HTTP handler to HTML.

webkit batteries · std.web router · ai in the handler

Static site generation

This site is the case study: build.ecko renders every page to dist/, Cloudflare serves bytes - no Node, no bundler, no runtime in production.

Generator is an Ecko program · No production runtime · Docs from Markdown

Internal tooling

The things a team builds for itself

MCP servers for internal systems

The mcp package does client and server, and the capability model is exactly what you want when exposing internal tools to an agent.

mcp package both ways · Grants on imports · One binary deployment

Internal admin CLIs

The cli package for flags and subcommands, one binary to scp, and mock mode for dry-run paths that still execute real validation logic.

cli package · Single artefact · Dry-run in mock mode

Regulated work

Where you must prove what happened

Insurance claims intake

Typed extraction into structs beats prompt-and-parse, and JSONL tracing gives you a per-claim audit trail with token and cost attribution.

Typed extraction · JSONL tracing · Per-claim attribution

KYC and AML review

The secret and reveal builtins keep PII out of logs by construction, and capability grants let you prove a component never had network access.

Secrets by type · Capability grants · Offline mock mode