# Next.js boilerplate with Admin panel

> A working /admin for your users: search and filter every account, ban and unban with a reason and an expiry, change roles, end sessions, impersonate a user with a banner and a stop button, and an audit log of every admin action. Works with Better Auth, Clerk and Supabase Auth, on Drizzle, Prisma or no database.

Users, bans, impersonation and an audit log. Your code, any auth provider.

- **Category:** Admin
- **Pricing:** Free. It is your own code: no seats, no per-viewer pricing, no vendor bill. Clerk counts impersonations: 5 a month on its free plan.
- **Best for:** SaaS teams who need to answer support tickets from inside the app: find the account, see how they sign in, ban the abuser, view the app as the confused customer, and prove afterwards who did what.
- **Requires:** auth
- **Vendor docs:** https://nextjs.org/docs/app/api-reference/file-conventions/route-groups

## Trade-offs

- Admins are one role. There are no per-page permissions or custom roles out of the box; add them in `src/lib/admin/policy.ts` and your auth battery's role list.
- What each provider allows shapes the panel. Clerk cannot filter users by role or ban state and has no ban expiry (a script lifts timed bans). Supabase has no built-in impersonation, so the panel builds it from a sign-in link, and the admin signs in again afterwards.
- The audit trail needs a database. With Clerk and no database, entries go to server logs as JSON lines, which most hosts keep for days, not years.
- It lives in your Next.js app, so an admin page can leak server-only data into a client component. The path-scoped rules exist to catch that.

## Known fixes it ships

- [Designing an audit log for an admin panel](https://agenticboilerplate.com/cookbook/admin-panel/adding-an-audit-log): One append-only table, namespaced past-tense actions, emails copied in, and a clear rule for when the audit row can share a transaction with the change and when it cannot.
- [Bans that actually sign people out](https://agenticboilerplate.com/cookbook/admin-panel/bans-and-session-revocation): Setting banned = true stops the next sign-in, not the session already open. What Better Auth, Clerk and Supabase do on a ban, where caches and tokens let a banned user linger, and how to say so.
- [Empty states that are not sad](https://agenticboilerplate.com/cookbook/admin-panel/empty-states-that-are-not-sad): An empty state that only says "No data available" is a dead end. It should say what belongs here, why it is missing, and what to do next.
- [Making the first admin without a back door](https://agenticboilerplate.com/cookbook/admin-panel/first-admin-without-a-backdoor): A fresh deploy has no admin, and the admin page needs one to add one. Use a terminal script with database or API credentials, never an env list of emails or a first-user-wins rule.
- [impersonating-users-safely](https://agenticboilerplate.com/cookbook/admin-panel/impersonating-users-safely): 
- [Paginating admin tables without a client library](https://agenticboilerplate.com/cookbook/admin-panel/paginating-a-users-table): Offset pages with a total for the users table, keyset cursors for the audit log, both in the URL and rendered on the server. When to use which, and the details that make each correct.
- [Role checks that survive a layout refactor](https://agenticboilerplate.com/cookbook/admin-panel/role-checks-that-survive-a-refactor): A check that lives only in a layout disappears the day someone moves the page. Put the boundary where the route is, and check again where the work happens.
- [Route group or path segment: how to lay out an admin section](https://agenticboilerplate.com/cookbook/admin-panel/route-group-vs-path-segment): A route group shares a layout without touching the URL; a path segment is the URL. Admin panels need both, and confusing them produces public pages and 404s.

## Generate it

[Build a repo with Admin panel](https://agenticboilerplate.com/build?b=admin-panel)

---

Agentic Boilerplate: A Next.js repo your agent already knows. Free during launch, then $99 once.

- Site map for agents: https://agenticboilerplate.com/llms.txt
- Public API: https://agenticboilerplate.com/openapi.json
- Contact: agenticstudio@gmail.com
