# ShipKit > SaaS boilerplate on TanStack Start + Cloudflare Workers: auth, Stripe/Creem payments, credits, admin console and i18n, built for Claude Code and Cursor. Pay once. ShipKit is a SaaS starter template sold as a one-time license (https://shipkit.sh/pricing): a private GitHub repository the buyer builds their own product on. The docs below describe the template. Every page also exists in Chinese under https://shipkit.sh/zh/. ## Docs: Get started - [Introduction](https://shipkit.sh/docs/introduction): What ShipKit is, what the template ships with, the stack it is built on and why, and how the repository is laid out. - [Getting started](https://shipkit.sh/docs/getting-started): From clone to a running local app you are an admin of, in the order that works — install, secrets, database, dev server, first sign-in. - [Working with AI agents](https://shipkit.sh/docs/ai-agents): How ShipKit is set up for Claude Code, Codex and Cursor — the rule files, the skills for recurring jobs, and the tests that catch an agent's mistakes. - [Configuration](https://shipkit.sh/docs/configuration): Where each kind of setting lives — the config files in src/config, the environment variables, wrangler.jsonc, and the settings operators edit in the admin console. - [Deploy](https://shipkit.sh/docs/deploy): Put ShipKit on Cloudflare Workers — create D1 and R2, push secrets, migrate, deploy, attach a domain, and wire OAuth, webhooks and email for production. - [Upgrading](https://shipkit.sh/docs/upgrading): Pull a new ShipKit release into your project with git — add the release repo as a remote, merge a version tag, resolve conflicts, and bring migrations along. ## Docs: Concepts - [Architecture](https://shipkit.sh/docs/architecture): How a request moves through ShipKit, how the code is split into core and feature slices, and the bundle rules that keep the site fast. - [Server functions](https://shipkit.sh/docs/server-functions): The one data channel from page to database — loaders, React Query, authedFn and adminFn, when to use an API route instead, and rate limiting. - [Database](https://shipkit.sh/docs/database): Cloudflare D1 with Drizzle — where tables are defined, the migration workflow, seeding, and writing safely without interactive transactions. - [Roles and permissions](https://shipkit.sh/docs/permissions): How ShipKit decides who can do what in the admin console — permissions, roles, the built-in admin, and how to guard a new page or server function. ## Docs: Features - [Authentication](https://shipkit.sh/docs/authentication): Passwordless sign-in with better-auth — Google and One Tap, optional GitHub, emailed codes — plus sessions, the auth config rule, and account deletion and export. - [Payments](https://shipkit.sh/docs/payments): Stripe and Creem are both wired in. How checkout, webhooks, plan changes and refunds work, how to pick a provider, and how to test locally. - [Credits and metered usage](https://shipkit.sh/docs/credits): The credit ledger, where credits come from (plans, packs, admins), how to charge for work safely on D1, and the worked example of a metered API endpoint. - [Admin console](https://shipkit.sh/docs/admin-console): The /admin console — its five sections, the user drawer, overview KPIs, operator settings, and how to add a page of your own. - [API keys](https://shipkit.sh/docs/api-keys): The two kinds of API key, the admin data API at /api/v1/admin/* and the user API at /api/v1/me/*, the response envelope, and how to add an endpoint. - [Email and notifications](https://shipkit.sh/docs/email-notifications): Transactional email through Resend, templates localized by each user's locale, the email log, and the in-app notification bell fed by notify(). - [File storage](https://shipkit.sh/docs/file-storage): How ShipKit stores files in Cloudflare R2 through a Worker binding — uploads, private downloads, profile photos, quotas and the optional files module. - [Internationalization](https://shipkit.sh/docs/i18n): Paraglide messages, English at / and Chinese at /zh, how locale is detected and remembered, localized emails and content, and adding a language. - [Blog, docs and legal pages](https://shipkit.sh/docs/content): Writing the blog, docs and legal pages in MDX — file naming per language, frontmatter, the table of contents, and adding a collection of your own. - [Landing page and themes](https://shipkit.sh/docs/landing-themes): The landing page as a list of blocks in one config file, the block shapes you can use, the four built-in themes, and product screenshots. - [More modules](https://shipkit.sh/docs/more-modules): Product analytics, the affiliate programme, the audit log, in-app feedback, the pre-launch waitlist and the public demo mode, and how to switch each one on or off. ## Docs: Customize - [Adding features](https://shipkit.sh/docs/adding-features): Build a new module as a vertical slice — schema, server