Guides / 2026-09-24
The best SaaS boilerplates for AI coding agents in 2026 (Claude Code, Cursor, Codex)
Twelve SaaS starters compared on what they actually give a coding agent: AGENTS.md and CLAUDE.md, skills, MCP servers, llms.txt, and whether anything checks that the agent kept to the rules. Prices and sources as of September 2026.

The short answer: if an agent will write most of your SaaS, the kits with
the deepest agent tooling today are MakerKit (paid; skills, MCP server,
per-package AGENTS.md), Open SaaS (free; skills, a Claude Code plugin,
llms-full.txt) and supastarter (paid; AGENTS.md, Agent Skills,
Markdown docs). ShipKit, which we make, is the one built around a
different idea: the rules an agent must follow are enforced by tests and CI,
so a broken convention fails the build instead of waiting for review.
Almost every boilerplate now says "AI-ready". That phrase covers anything from
a single .cursorrules file to a full MCP server. This page sorts them by
what is really in the repository.
A disclosure first: we make ShipKit, one of the kits below. Every fact about the other kits comes from their own website, docs or repository, checked on 24 September 2026. Where a page didn't say something, we wrote "not stated" rather than guess. Prices change often, so check before you buy.
What "agent-ready" should mean
Three findings are worth knowing before you compare kits:
- Written context alone doesn't make an agent more correct. An ETH Zurich study (Gloaguen et al., 2026) found that repository context files "do not generally improve task success rates" and raise inference cost by over 20% on average. It also found that the instructions in them "are well followed".
- It does make the agent faster. Across 10 repositories and 124 pull
requests, an
AGENTS.mdcut median runtime by 28.64% and output tokens by 16.58%, with comparable task completion (Lulla et al., 2026). - The vendors say the same. Anthropic's own guidance calls
CLAUDE.md"advisory" and says hooks and checks are what "guarantee the action happens". Its first recommendation is to give the agent "a check it can run: tests, a build" (Claude Code best practices).
So look for three layers, in order of how much they are worth:
- Checks the agent can run that fail when it breaks the architecture. Typecheck and lint catch syntax and style, not "this admin endpoint has no permission check".
- Procedures for the risky, multi-step jobs (payments, OAuth, deploy), written as skills or commands the agent follows step by step.
- Context: a short
AGENTS.md/CLAUDE.md, and docs the agent can read as Markdown (llms.txt,.mdpages, an MCP server).
The short version
| Kit | Stack | Price (Sept 2026) | Agent files and tools | Anything enforced? |
|---|---|---|---|---|
| ShipKit | TanStack Start, Cloudflare Workers, D1 | $99 one-time (launch) | CLAUDE.md, AGENTS.md, 9 setup skills, llms.txt + llms-full.txt | Yes: architecture tests, deletion recipes run in CI, schema/migration check |
| MakerKit | Next.js or TanStack Start; Supabase, Drizzle or Prisma | $349 / $649 one-time | AGENTS.md (root and per package), CLAUDE.md, 9 skills, MCP server, llms.txt | Typecheck, lint and healthcheck commands; no architecture tests stated |
| supastarter | Next.js (also Nuxt, TanStack Start), Hono | $299 / $799 / $1,499 one-time | AGENTS.md, Agent Skills, .cursorrules, docs as .md | Lint and Playwright e2e configured |
| Open SaaS | Wasp (React, Node, Prisma, Postgres) | Free, MIT | AGENTS.md, CLAUDE.md, skills, Claude Code plugin, llms-full.txt | Playwright e2e, ESLint in CI |
| TurboStarter | Turborepo: Next.js, Expo, extension, Hono | $249 / $399 one-time | AGENTS.md, skills, a reviewer subagent, docs MCP server | Not stated |
| Achromatic | Next.js, tRPC, Prisma or Drizzle | $180 one-time | Instructions for Codex, Claude Code and Cursor; local MCP server | Not stated |
| FlareStarter | TanStack Start, Cloudflare Workers, D1 | Free (Apache-2.0); Pro $99 | AGENTS.md, CLAUDE.md | Lint, typecheck and build in CI |
| MkSaaS | Next.js, Drizzle, Better Auth | $129 one-time (sale) | agents.md, claude.md, ~17 Cursor rules | Not stated |
| NextDevKit | Next.js; Vercel, Workers or AWS | $169–$219 | Rules generated per IDE, llms.txt | Not stated |
| Cove Stack | TanStack Start, Postgres | Free, Unlicense | AGENTS.md, a testing guide, skills | Not stated |
| Next.js SaaS Starter | Next.js, Postgres, Drizzle, Stripe | Free, MIT | None | Not stated |
| ShipFast | Next.js, MongoDB or Supabase | $199–$299 one-time | None found | Not stated |
How to choose, in three questions
1. Who reviews the agent's work? If you read every diff, written context and a good test suite are enough, and any kit in the top half works. If you don't, and most solo builders shipping with an agent don't, you want the repository to reject a broken change on its own.
2. Which jobs will the agent do unsupervised? Wiring Stripe webhooks, OAuth clients and a production deploy are the steps where a wrong guess costs money or leaks data. Kits that ship these as skills (ShipKit, MakerKit, supastarter, Open SaaS) turn them into a procedure instead of an improvisation.
