SvelteKit starters maintained for teams shipping multi-tenant B2B.
Organizations, roles, invites, seat billing and an append-only audit log — verified absent from every free alternative we checked, at the schema level. Three databases to pick from: Cloudflare D1/SQLite, Supabase, or any Postgres. Each kit ships an AGENTS.md and a generated TypeDoc API reference, so Claude Code, Cursor and Copilot start from the real architecture.
Maintained is the claim we can defend: a public changelog, and a release gate that unzips the shipped artifact into an empty directory and installs it with no cache before anything is published. If a buyer can't install it, it doesn't ship.
What you can check before you buy
Three demos run on real infrastructure against a real database, reset daily. The clip below is the Postgres demo refusing a member a request its role does not allow — the same code path a paying customer runs.
RBAC denial, captured from the live Postgres demo — click to open the running app.
The organization screen, running on Postgres with the role and seat model wired.- 1072 automated tests across the three kits (357 + 390 + 325), each at or above 95% coverage.
- Docs, API reference and architecture notes are public in the GitHub repos — source code is not.
- A dated changelog — 39 releases, parsed from the kits' own release files, not typed by hand.
- 30-day refund, no questions asked.
Included for AI coding agents
Every starter ships an AGENTS.md describing its own architecture, commands, and conventions, plus a TypeDoc API reference generated from the source, so tools like Claude Code, Cursor, and Copilot work from the real surface instead of guessing. These files are here because they cost nothing to include and make the kit more usable — not because they are unusual. Svelte's own CLI (npx sv add ai-tools) scaffolds a framework-level AGENTS.md into any SvelteKit project; ours is the product-specific layer on top of that.
Ships in every kit — architecture, commands, and conventions for that codebase
Generated, compiler-verified — never drifts from the code
Site-level index — every guide, comparison, and doc URL, machine-readable
How orgs → members → invites → RBAC → billing → audit fit together, and which layer owns what
What's shipped
The same core, on real Postgres with Drizzle ORM — connection pooling, opt-in RLS, and zero provider lock-in. The vendor-neutral default if you run Postgres anywhere.
v0.1.13 — 325 automated tests against a real Postgres test database.
Same multi-tenancy, RBAC, billing, and audit log — running on Supabase for auth, database, and realtime. Pick this if you are already on Supabase.
v0.3.4 — 390 automated tests, production-ready with RLS, RBAC, invites, billing.
The zero-ops flagship on Cloudflare Pages + SQLite/D1 — orgs, invites, roles, seat billing, done and tested.
v0.2.14 — 357 automated tests, each shipped kit installed from clean and its suite run before release.
Documentation & guides
Why buy when AI can generate?
An agent will happily write your tenant-isolation policy, your seat gate, and your audit writer in an afternoon. What it cannot tell you is whether they are right — whether a policy that reads tight still leaks a row across tenants, whether a retried billing webhook charges a seat twice, whether anyone can mutate the audit trail. Those are the parts that are slow to review and expensive to be wrong about, and the failure is yours, not the model's. These kits ship that layer already wired and covered, so the thing you build on is the risky part instead of a fresh copy of it.
If wiring it up yourself would take you a few weeks — your own estimate, not ours — it pays for itself before you write a line of your own product.
Why not a free starter?
Free starters are good, and one of them is probably the first thing you found. The difference shows up after you build on it: dependencies get CVEs, framework majors land, and a kit that stopped shipping is a kit you maintain yourself. These kits have shipped39 dated releasessince 26 August 2026 — a count parsed from the kits' own release files at build time, with every release listed where you can read it. Lifetime updates and support are included with a purchase; the changelog is how you hold that promise to account, and it exists for exactly that reason.
The free alternative most people compare against,CMSaasStarter, has no tagged release, and at the last check behind this page (2026-10-02) its most recent commit was dated 21 March 2026. Check the link rather than trusting the sentence — if it has shipped since, this paragraph is wrong and the link is how you would know.
Status, stated plainly
No countdowns, no pre-orders, no invented traction. Every product above is shipped, live with a working demo and instant download after purchase. If a problem above is yours, buy the product directly or reach out with questions — we aim to respond within 48 hours.
Get in touch
Questions about the product, team licenses, or anything else? We'll aim to respond within 48 hours.