Skip to content

Frequently asked questions

12 questions

What is supastack?

supastack is a modular foundation for building AI-powered SaaS products. It brings together common infrastructure so you can focus on product-specific features.

Does it support web and mobile?

Yes. supastack includes Next.js and Expo apps as starting points for web and mobile experiences.

What authentication is included?

Better Auth covers email/password, OTP, and social sign-in. Personal workspaces are provisioned with the account so product records stay scoped from day one.

How does it support AI?

supastack includes configurable multi-provider AI, usage tracking, budgets, and encrypted bring-your-own-key support.

How are subscriptions handled?

For products built on the kit, Stripe billing, subscriptions, and entitlements form the paid-access foundation. Provider secrets stay server-only.

Where does my product-specific code live?

Product-specific features remain in a separate codebase while the product configures and integrates supastack’s foundation modules.

How does supastack pricing work?

The kit is a one-time purchase with lifetime updates: One Framework at $249 or All Frameworks (Next.js, iOS, Android) at $499, plus $75 per extra developer seat. No kit subscription. Checkout on this site is not connected yet.

How do workspaces scope my data?

User-owned records are scoped by workspaceId. Identity, entitlements, AI usage, billing events, and audit entries stay inside the personal workspace boundary.

How do background jobs work?

Trigger.dev is the explicit job runtime. The JobRunner contract only promises enqueue, status, and cancel—workflow semantics stay Trigger.dev-specific and explicit.

How is email different from outreach?

Transactional email covers product workflows such as completion notices. Cold outreach and campaigns are product concerns outside this kit’s email module.

Can mobile expose Stripe Checkout?

Not yet. Mobile must not present Stripe Checkout until RevenueCat exists. Web can use Stripe for subscriptions and entitlements when billing is configured.

Where do AI provider keys live?

Bring-your-own-key credentials are encrypted and stay server-only. Keys are redacted from logs; usage and budgets remain visible at the workspace level.

Open full FAQ page
Documentation
Browse documentation

Web / Product surfaces

Organizations and invites

Ship the demo-style org loop: create, switch, invite, roles, leave, and danger-zone delete.

Setup and configuration

Organization workspaces are distinct from personal workspaces in packages/db. After signup, onboarding gates (/onboarding, /new-organization, /select-organization, /choose-plan) push the user into an active org before product billing and settings.

Invites create a pending workspace_invitation row and send transactional email with a /invite/[token] accept URL. Accept requires a matching signed-in email. Member list, role updates, and leave live under /settings/members; rename/delete and leave also appear on /organization/settings.

Routes
  /new-organization
  /select-organization
  /invite/[token]
  /settings/members
  /organization/settings

Server actions
  createOrganizationAction
  createWorkspaceInviteAction
  acceptWorkspaceInviteAction
  updateMemberRoleAction
  leaveOrganizationAction
  renameOrganizationAction
  deleteOrganizationAction

Implementation workflow

Resolve the active workspace from cookie → user preference → membership, then verify membership on every write. Owners and admins manage invites/roles; sole owners cannot leave or demote themselves.

Prefer evaluateLeaveOrganization and evaluateMemberRoleUpdate from @starterkit/db before mutating memberships. Emit member.left / member.role_changed in-app notifications after successful mutations when inAppProduct is enabled.

Keep Platform Admin / impersonation frozen until PRODUCT.md explicitly authorizes it. Guest roles remain deferred.

Verification and troubleshooting

Focused Vitest: workspace leave/role helpers, invite acceptance, organization-onboarding gates. Manual: create org → invite → accept on a second account → update role → leave as non-owner → delete as owner with typed confirm.