3. Does the stack suit you apart from the AI features? Agent tooling is the easiest part of a kit to copy. The database, the host, and whether you need teams and organizations are not. Pick the stack first, then the best agent support within it.
The kits
ShipKit
TanStack Start on Cloudflare Workers, with D1, R2, Drizzle, passwordless Better Auth, Stripe and Creem, an admin console, credits, API keys and English and Chinese.
What the agent gets: a CLAUDE.md and AGENTS.md with the hard rules,
and 9 skills for the setup flows: first run, Google OAuth, Stripe, Creem,
deploy, adding a feature, deleting one, an SEO audit and the admin data API.
The docs are published as llms.txt and a full-text
llms-full.txt.
What is enforced:
- A unit test reads every admin route and server function and fails if one doesn't check a permission.
- Another fails if a module the browser loads imports server-only code.
- Every optional feature has a deletion recipe.
bun run verify:deletionapplies it to a copy of the repo and requires the build, typecheck and tests to pass, and CI runs it on every pull request. - CI fails if the database schema changed without a migration.
Where it's weaker: no MCP server, no teams or organizations yet, Cloudflare only, and no buyer reviews yet because it's new. $99 one-time at launch; there's a live demo with no sign-up.
MakerKit
The most complete agent package among the paid kits. It ships AGENTS.md at
the root and per package, a CLAUDE.md, Gemini instructions, nine skills
(/server-action-builder, /rls-review, /playwright-e2e, /bug-hunt and
others) and an MCP server, launched in September 2025, that exposes its
components, scripts and a PRD tracker. Its instructions tell the agent to run
typecheck, lint and format. Next.js or TanStack Start, with Supabase or
Drizzle/Prisma. $349 (Pro) or $649 (Teams). Choose it if you are building
multi-tenant B2B and want the broadest agent tooling.
(source)
supastarter
Markets itself as "the SaaS starter kit your coding agent deserves". It ships
AGENTS.md, Agent Skills for features, auth, payments and tests, and
.cursorrules, and every docs page is available as Markdown. Lint and
Playwright end-to-end tests are configured. Next.js, Nuxt or TanStack Start,
with organizations, five payment providers and the widest auth options
(passkeys, 2FA). $299, $799 or $1,499 by seats. Choose it if you're a team
on Postgres and want an established kit with agent support.
(source)
Open SaaS
The strongest free option. Built on the Wasp framework, with AGENTS.md,
CLAUDE.md, skills for both Claude Code and other agents, llms.txt and
llms-full.txt for the docs, and an official Wasp plugin for Claude Code.
Playwright tests and ESLint run in CI. Its own docs call the rules "just a
starting point". About 16k GitHub stars, MIT. Choose it if you want free
and don't mind building on Wasp.
(source)
TurboStarter
A monorepo that covers web, mobile (Expo) and a browser extension. One
.agents/ folder with skills, a code-reviewer subagent and a
setup-new-feature command is linked into the Cursor, Claude and GitHub
folders, plus a public MCP server for the docs. $249, or $399 with its AI kit.
Choose it if you need mobile and web from one codebase.
(source)
Achromatic
Next.js with tRPC, shipping repository instructions for Codex, Claude Code and Cursor and a local, read-only MCP server with 19 tools that report the project's structure and validation commands. $180 one-time, unlimited projects. Choose it if you want MCP-level context on a Next.js stack at a lower price. (source)
FlareStarter
The closest to ShipKit on stack: TanStack Start, Workers, D1, Drizzle and
Better Auth, open source under Apache-2.0, with AGENTS.md imported into
CLAUDE.md. CI runs lint, typecheck and build. A Pro edition ($99 one-time)
adds organizations and RBAC. Choose it if you want Cloudflare and want to
start free.
(source)
MkSaaS, NextDevKit, Cove Stack
- MkSaaS ($129 on sale) ships
agents.md,claude.mdand about 17 topic rules for Cursor, and recommends the Context7 and Chrome DevTools MCP servers. - NextDevKit ($169–$219) keeps its rules in one folder and generates them per IDE. Its docs make a good point: "AI rules are not the more the better".
- Cove Stack (free) is a minimal TanStack Start base with an
AGENTS.mdand a testing guide for agents.
Next.js SaaS Starter and ShipFast
Two popular kits with no agent files at all. The official Next.js starter is
free and minimal. ShipFast is the best-known paid Next.js kit, and it markets
compatibility with AI editors rather than shipping instructions for them.
Either is fine if you plan to write your own AGENTS.md.
Our take
- Broadest tooling, paid: MakerKit, then supastarter.
- Free: Open SaaS, or FlareStarter if you want Cloudflare.
- Mobile plus web: TurboStarter.
- You won't review every diff: that's the case ShipKit was built for. Written rules get followed most of the time; the ones that matter here are also tests, so the rest of the time the build fails instead of your production app.
Whatever you choose, add the check before you add the context. A
fifty-line AGENTS.md and a test that fails on a missing permission check do
more than a thousand-line rules file.