functions, route, registries — and keep it deletable with a verified recipe. - [Deleting features](https://shipkit.sh/docs/deleting-features): Remove the bundled modules you don't need — credits, files, blog and docs, waitlist and more — with recipes that are checked by build, typecheck and tests. ## Docs: Reference - [Commands](https://shipkit.sh/docs/commands): Every package.json script in ShipKit, grouped by what you use it for, plus the handful of wrangler one-liners you will reach for. - [Operations](https://shipkit.sh/docs/operations): What runs in production besides requests — the nightly cron jobs, logs and error pages, rate limits, security headers, CI and backups. - [Troubleshooting](https://shipkit.sh/docs/troubleshooting): The failures you are most likely to hit with ShipKit — env validation, migrations, stale generated files, OAuth, webhooks — and how to fix each one. ## Blog - [Stripe vs Creem vs Paddle vs Lemon Squeezy: getting paid when Stripe doesn't support your country](https://shipkit.sh/blog/stripe-vs-creem-vs-paddle-vs-lemon-squeezy): Selling a SaaS to customers abroad without a company in a Stripe country? Four payment platforms compared: who is the merchant of record, what each charges, who can sign up, and how the money gets home. Worked through for mainland China, as of September 2026. - [TanStack Start vs Next.js: why we built a SaaS starter on TanStack Start](https://shipkit.sh/blog/tanstack-start-vs-nextjs): Next.js is the default for React SaaS. We chose TanStack Start for ShipKit anyway: native Cloudflare Workers support, type-safe routing and an explicit data flow that an AI agent can follow. Here is the trade, including what we gave up. - [How to sell access to a private GitHub repo](https://shipkit.sh/blog/sell-access-to-a-private-github-repo): Payment in, read-only collaborator out, access gone on a full refund: the whole delivery flow behind shipkit.sh, with the GitHub API calls and the edge cases that bite. - [Moving from Cloudflare D1 to Postgres later: what an AI can translate, and what it can't](https://shipkit.sh/blog/migrate-d1-to-postgres): Starting on D1 (SQLite) doesn't lock you in forever. Switching a Drizzle app to Postgres is mostly mechanical, and an AI agent handles that part well. The real work is behavior that changes silently and the data you already have. A checklist. - [The best TanStack Start boilerplates in 2026, compared](https://shipkit.sh/blog/best-tanstack-start-boilerplates): Nine TanStack Start SaaS starters side by side: where each one runs, which database, auth and payments it uses, what it costs, and who it is actually for. Written by the makers of one of them. - [Cloudflare Workers + D1 vs Vercel + Postgres for a SaaS: why ShipKit chose Cloudflare](https://shipkit.sh/blog/why-cloudflare-workers-not-vercel): What it costs to run a SaaS on Workers, D1 and R2 versus Vercel and a hosted Postgres, at 1,000 and 10,000 users, with the arithmetic. What Cloudflare gives you, what it takes away, and when to pick the other side. - [The best SaaS boilerplates for AI coding agents in 2026 (Claude Code, Cursor, Codex)](https://shipkit.sh/blog/best-saas-boilerplates-for-ai-coding-agents): Twelve SaaS starters compared on what they actually give a coding agent: AGENTS.md and CLAUDE.md, skills, MCP servers, llms.txt, and whether anything checks that the agent kept to the rules. Prices and sources as of September 2026. - [The best SaaS starter kits for Cloudflare Workers in 2026](https://shipkit.sh/blog/best-saas-starter-kits-for-cloudflare-workers): Ten SaaS boilerplates that deploy to Cloudflare Workers, compared: which run natively and which go through an adapter, D1 or Postgres over Hyperdrive, auth, payments and price. With the Workers and D1 limits that decide the choice, as of September 2026. - [Why every feature in this template is deletable](https://shipkit.sh/blog/why-every-feature-is-deletable): A starter you delete from is more useful than one you add to — but only if deleting is a recipe rather than an archaeology dig. - [D1 has no interactive transactions: how to spend a balance safely anyway](https://shipkit.sh/blog/d1-has-no-transactions): Spending credits safely on Cloudflare D1, where db.transaction() throws: a conditional single statement, when to reach for batch(), and the append-only ledger ShipKit uses so there is no balance to get wrong. - [From clone to deployed, start to finish](https://shipkit.sh/blog/from-clone-to-deploy): Every step between `bun install` and a live domain — what you configure, in what order, and which steps you genuinely cannot automate. ## Optional - [Full text](https://shipkit.sh/llms-full.txt): every page above in one Markdown file - [About](https://shipkit.sh/about): who makes ShipKit, and the company facts - [Pricing](https://shipkit.sh/pricing): what the license includes and costs - [Sitemap](https://shipkit.sh/sitemap.xml): every page, both languages