# CMSaasStarter: a SvelteKit SaaS template with Supabase and Stripe already wired

> An MIT licensed boilerplate that ships authentication, subscriptions, a blog engine and a billing portal so a founder can skip the boring half of a launch.

**scosman/CMSaasStarter** — A modern SaaS template/boilerplate built with SvelteKit, Tailwind, and Supabase. Includes marketing page, blog, subscriptions, auth, user dashboard, user settings, pricing page, and more.

- Repository: https://github.com/scosman/CMSaasStarter
- Website: https://saasstarter.work
- Stars: 2,369 · Forks: 473
- Language: Svelte
- License: MIT
- Published: 2026-10-07 · Updated: 2026-10-07 · Language: en
- Canonical page: https://hysenlabs.com/projects/scosman-cmsaasstarter

## A bill of sale for the boring half of a SaaS launch

The feature list reads like a checklist for the first three months of a subscription product, and that is the clearest way to understand the template. Authentication covers sign up, sign out, forgot password, email verification and oAuth, powered by Supabase Auth, and it includes a GDPR cookie warning for European users. Payments are Stripe Checkout for subscriptions plus the Stripe customer portal for self service card changes, upgrades, cancellation and receipt downloads.

Around that core sit the pieces that are genuinely tedious to build twice. There is a marketing page with SEO optimization and a sitemap, a blog engine with rich formatting, RSS and SEO optimization, a pricing page, a contact form, and a site search that the README describes as running without a backend. There is a user dashboard with profile, settings, and email and password updates, and an onboarding flow that runs after signup to collect user data and pick a payment plan.

Email is treated as a first class feature rather than an afterthought, with template support and a separate administration address for internal messages. A theme and UI component toolkit is included, and the last feature on the list is extensibility: additional marketing pages, admin portals, database backends and API endpoints. The live demo at saasstarter.work is described as fully functional, which means you can click through the whole flow before cloning anything.

## Svelte 5 and Tailwind 4 in the dependency list

The technology choices are specific enough to date the template. The package manifest pins Svelte at ^5.0.0, Vite at ^6.3.5, Tailwind CSS at ^4.0.9 with the PostCSS plugin, and DaisyUI at ^5.0.0, all under SvelteKit ^2.21.1. Those are current major versions rather than the long tail of the framework, which matters because boilerplates usually accumulate stale major versions and force you into a migration before you write anything.

Supabase appears four ways in the dependency list, split between the Svelte UI components, the SSR helper, the auth UI shared package and the JavaScript client. Stripe is deliberately absent from the dependencies. Billing runs through Checkout and the portal rather than a Stripe SDK, so the template never handles card data itself and there is no payment code to audit on the server.

Two smaller dependencies are worth calling out because they explain specific features. `fuse.js` is the client side search library behind the backend free site search, and `handlebars` is there for email templates. `super-sitemap` generates the sitemap for the marketing and blog pages. A `patch-package` postinstall script runs on every install, and the repository has a `patches/` directory to match, so the project does carry patched dependencies and you should look at what they change before you treat the install as unmodified.

## The environment file is the entire integration surface

For a project with this many third party services, the contract for wiring them up is refreshingly small. The `.env.example` file in the repository root lists three required values, all with a placeholder you are expected to replace:

```bash
PUBLIC_SUPABASE_URL='https://REPLACE_ME.supabase.co'
PUBLIC_SUPABASE_ANON_KEY='REPLACE_ME'
PRIVATE_SUPABASE_SERVICE_ROLE='REPLACE_ME'

# Stripe settings
PRIVATE_STRIPE_API_KEY='REPLACE_ME'
```

The naming convention does real work here. Values prefixed with `PUBLIC_` are shipped to the browser, which is correct for the Supabase URL and anonymous key because the anon key is designed to be public and protected by row level security instead. The service role key carries a `PRIVATE_` prefix, and it must stay on the server, since that key bypasses row level security entirely.

The rest of the file is optional and commented out: an administration address for internal messages, a from address for outbound mail, and a Resend API key. Email through Resend is therefore a feature you switch on rather than one you have to configure to get a working app, which is a reasonable default when a template's primary job is to be runnable.

## Cloudflare and Supabase, with the free tier limits stated outright

The README does something few templates bother with: it names a price for its own recommended hosting stack and states the cons. The suggested stack is Cloudflare Pages for the host and CDN, Cloudflare Workers for serverless compute, Supabase Auth for authentication and Supabase Postgres for the database. The template itself costs nothing to use.

The zero cost tier is described as Supabase free plus Cloudflare free, and the listed benefits are unlimited static page requests, 100k serverless function calls a day, and a claim that it scales to thousands of users. The cons are the interesting part. The free tier does not include database backups, the README suggests hooking up `pgdump` backups on a Lambda and S3 for a few cents a month if that matters to you, and Supabase will auto pause your database after seven days of inactivity.

