# VerdantStack > Three SvelteKit starters for B2B SaaS over one shared service layer: organizations → members → invites → role-based access → seat billing → append-only audit log. Choose your database — Cloudflare D1/SQLite, Supabase, or any Postgres. Every kit ships 325–390 automated tests, a clickable live demo, an AGENTS.md, and a generated TypeDoc API reference. One-time pricing, 30-day refund. ## Products One-time license (single seat, unlimited projects, lifetime updates + support). Each kit is a **paid, source-available product**: buy on the product page and it is delivered privately to buyers (no public npm/registry). Every kit ships with AGENTS.md and a generated TypeDoc API reference. - [VerdantStack](https://verdantstack.dev/) — Home: developer starters for the parts of software products nobody demos — multi-tenancy, seat billing, role-based access, audit logging - [All products](https://verdantstack.dev/products/) — index of every VerdantStack starter; one-time prices, single-seat license, lifetime updates + support - [Changelog](https://verdantstack.dev/changelog/) — every dated release across all three kits, parsed from the repo's CHANGELOG files at build time; 36 releases and 153 individual changes between 2026-08-26 and 2026-10-04 - [Multi-tenant SvelteKit Starter](https://verdantstack.dev/products/multi-tenant-sveltekit-starter/) — **$79 one-time**. A production-shaped B2B SaaS foundation with multi-tenancy wired end-to-end. Organizations, invitations, role-based access, seat-based billing via a merchant of record, and an append-only audit log. SQLite + Drizzle ORM. - [SvelteKit + Supabase Starter](https://verdantstack.dev/products/sveltekit-supabase-starter/) — **$99 one-time**. Same multi-tenancy, RBAC, billing, and audit log — running on Supabase for auth, database, and realtime. PostgreSQL via Supabase with RLS defense-in-depth. - [SvelteKit + Postgres Starter](https://verdantstack.dev/products/sveltekit-postgres-starter/) — **$79 one-time**. Same multi-tenancy, RBAC, billing, and audit log — on real Postgres with Drizzle ORM + postgres.js, opt-in Row-Level Security, connection pooling, and no provider lock-in. 325 automated tests against a real Postgres test database. ## Live Demos All three products have a free, clickable, live demo (demo credentials are shown on the landing page): - [Multi-tenant SvelteKit Starter — live demo](https://multi-tenant-starter.verdantstack-site.pages.dev/) — the real kit running on Cloudflare Pages + D1, seeded with Northwind Labs (owner dana@northwind.example / Dana-demo-2026, member riley@northwind.example / Riley-demo-2026), reset daily - [SvelteKit + Supabase Starter — live demo](https://supabase-starter.verdantstack-site.pages.dev/) — the real kit running on Cloudflare Pages + Supabase Postgres with RLS, seeded the same way, reset daily - [SvelteKit + Postgres Starter — live demo](https://postgres-starter.verdantstack-site.pages.dev/) — the real kit running on Cloudflare Pages + any-Postgres (postgres.js + Drizzle), seeded the same way, reset daily ## Comparisons & Guides - [Documentation index](https://verdantstack.dev/docs/) — all guides, comparisons, and resources - [How to Use Claude Code with VerdantStack](https://verdantstack.dev/docs/claude-code-with-verdantstack/) — Build SaaS features faster with Claude Code. AGENTS.md and machine-readable docs make your agent productive from the first prompt. - [Connect an AI Agent to Your SaaS Data with MCP](https://verdantstack.dev/docs/mcp-server-for-ai-agents/) — Every kit ships a read-only MCP server over its own service layer. Point any MCP host at it and the agent can read orgs, members, invites and the audit log. - [How to Use Cursor with VerdantStack](https://verdantstack.dev/docs/cursor-with-verdantstack/) — Integrate Cursor AI with VerdantStack starters. AGENTS.md and machine-readable docs make Cursor productive from the first edit. - [How to Build SaaS Features with AI Coding Agents](https://verdantstack.dev/docs/build-with-ai-agents/) — A complete guide to AI-assisted SaaS development: