# Batteries for your Next.js repo

Pick one per category, or none. Each battery brings working code plus the rules, skills and known fixes your agent needs for it.

- [Admin panel](https://agenticboilerplate.com/with/admin-panel) (Admin): A working /admin for your users: search and filter every account, ban and unban with a reason and an expiry, change roles, end sessions, impersonate a user with a banner and a stop button, and an audit log of every admin action. Works with Better Auth, Clerk and Supabase Auth, on Drizzle, Prisma or no database.
- [AI bundle](https://agenticboilerplate.com/with/ai-bundle) (AI): The Vercel AI SDK on Anthropic or OpenAI, split into three sub-options you toggle independently. The provider choice picks the SDK package, the API key and the model catalogue. Each sub-option adds its own files, rules, skills and docs, and nothing in one sub-option imports another.
Always generated: src/lib/ai/models.ts is the model allowlist for the chosen provider, and the only place a model id is named. src/lib/ai/provider.ts is its server-only façade. src/lib/ai/prompt.ts assembles the instructions, and src/lib/ai/untrusted.ts wraps untrusted content. src/lib/ai/messages.ts is the validated wire format and src/lib/ai/http.ts the shared error responses. src/lib/ai/access.ts decides who may call the AI routes: signed-in users when the repo has an auth battery, anyone when it does not. src/lib/ai/eval.ts, src/lib/ai/evals/** and scripts/ai-eval.ts are the prompt regression harness. scripts/ai-models.ts lists the models the app may call. Unit tests in tests/unit/ai-*.test.ts run on a mock model, so they need no key and cost nothing.
Chat adds src/app/api/chat/route.ts, the /chat page and src/components/ai/chat.tsx (built on the component kit). With an auth battery the page lives in the signed-in app (src/app/(app)/chat/page.tsx, a Chat entry in the app sidebar and a card on the dashboard); without one it is a public page (src/app/chat/page.tsx) linked from the site header. Structured output adds src/lib/ai/structured.ts, src/lib/ai/schemas.ts and the ai-structured-output rule. Tool calling adds src/lib/ai/tools/**, src/lib/ai/knowledge-base.ts, src/lib/ai/agent.ts, src/app/api/agent/route.ts, the ai-tools rule and the add-tool skill. When a streaming route ships, vercel.json turns on request cancellation for it, so Stop really stops the upstream call on Vercel.
- [Better Auth](https://agenticboilerplate.com/with/better-auth) (Sign in): Self-hosted, TypeScript-native authentication that lives in your own database. Email and password, magic links, and Google, GitHub and Microsoft sign-in (each on when its keys are set), with sign-up, password reset, account settings, a role column the admin panel can trust, and server-side session helpers with no vendor session service in the request path.
- [MDX blog](https://agenticboilerplate.com/with/blog-mdx) (Content): A file-based blog: posts are MDX files in `content/blog`, compiled at build time by @next/mdx. Ships validated frontmatter, a prerendered index and post pages, a per-post OG image, an RSS 2.0 feed and sitemap entries.
- [Payload blog](https://agenticboilerplate.com/with/blog-payload) (Content): Payload CMS running inside this Next.js app, with the admin panel at /cms. Content lives in the Postgres database you already chose. Blog pages read through the local API, not over HTTP. Drafts autosave, previews are authenticated and SQL migrations are committed.
- [Sanity blog](https://agenticboilerplate.com/with/blog-sanity) (Content): A hosted, structured blog on Sanity. The Studio mounts inside this app at /studio, and every GROQ query lives in one typed file. Draft previews use Next.js draft mode. Webhook revalidation puts a publish live in seconds, with no deploy.
- [Clerk](https://agenticboilerplate.com/with/clerk) (Sign in): Hosted authentication: Clerk's sign-in, sign-up and account settings, restyled with your design's tokens in light and dark, with Google, GitHub and Microsoft switched on from the Clerk dashboard. With a database selected, a Svix-signed webhook mirrors users into your own tables.
- [Crisp](https://agenticboilerplate.com/with/crisp) (Support): The Crisp chat widget, loaded through next/script at idle and behind a consent gate. A typed wrapper covers the `$crisp` command queue. Identification is HMAC-verified and read from the shared `@/lib/auth/session` surface. Route-based hiding keeps it off your marketing hero.
- [DataFast](https://agenticboilerplate.com/with/datafast) (Analytics): Revenue-first web analytics. The DataFast script loads from your own origin after hydration. A route handler forwards events, so ad blockers have no hostname to match. Goals are typed against a catalogue and stripped of personal data. Server-side goals go through the Goals API after the response. With Stripe, Polar or Dodo selected, every checkout carries the visitor id in its metadata. Revenue lands on the channel that earned it.
- [Dodo Payments](https://agenticboilerplate.com/with/dodo) (Payments): Subscriptions and one-time payments on Dodo Payments, a merchant of record that sells worldwide and remits sales tax for you. Hosted checkout, the customer portal, refunds and disputes that revoke access, and a Standard Webhooks endpoint with delivery-id idempotency. Plans live in src/lib/pricing.ts and /pricing renders with no keys.
- [Drizzle ORM](https://agenticboilerplate.com/with/drizzle) (ORM): TypeScript-first SQL ORM with generated SQL migrations, a typed query builder and a relational query API. It is the default ORM. It fills src/db/schema.ts through the db-schema slot, which every other battery injects its tables into. It wraps the connection your database battery configured instead of opening its own.
