Authentication & abuse controls
Verified email flows, OAuth, password recovery, MFA, Turnstile, Redis rate limits, and authentication event history.
MIT licensed · Production-minded
Authentication, organizations, Stripe billing, a credit ledger, private storage, background jobs, and a separate admin console—connected through one enforceable architecture.
The starter focuses on the parts that become expensive after launch: ownership, retries, reconciliation, operational access, and explicit boundaries.
Verified email flows, OAuth, password recovery, MFA, Turnstile, Redis rate limits, and authentication event history.
Stripe Prices drive checkout; lifecycle webhooks update organization subscriptions and capability checks.
An append-only, traceable ledger connects purchases, grants, task spending, reversals, and balances.
Personal and shared workspaces, invitations, roles, last-owner protection, and pooled resources.
Private S3-compatible uploads, signed access, lifecycle state, and a durable retryable database queue.
A separately deployed admin application with MFA, read/write roles, audit events, and billing visibility.
Routes translate HTTP. Services own invariants. Models own queries. The database owns constraints. Tests stop those boundaries from quietly dissolving.
Authenticate, validate, and translate HTTP into a business operation.
Coordinate invariants, idempotency, authorization, and side effects.
Provide typed, tenant-aware persistence behind one query boundary.
Enforce uniqueness, ownership, references, and durable state transitions.