principles, workflow, and tool-specific guides. - [SvelteKit vs Next.js for SaaS](https://verdantstack.dev/comparison/sveltekit-vs-nextjs-saas/) — Honest comparison of features, pricing, performance, and developer experience - [Multi-Tenant Starter Checklist](https://verdantstack.dev/comparison/multi-tenant-starter-checklist/) — The 5 essential features every multi-tenant starter kit must have - [VerdantStack vs CMSaasStarter](https://verdantstack.dev/comparison/sveltekit-starter-vs-cmsaasstarter/) — Feature-by-feature comparison with the free open-source Supabase starter - [SvelteKit + Postgres vs Supabase](https://verdantstack.dev/comparison/sveltekit-postgres-vs-supabase/) — Provider-neutral Postgres with Drizzle vs managed Supabase — auth, RLS, pooling, realtime, and lock-in - [SvelteKit + Postgres vs Next.js + Prisma](https://verdantstack.dev/comparison/sveltekit-postgres-vs-nextjs-prisma/) — Building a multi-tenant SaaS: framework ergonomics, Drizzle vs Prisma, Postgres hosting - [Drizzle ORM vs Prisma for SvelteKit](https://verdantstack.dev/comparison/drizzle-orm-vs-prisma-sveltekit/) — SQL-first Drizzle vs Prisma's schema DSL for a SvelteKit SaaS - [Supabase vs Drizzle](https://verdantstack.dev/comparison/supabase-vs-drizzle/) — why these are not competitors: Supabase is a managed Postgres platform, Drizzle is a TypeScript ORM that connects to any Postgres, including Supabase's - [SQLite vs Postgres for a Multi-tenant SaaS](https://verdantstack.dev/comparison/sqlite-vs-postgres-multi-tenant-saas/) — Concurrency, connections, migrations, and the replica threshold where you should switch - [The B2B SaaS data model: organizations, memberships, invites, and roles](https://verdantstack.dev/saas/b2b-organizations-memberships-data-model/) — One user, many companies. Why the role belongs to the membership, not the user - [Multi-tenancy across stacks: how each framework isolates a tenant](https://verdantstack.dev/saas/multi-tenancy-across-stacks/) — Where Django, Rails, Laravel, Next.js, NestJS, Go and Phoenix enforce isolation, and why only one mechanism makes a missed filter impossible - [Best SvelteKit SaaS Starters 2026](https://verdantstack.dev/bestof/sveltekit-saas-starters-2026/) — Compare the top SvelteKit starter kits for multi-tenant B2B SaaS - [How to Build Multi-Tenant SaaS](https://verdantstack.dev/docs/how-to-build-multi-tenant-saas-sveltekit/) — Step-by-step guide to building a production-ready multi-tenant SaaS with SvelteKit - [SvelteKit SaaS Boilerplate](https://verdantstack.dev/docs/sveltekit-saas-boilerplate/) — What you actually need in a SaaS boilerplate (and what free starters skip) - [Multi-Tenant SvelteKit Template](https://verdantstack.dev/docs/multi-tenant-sveltekit-template/) — How to implement organizations, RBAC, seat billing, and audit logging - [Make Your Codebase AI-Agent-Friendly](https://verdantstack.dev/docs/make-codebase-ai-agent-friendly/) — AGENTS.md, llms.txt, and API references — the context files AI coding agents need to work productively in your code ## Documentation - [Multi-tenancy in SvelteKit](https://verdantstack.dev/products/multi-tenant-sveltekit-starter/docs/sveltekit-multi-tenant-auth/) — Multi-tenant auth, session management, and database design decisions for SvelteKit - [RBAC model](https://verdantstack.dev/products/multi-tenant-sveltekit-starter/docs/sveltekit-rbac-role-hierarchy/) — Role-based access control: three roles with strict hierarchy enforced server-side - [Invite link flow](https://verdantstack.dev/products/multi-tenant-sveltekit-starter/docs/sveltekit-invite-link-flow/) — Single-use hashed invite tokens with expiry and atomic claim - [Seat billing adapter pattern](https://verdantstack.dev/products/multi-tenant-sveltekit-starter/docs/seat-billing-adapter-pattern/) — Pluggable BillingAdapter interface for merchant-of-record checkout - [Append-only audit log](https://verdantstack.dev/products/multi-tenant-sveltekit-starter/docs/append-only-audit-log-design/) — Audit trail design: append-only by construction, no update/delete path - [Hashed