
The Next.js Supabase SaaS boilerplate that already runs the plumbing
An AI agent can scaffold a Next.js Supabase starter in minutes: a login page, a table, a dashboard. What it can't reliably produce is tenant isolation that holds under every query, billing that survives webhook retries and plan changes, and a codebase that keeps getting upgrades. This Next.js Supabase template ships those on the first run, so your agent builds features on top of them.
Customers can sign up and pay
Teams can invite each other
You can operate it
What the Supabase kit does, and how
Tenant isolation in Postgres
Account-owned tables carry an account_id and have Row Level Security enabled. Policies call helper functions like has_role_on_account, has_permission, and is_account_owner.
A query written in a hurry, by you or by an agent, still can't read another team's rows. The kit's pgTAP helpers let you test cross-account access, so a policy regression fails in CI.
Supabase Auth, fully wired
Email and password, OAuth providers, magic links, TOTP multi-factor auth, password reset, and email verification, with auth emails you can preview locally in Mailpit.
Sessions and user IDs come from the same Postgres that enforces your RLS policies, so there is no second user store to keep in sync.
Billing with provider swap
A billing gateway package sits in front of Stripe and Lemon Squeezy. Plans are defined in one config file: flat-rate, tiered, and per-seat, for personal or team accounts. Webhooks update subscription rows in the database.
Changing provider or adding a plan is a config change, and the docs cover metered usage, credits, and one-off payments when you outgrow simple subscriptions.
Typed schema and SQL migrations
Schema changes are SQL migration files. Running supabase:typegen regenerates the TypeScript types the Supabase clients use, and server actions validate input with Zod through next-safe-action.
A renamed column breaks the type check, not production.
Supabase Storage and Realtime
File uploads go through Supabase Storage, protected by the same account model. In-app notifications are stored in Postgres with RLS and can stream live over Supabase Realtime when you turn it on.
You use the Supabase services you already pay for instead of adding another vendor.
Built for agent-assisted work
AGENTS.md and CLAUDE.md files live at the root and in each package, including one for the database that spells out how to write migrations and RLS policies. The repo includes a MakerKit MCP server and a .mcp.json that Claude Code picks up automatically.
Claude Code, Cursor, or Codex write migrations and RLS policies the way the kit already does.
Who the Supabase SaaS Starter Kit is for
A good fit if you
- Want Postgres, auth, storage, and realtime from one provider
- Are building B2B SaaS where team data leaking across accounts would end the business
- Want access rules enforced in the database, readable as SQL and covered by tests
- Might ship on Next.js now and want React Router or TanStack Start available under the same license
Probably not a fit if you
- Must run on a Postgres host that isn't Supabase (pick Drizzle or Prisma below)
- Want every access check in application code rather than in SQL policies
- Can't run Docker locally; the local Supabase stack needs it
- Don't write code: this is a codebase you run, extend, and deploy yourself
Supabase vs Drizzle vs Prisma: which MakerKit stack?
All three kits ship auth, teams, billing, and an admin panel. They differ in where your data lives and where access control is enforced.
Supabase (this page)
Choose it when you want Supabase to run auth, database, storage, and realtime, and want tenant isolation enforced by RLS policies in Postgres.
Frameworks: Next.js 16, React Router 8, TanStack Start. Billing: Stripe or Lemon Squeezy.
Drizzle + Better Auth
Choose it when you want any Postgres host, auth that runs inside your app, and SQL-like queries defined in TypeScript.
See the Next.js Drizzle SaaS starter kit.
Prisma 7 + Better Auth
Choose it when your team already knows Prisma and prefers a declarative schema file, Prisma Migrate, and Prisma Studio.
See the Next.js Prisma SaaS starter kit.
Torn between the two ORMs? Read Drizzle vs Prisma for SaaS. Building on Supabase with a different framework? The same kit powers the React Router SaaS starter kit and the TanStack Start boilerplate.
What the Supabase kit gets you, and how fast it runs
What you get
- Access to the private GitHub repositories for the Next.js, React Router, and TanStack Start versions
- One-time purchase, lifetime license, unlimited projects
- Lifetime updates to the Supabase kit, including major versions, merged from the upstream remote when you choose
- Support on Discord; Pro covers 1 developer, Teams up to 5
- Client work needs the Team License, and each client needs their own license. Full terms on the license page.
- The Supabase kit documentation is public, so you can check every feature before you buy. Refunds are generally not offered once repository access is redeemed.
From purchase to first deploy
Prerequisites: Node.js 20.10+, pnpm 10.19+, Docker, Git, and working knowledge of the Next.js App Router and Supabase.