- [Lemon Squeezy](https://agenticboilerplate.com/with/lemonsqueezy) (Payments): Subscriptions and one-time purchases on Lemon Squeezy, the merchant of record: hosted checkout for monthly, yearly and lifetime prices, the signed customer portal, refunds that revoke access, and X-Signature verified webhooks made idempotent without a delivery id. Plans live in src/lib/pricing.ts and /pricing renders with no keys.
- [Mailgun](https://agenticboilerplate.com/with/mailgun) (Email): Transactional email through Mailgun, behind one provider-agnostic send function. React Email templates are rendered to HTML before sending. Suppression lists are read straight from Mailgun's own API. Mail routes to the EU or US region, and the event webhook is signature-verified.
- [Neon](https://agenticboilerplate.com/with/neon) (Database): Serverless Postgres with copy-on-write database branching. It ships an HTTP driver for one-shot queries and a pooled connection for route handlers that need a session. It also adds a read-only db-inspector agent, and a Bash guard that keeps migrations off the pooler.
- [Polar](https://agenticboilerplate.com/with/polar) (Payments): Subscriptions and one-time payments on Polar, the merchant of record: hosted checkout, the customer portal, refunds that revoke access, and a signature-verified webhook with delivery-id idempotency. Plans live in src/lib/pricing.ts and /pricing renders with no keys.
- [PostHog](https://agenticboilerplate.com/with/posthog) (Analytics): Product analytics with a typed event catalogue. The browser client captures page views on App Router navigations. The server client flushes with `after()`, so events go out before the serverless function exits. Identity helpers refuse to send PII. An /ingest reverse proxy sends events through your own domain, so fewer get blocked.
- [Postmark](https://agenticboilerplate.com/with/postmark) (Email): Transactional email through Postmark, behind one provider-agnostic send function. React Email templates are rendered to HTML and text before sending. Transactional and broadcast mail use separate message streams. The suppression list is mirrored from Postmark's own. A basic-auth webhook handles bounces, spam complaints and subscription changes.
- [Prisma](https://agenticboilerplate.com/with/prisma) (ORM): Prisma 7 ORM on the driver adapter for your database, with a client that survives hot reload. The schema is slotted, so every other battery writes its tables into it. Committed SQL migrations and a seed script are included.
- [Cloudflare R2](https://agenticboilerplate.com/with/r2) (Storage): S3-compatible object storage with no egress fees. You get a private bucket, presigned PUT uploads issued only after an authorisation check, and presigned downloads. Bucket CORS and lifecycle rules live in the repo as configuration. A token-only dropzone uploads straight to R2.
- [Resend](https://agenticboilerplate.com/with/resend) (Email): Transactional email through Resend, behind one provider-agnostic send function. React Email templates cover sign-in links, password resets, email checks, welcome and receipts. Every transactional send carries an idempotency key. A bounce webhook stops you mailing an address that no longer exists.
- [Sentry](https://agenticboilerplate.com/with/sentry) (Errors): Error and performance monitoring wired the way Next.js 16 expects it. instrumentation.ts covers the server and edge runtimes, and instrumentation-client.ts covers the browser. onRequestError captures Server Component and Route Handler failures. A global-error boundary catches the ones React would otherwise swallow.
The part that is not boilerplate is src/lib/observability/scrub.ts. Every event passes through it before it leaves the process. Request bodies are dropped, not filtered. Console breadcrumbs are discarded. Users are identified by opaque id only. captureHandled() attaches a stable fingerprint, so caught errors group by cause, not by whichever helper wrapped them.
- [Stripe](https://agenticboilerplate.com/with/stripe) (Payments): Subscriptions and one-time payments on Stripe: hosted Checkout, the customer portal, refunds that revoke access, and a signature-verified webhook with event-id idempotency. Plans live in src/lib/pricing.ts and /pricing renders with no keys.
- [Supabase](https://agenticboilerplate.com/with/supabase) (Database): Postgres with auth, storage and realtime attached, plus a local stack you can run from the CLI. Pick it when you want one vendor for the database and the services around it.
- [Supabase Auth](https://agenticboilerplate.com/with/supabase-auth) (Sign in): Cookie-based Supabase Auth for the Next.js App Router: sign-in with Google, GitHub and Microsoft buttons for whichever providers your Supabase project has switched on, email and password, magic links, password reset, and profile and security settings. It ships @supabase/ssr clients, session refresh in the proxy and RLS-aware query helpers, and the shared getSessionUser, requireUser and requireRole surface is backed by app_metadata.role.
- [Supabase Storage](https://agenticboilerplate.com/with/supabase-storage) (Storage): Object storage on the Supabase project you already have. A migration creates a private bucket with row level security policies. Signed upload URLs are issued only after an authorisation check. You also get signed downloads, on-the-fly image transformation and a token-only dropzone that uploads straight to storage.
- [Vercel Blob](https://agenticboilerplate.com/with/vercel-blob) (Storage): Object storage on the platform you already deploy to, in a private Blob store. Client uploads go straight from the browser to Blob after an authorisation check. Each client token is locked to one pathname, one content type and one size. Downloads use short-lived signed URLs, and the dropzone has progress and cancel.

---

Agentic Boilerplate: A Next.js repo your agent already knows. Free during launch, then $99 once.

- Site map for agents: https://agenticboilerplate.com/llms.txt
- Public API: https://agenticboilerplate.com/openapi.json
- Contact: agenticstudio@gmail.com