session auth](https://verdantstack.dev/products/multi-tenant-sveltekit-starter/docs/sveltekit-hashed-session-auth/) — Database-backed sessions with hashed tokens for revocation - [Rate limiting login](https://verdantstack.dev/products/multi-tenant-sveltekit-starter/docs/sveltekit-rate-limiting-login/) — Sliding-window failed-attempt rate limiter with pre-hash blocking - [SaaS starter evaluation checklist](https://verdantstack.dev/products/multi-tenant-sveltekit-starter/docs/saas-starter-evaluation-checklist/) — Six-dimension evaluation framework for choosing a SaaS starter - [Sell software without Stripe](https://verdantstack.dev/products/multi-tenant-sveltekit-starter/docs/sell-software-without-stripe-access/) — Merchant-of-record options for developers in countries where Stripe isn't available - [Starter checklist](https://verdantstack.dev/products/multi-tenant-sveltekit-starter/docs/multi-tenant-starter-checklist/) — Production readiness checklist for multi-tenant SaaS starters - [Drizzle ORM migrations](https://verdantstack.dev/products/multi-tenant-sveltekit-starter/docs/drizzle-orm-migrations-sveltekit/) — Schema-first database management with Drizzle Kit in SvelteKit - [Multi-tenant database design](https://verdantstack.dev/products/multi-tenant-sveltekit-starter/docs/multi-tenant-database-design/) — Shared-database tenant isolation patterns with org-scoped queries - [Session management](https://verdantstack.dev/products/multi-tenant-sveltekit-starter/docs/sveltekit-session-management/) — Server-side sessions with hashed tokens, httpOnly cookies, and DB-backed revocation - [Hooks & middleware](https://verdantstack.dev/products/multi-tenant-sveltekit-starter/docs/sveltekit-hooks-middleware/) — Server-side request handling with hooks.server.ts - [Testing with Vitest](https://verdantstack.dev/products/multi-tenant-sveltekit-starter/docs/sveltekit-testing-vitest/) — Unit tests, integration tests, and HTTP-level patterns from a 357-test suite - [SQLite for production SaaS](https://verdantstack.dev/products/multi-tenant-sveltekit-starter/docs/sqlite-production-saas/) — WAL mode, tenant isolation, connection handling, and ceiling awareness - [Environment variables](https://verdantstack.dev/products/multi-tenant-sveltekit-starter/docs/sveltekit-environment-variables/) — Public vs private, static vs dynamic, .env files, Cloudflare Workers secrets - [CSRF protection](https://verdantstack.dev/products/multi-tenant-sveltekit-starter/docs/sveltekit-csrf-protection/) — What SameSite=Lax stops, the two holes it leaves, and the tests that pin it - [Error handling](https://verdantstack.dev/products/multi-tenant-sveltekit-starter/docs/sveltekit-error-handling/) — fail(), error(), redirect(), and typed error patterns for form actions ## SvelteKit + Supabase Starter — Documentation - [Architecture](https://verdantstack.dev/products/sveltekit-supabase-starter/docs/architecture/) — thin routes → framework-free services → rbac/billing seams → supabase/client.ts; RLS defense-in-depth (service-only foundation — you wire the route layer) - [RBAC & RLS](https://verdantstack.dev/products/sveltekit-supabase-starter/docs/rbac/) — three roles enforced server-side at the app layer and again via Supabase Row Level Security - [Seat billing](https://verdantstack.dev/products/sveltekit-supabase-starter/docs/billing/) — pluggable BillingAdapter for merchant-of-record checkout, enforced at invite acceptance - [Testing](https://verdantstack.dev/products/sveltekit-supabase-starter/docs/testing/) — 16 Vitest suites (390 tests) against an in-memory fake Supabase client; RLS checks via supabase start - [Versioning](https://verdantstack.dev/products/sveltekit-supabase-starter/docs/versioning/) — semantic versioning, Keep a Changelog, and the release process ## SvelteKit + Postgres Starter — Documentation - [Multi-tenant DB design](https://verdantstack.dev/products/sveltekit-postgres-starter/docs/postgres-multi-tenant-drizzle-design/) — shared-database tenancy on Postgres with Drizzle ORM: org_id scoping, uuid PKs, bigint-ms timestamps - [RLS