- Clone the repository and run
pnpm i. - Run
pnpm turbo gen setupto pointupstreamat MakerKit for future updates. - Start local Supabase with
pnpm run supabase:web:start(Postgres, Studio, and Mailpit in Docker). - Run
pnpm devand sign in with the seeded test user. - Follow the production checklist: Supabase project, migrations, auth URLs, SMTP, billing webhooks, hosting. The docs budget 2 to 3 hours for a first deployment.
Our customers love Makerkit ❤️
Rob, founder at Provider.app
Watch the full interview with Rob.Sebastian, founder at Watchthis
Watch the full interview with Sebastian.Michael, founder at ChatFlow
Watch the full interview with Michael.Supabase kit pricing
One-time payment, lifetime updates, unlimited projects
- Lifetime access to your stack of choice
- Build unlimited applications
- Continuous updates
- Access to the Discord community
- The best support in the SaaS Starter kits market, period.
- Community and Chat support
- Community-based feature requests and Request for Comments. You have a say in what Makerkit should build next.
- One-time payment, no subscriptions
- Includes access to our free Figma UI kit
Pro A B2B SaaS Starter Kit for individual developers.
| Teams A B2B SaaS Starter Kit for teams of developers or companies.
|
Supabase SaaS Starter Kit FAQ
What is included in the Supabase SaaS starter kit?
Supabase Auth (email and password, OAuth, magic links, TOTP MFA), personal and team accounts with owner, admin, and member roles, email invitations, subscription billing with Stripe or Lemon Squeezy, a super admin panel, in-app notifications, i18n, transactional emails, and a Turborepo monorepo with Playwright tests. The database schema and RLS policies are SQL migrations you own, with pgTAP test helpers for testing them.
Which frameworks does the Supabase kit support?
One license gives you the Supabase kit for Next.js 16, React Router 8, and TanStack Start. All three use the same Supabase-native architecture: Supabase Auth, Postgres with RLS, and Supabase Storage. Remix users should use the React Router 8 version, since Remix merged into React Router.
How does multi-tenancy work with Supabase?
Data belongs to an account (personal or team) through an account_id column. Row Level Security policies call helper functions such as has_role_on_account, has_permission, and is_account_owner, so Postgres itself decides which rows a user can read or write. You protect your own tables with the same helpers, and the kit ships pgTAP utilities to test those policies.
Can I self-host?
Yes. Supabase is open source and can be self-hosted, and the kit has deployment guides for Docker and VPS hosting in addition to Vercel and Cloudflare. If you self-host Supabase you take on backups, upgrades, and infrastructure yourself; Supabase Cloud handles that for you.
Can I use my own PostgreSQL database instead of Supabase?
Not with this kit. It depends on Supabase Auth, Storage, and RLS. If you want a plain Postgres database from Neon, Railway, RDS, or your own server, choose the Next.js Drizzle kit or the Next.js Prisma kit, which use Better Auth and run on any Postgres provider.
How are updates delivered, and for how long?
The kit is a private GitHub repository. You keep MakerKit as an upstream remote and merge updates into your project with git pull upstream main, on your own schedule. Both the Developer and Team licenses include lifetime updates to the kit you bought, including major versions.
Can my team use one license?
The Pro (Developer) license is for one developer. The Teams license gives repository access to up to 5 developers in the same organization. Building and handing over source code to clients requires the Team License, and each client needs their own MakerKit license.
Can AI coding agents work with the codebase?
Yes, that is how most customers build on it now. The repository ships AGENTS.md and CLAUDE.md files at the root and in each package (including rules for Supabase migrations and RLS), skills for Claude Code, and a MakerKit MCP server your agent can call. Claude Code, Cursor, Codex, Windsurf, Gemini, and Antigravity are covered in the docs.
I already started with another boilerplate. Can I migrate?
There is no automated importer from other boilerplates. The practical path is to recreate your domain tables as Supabase migrations with RLS, move your feature code into the app, and let the kit handle auth, teams, and billing. If you are on an older MakerKit version, the docs include dedicated upgrade guides.
Do I need to know Supabase already?
You should know the basics: creating a Supabase project, Postgres, and how the Supabase client works. The kit builds on Supabase and the Next.js App Router rather than teaching them, so expect a learning curve if both are new to you.
Can I switch to the Drizzle or Prisma kit later?
Each kit is a separate product with its own license. Existing customers get a discount when they buy another stack; the FAQ page explains how to switch.
Docs, course, and community for Supabase and Next.js
Kit-specific documentation, a guided course, and a Discord where you can ask questions about your codebase.
Documentation
Course
Discord Community
Start on a Supabase baseline where RLS already isolates every team
Spend your first week on the product, not on RLS policies, webhooks, and invitation flows.