That pause behavior is the single most likely first surprise for someone who follows the free tier advice. The $30 per month tier, Supabase Pro plus paid Cloudflare Workers, exists precisely to remove both problems: real backups and no auto pause. The README's guidance is to move up once you have paying customers or investors, which is an honest framing of a template as a pre revenue accelerator rather than a production platform.

## Pre-rendering for the pages that do not need a server

The performance section commits to pre rendering, meaning static generation, for marketing pages, pricing and blog content. Those are the routes where every visitor sees the same bytes, so generating them at build time is the obvious win and is the reason a marketing site backed by a template like this can be fast without a cache layer.

The second claim is about navigation. The README describes instant navigation as the best of client side and server side rendering combined, where the first page is server rendered for the fastest possible initial load and subsequent navigations are handled on the client. That is SvelteKit's default model, so this is less a feature the template adds than a property of the framework it is built on. It is still worth knowing, because it is the thing that decides how the app feels once a user starts clicking through the dashboard.

Database work is not entirely in the static path. The repository ships `database_migration.sql` at the root, which is where the Supabase schema and any row level security policies are meant to live, so the database layer is versioned as a file rather than applied by clicking through the Supabase dashboard. There are also `analytics_docs.md` and `email_docs.md` at the root, which suggests analytics and mail setup are documented separately from the main README rather than being automatic.

## Linting, testing and the repository that moved

The toolchain is more complete than most boilerplates. The package scripts include `dev`, `build` and `preview` from Vite, `lint` wired to ESLint, `format` and `format_check` wired to Prettier with the Svelte plugin, and a `check` script that runs `svelte-kit sync` followed by `svelte-check` against the tsconfig. Tests run through Vitest, with a separate `test_run` script for a single non watching pass, and CI is configured with three workflows for build, format checking and linting, each badged at the top of the README.

One thing to know before you clone: the repository is now `scosman/CMSaasStarter`, but every link inside the README still points at `CriticalMoments/CMSaasStarter`, including the badge links, the demo link and the issue link. GitHub redirects the old path, so the links work, and the credentials imply the project moved out of the Critical Moments organisation and into a personal account. The README also credits Kiln AI as the origin: the fine tuning and dataset tool at getkiln.ai was built with this template, and Critical Moments runs a similar commercial site on a fork of it.

So the practical read is that this is a template with two real downstream users, which is a better signal of fitness than star count alone. It has 2,366 stars and 471 forks, is not archived, and was last pushed on 2026-03-21, so it sits inside the 183 day window from October 2026 and the dependency versions confirm the maintenance is current.

## Conclusion

CMSaasStarter is best understood as an opinionated starting point rather than a framework. The parts it saves you are the tedious ones: auth flows, a Stripe checkout and portal pair, a marketing page with a sitemap, a blog engine with RSS, and an onboarding sequence. The parts you still own are the product. Read the feature list as a bill of sale, confirm your database migrations live in database_migration.sql, and spend your time on the screens the template cannot guess for you. Fork it, run the dev server, and delete what you do not need before you write a line of feature code.

## FAQ

### What is CMSaasStarter and what stack does it use?

CMSaasStarter is an MIT licensed SaaS boilerplate built with SvelteKit, Tailwind CSS and DaisyUI, backed by Supabase for auth and Postgres and Stripe for subscriptions. It ships a marketing page, blog, dashboard, pricing page, onboarding flow and billing portal.

### Do I need a paid Supabase or Cloudflare plan to use it?

No. The template itself is free, and the README describes a working zero cost tier using the Supabase and Cloudflare free plans, listing unlimited static requests and 100k serverless function calls a day. That tier has no database backups and Supabase auto pauses an inactive database after seven days, which the $30 per month tier removes.

### Where do I put the database schema and Supabase keys?

Schema goes in `database_migration.sql` at the repository root so it is versioned as a file. Keys go in an environment file based on `.env.example`: the Supabase URL and anon key use the `PUBLIC_` prefix, while the service role key and the Stripe API key use `PRIVATE_` and must stay on the server.

### Can I see the finished product before cloning it?

Yes. The README points to a fully functional demo at saasstarter.work covering the homepage, pricing, settings and payments portal screens. Two production sites built from forks are also referenced: criticalmoments.io and getkiln.ai, the Kiln AI dataset tool.

## Sources

- [Issues](https://github.com/scosman/CMSaasStarter/issues)
- [License: MIT](https://github.com/scosman/CMSaasStarter/blob/main/LICENSE)
- [Project website](https://saasstarter.work)
- [README](https://github.com/scosman/CMSaasStarter/blob/main/README.md)
- [scosman/CMSaasStarter on GitHub](https://github.com/scosman/CMSaasStarter)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/scosman-cmsaasstarter