defense-in-depth](https://verdantstack.dev/products/sveltekit-postgres-starter/docs/row-level-security-sveltekit-postgres/) — opt-in Row-Level Security: fail-closed, app.current_user_id GUC, per-table policies - [Connection pooling](https://verdantstack.dev/products/sveltekit-postgres-starter/docs/sveltekit-postgres-connection-pooling/) — postgres.js pool sizing, PgBouncer/Supavisor, and Neon pooled connections - [Drizzle migrations](https://verdantstack.dev/products/sveltekit-postgres-starter/docs/drizzle-postgres-migrations-sveltekit/) — schema-first Postgres migrations with drizzle-kit, applied at boot - [Read replicas](https://verdantstack.dev/products/sveltekit-postgres-starter/docs/postgres-read-replica-routing-sveltekit/) — write/read splitting with Drizzle, lag-tolerant reads - [Full-text search](https://verdantstack.dev/products/sveltekit-postgres-starter/docs/postgres-full-text-search-sveltekit/) — native Postgres tsvector + GIN over the audit log - [JSONB metadata](https://verdantstack.dev/products/sveltekit-postgres-starter/docs/jsonb-metadata-saas-audit-logs/) — flexible audit-log metadata and the jsonb upgrade path - [Session management](https://verdantstack.dev/products/sveltekit-postgres-starter/docs/postgres-session-management-sveltekit/) — hashed, DB-backed, revocable sessions with 30-day expiry ## Source Code The kit source is the **paid product** and ships **privately to buyers** — the public GitHub repos are proof-only (docs, features, screenshots). See the product pages to buy. - [Multi-tenant SvelteKit Starter (proof repo)](https://github.com/verdantstack/multi-tenant-sveltekit-starter) — docs & features, plus the generated API reference at `docs/api`; **buy the kit →** on the product page - [SvelteKit + Supabase Starter (proof repo)](https://github.com/verdantstack/sveltekit-supabase-starter) — docs & features, plus the generated API reference at `docs/api`; **buy the kit →** on the product page - [SvelteKit + Postgres Starter (proof repo)](https://github.com/verdantstack/sveltekit-postgres-starter) — docs & features, plus the generated API reference at `docs/api`; **buy the kit →** on the product page ## API Reference (TypeDoc) The generated TypeDoc reference for each kit is public in its proof repo under `docs/api` — a browsable, machine-readable index of the public exports (auth, billing, db, http, ratelimit, rbac, services, ...). This is the surface AI coding agents read. - [Multi-tenant SvelteKit Starter — TypeDoc index](https://github.com/verdantstack/multi-tenant-sveltekit-starter/tree/main/docs/api) — API reference (TypeDoc) for the multi-tenancy, RBAC, seat-billing, and audit-log core - [SvelteKit + Supabase Starter — TypeDoc index](https://github.com/verdantstack/sveltekit-supabase-starter/tree/main/docs/api) — API reference (TypeDoc) for the Supabase-backed kit - [SvelteKit + Postgres Starter — TypeDoc index](https://github.com/verdantstack/sveltekit-postgres-starter/tree/main/docs/api) — API reference (TypeDoc) for the Postgres-backed kit - [License Agreement](https://verdantstack.dev/docs/license/) — single-seat license, unlimited projects, lifetime updates + lifetime standard support, 30-day refund - License: source-available to buyers (EULA); not open source ## Services - [Deployment service](https://verdantstack.dev/services/) — fixed-price, fixed-scope deployment for SvelteKit SaaS starters: T1 $149 reference deploy, T2 $299 alternate platform, T3 $499 deploy and harden. Written only, no calls, client holds every account, 5-day acceptance window, 14 days written support after acceptance. No client count is claimed because none exists. ## Contact - [Contact form](https://verdantstack.dev/contact/) — name, email, subject, message; stored in our own database, no third party - [Privacy](https://verdantstack.dev/privacy/) — no cookies, no third-party requests, no persistent identifier; click events counted first-party with a daily-rotating salted IP hash, never the IP itself - Async support only: docs first, then verdantstack@proton.me - Response target: 48 hours