# Next.js boilerplate with AI bundle

> The Vercel AI SDK on Anthropic or OpenAI, split into three sub-options you toggle independently. The provider choice picks the SDK package, the API key and the model catalogue. Each sub-option adds its own files, rules, skills and docs, and nothing in one sub-option imports another.
Always generated: src/lib/ai/models.ts is the model allowlist for the chosen provider, and the only place a model id is named. src/lib/ai/provider.ts is its server-only façade. src/lib/ai/prompt.ts assembles the instructions, and src/lib/ai/untrusted.ts wraps untrusted content. src/lib/ai/messages.ts is the validated wire format and src/lib/ai/http.ts the shared error responses. src/lib/ai/access.ts decides who may call the AI routes: signed-in users when the repo has an auth battery, anyone when it does not. src/lib/ai/eval.ts, src/lib/ai/evals/** and scripts/ai-eval.ts are the prompt regression harness. scripts/ai-models.ts lists the models the app may call. Unit tests in tests/unit/ai-*.test.ts run on a mock model, so they need no key and cost nothing.
Chat adds src/app/api/chat/route.ts, the /chat page and src/components/ai/chat.tsx (built on the component kit). With an auth battery the page lives in the signed-in app (src/app/(app)/chat/page.tsx, a Chat entry in the app sidebar and a card on the dashboard); without one it is a public page (src/app/chat/page.tsx) linked from the site header. Structured output adds src/lib/ai/structured.ts, src/lib/ai/schemas.ts and the ai-structured-output rule. Tool calling adds src/lib/ai/tools/**, src/lib/ai/knowledge-base.ts, src/lib/ai/agent.ts, src/app/api/agent/route.ts, the ai-tools rule and the add-tool skill. When a streaming route ships, vercel.json turns on request cancellation for it, so Stop really stops the upstream call on Vercel.

Streaming chat, Zod-checked output and tool calling on the Vercel AI SDK.

- **Category:** AI
- **Pricing:** The AI SDK is free and open source (Apache 2.0). You pay the model provider per token. The defaults, Claude Sonnet 5 and GPT-6 Sol, both list at $2 per million input tokens and $10 per million output tokens. Claude Haiku 4.5 and GPT-6 Luna cost less. Claude Opus 5.5, Claude Fable 5.1 and GPT-6 Astra cost 2 to 5 times the default. Prompt caching and batch requests cut the bill, but you turn them on yourself.
- **Best for:** Any feature where the model reads something and writes something back: support triage, drafting, document extraction, a help assistant over your own content. Strongest when you want one provider abstraction now and the option to switch models later without touching call sites.
- **Vendor docs:** https://ai-sdk.dev/docs/introduction

## Trade-offs

- Unmetered on purpose. No usage counting, no per-user rate limit and no spend cap are generated. With an auth battery the AI routes need a session, which gives every request an owner but does not cap spend. Without one they are open to anyone. Read the cookbook doc "When to add usage metering" before you ship either.
- No background jobs. Everything runs inside the request, bounded by maxDuration. Long work (batch extraction, long documents) needs a queue this bundle does not generate.
- No tracing. AI SDK 7 emits telemetry once you register an integration (OpenTelemetry through @ai-sdk/otel), and the providers return request ids. An LLM observability tool is a recurring bill, so it is documented, not installed.
- One provider per repo. You pick Anthropic or OpenAI when you generate, and only that SDK and key ship. Adding the other later is one package and a few lines in src/lib/ai/models.ts. Streaming, tool calling and structured output port across both. Extended thinking, prompt caching and provider-specific tools do not.
- Tool calling is only as safe as the tools. The scaffold ships one read-only example and a per-surface registry. The first tool that writes to your database is where prompt injection gets real.

## Known fixes it ships

- [Prompt injection through user content: why delimiters are not the fix](https://agenticboilerplate.com/cookbook/ai-bundle/prompt-injection-through-user-content): Any text a user can influence can carry instructions. Wrapping helps a little; least-privilege tools, human confirmation and never trusting output as authorisation are what actually hold.
- [Streaming edge cases: aborts, disconnects, backpressure and errors after the first token](https://agenticboilerplate.com/cookbook/ai-bundle/streaming-edge-cases): A streamed response that fails halfway does not reject anything, and a user who closes the tab keeps billing you. The four cases every streaming route has to handle.
- [Tool retries and partial failures: what the AI SDK retries and what it does not](https://agenticboilerplate.com/cookbook/ai-bundle/tool-retries-and-partial-failures): The SDK retries the request to the model, never your tool's side effects. A tool that half-succeeded and then got called again is where duplicate charges come from.
- [When to add usage metering to an AI feature, and how to do it in an afternoon](https://agenticboilerplate.com/cookbook/ai-bundle/when-to-add-usage-metering): A public AI route is a public spend endpoint. The three signals that say you need metering now, and the smallest implementation that actually protects you.
- [When AI work has to move to a background job, and what breaks if you wait](https://agenticboilerplate.com/cookbook/ai-bundle/when-to-move-ai-work-to-a-background-job): Serverless functions have a hard timeout that no amount of streaming avoids. The four signals that mean the work no longer belongs in the request, and the smallest queue that fixes it.
- [When LLM tracing pays for itself, and the free version to build first](https://agenticboilerplate.com/cookbook/ai-bundle/when-tracing-pays-for-itself): A user reports an answer you cannot reproduce. Without the exact prompt, the tool steps and the model version, you are guessing. But a paid tracing tool is not the first thing to reach for.

## Generate it

[Build a repo with AI bundle](https://agenticboilerplate.com/build?b=ai-bundle)

---

Agentic Boilerplate: A Next.js repo your agent already knows. Free during launch, then $99 once.

- Site map for agents: https://agenticboilerplate.com/llms.txt
- Public API: https://agenticboilerplate.com/openapi.json
- Contact: agenticstudio@gmail.com
