create-sporekit
v0.1.19
Published
CLI for installing composable Sporekit developer kits.
Maintainers
Readme
create-sporekit
Build the parts of an application that should not have to start from zero.
Developed by Kyle Andre Lim, Software Engineer, at PiP Spore Technologies Inc.
create-sporekit is the Sporekit CLI for developers who want a real authentication foundation
without repeatedly wiring providers, sessions, protected routes, database adapters, environment
variables, and documentation by hand. It creates a working, framework-native Auth Kit starter or
adds a safe, opt-in integration to an existing application—so developers can spend their time on
their product, UI, roles, and business logic.
It is not a static authentication mockup. Fresh full-stack starters include an authentication flow that developers can run and then customize: email sign-up and sign-in, selected social providers, protected application areas, sign-out, server integration, and database setup.
What is available today
Auth Kit
The current production kit is Auth Kit. It helps developers start with a customizable authentication implementation rather than a blank framework screen. Existing projects are handled conservatively: Sporekit detects the framework and adds reviewable, opt-in files without replacing application pages, routes, or configuration.
Supported frameworks
- Next.js
- Vite + React
- TanStack Start
- Laravel
- React Native with Expo
- Astro
Fresh Next.js and Vite projects also support a workspace layout through --monorepo. Manual
framework installation is documented in the Storefront documentation,
rather than presented as a CLI framework choice.
Quick start
Authenticate your device, then initialize a project:
npx create-sporekit@latest login
npx create-sporekit@latest initThe login flow opens the Sporekit Storefront in a browser and verifies that the signed-in account has an active license before any non-dry-run installation begins.
The Sporekit roadmap
Sporekit is designed as a family of composable developer kits, not only an authentication CLI.
Planned: Payments Kit
Payments Kit will reduce the repeated work of implementing and maintaining payment gateways across providers. The goal is a consistent developer experience for payment flows, webhooks, status handling, environment setup, and provider-specific documentation—without rebuilding the same integration from scratch for every project. Planned provider research includes PayMongo, Dragonpay, Xendit, and other regional and global payment providers.
Possible future kits
The platform can expand with focused kits such as:
- Roles and organizations — teams, permissions, invitations, and multi-tenant foundations.
- Billing and subscriptions — plans, entitlements, invoices, and lifecycle events.
- Email and notifications — transactional email, templates, queues, and delivery events.
- Storage and media — uploads, signed access, transformations, and provider adapters.
- Security and audit logs — activity history, account protection, and compliance-oriented logs.
- Admin and operations — internal dashboards, support tools, and safe management workflows.
- AI application foundations — provider adapters, usage controls, and application-ready patterns.
These are future directions, not current package promises. Auth Kit is the available, supported starting point today.
Local development
pnpm --filter create-sporekit build
node packages/cli/dist/index.js --helpCreate a starter project
Run the CLI without a command to answer prompts for a project name, starter type, package
manager, social providers, and auth features. It bootstraps Next.js using the official
create-next-app defaults (TypeScript, Tailwind, ESLint, App Router, src/, and @/*),
then installs the selected Sporekit kit.
npx create-sporekit my-app
npx create-sporekit my-ui --ui-only --use-pnpm --yes
npx create-sporekit my-auth-app --providers google,apple --features email-security,passkey --yesUse --dry-run to inspect the exact plan without creating files. During local registry
development, pass --registry packages/kit-source/dist/registry.json.
Initialize the current directory
Use init for a guided shadcn-style workflow. In a fresh directory it asks for a framework,
authentication starter, social provider, and project name before running the framework scaffold
and selected kit installer. Pass --project-name . to intentionally scaffold into the current
empty directory. In an existing project, it detects the framework and writes only
.sporekit/config.json; it never replaces application files. A marker conflict requires an
explicit --overwrite.
For a fresh Next.js or Vite monorepo, pass --monorepo. The workspace is created at
<project-name>/, with the application at <project-name>/apps/web; that app workspace receives
the Sporekit marker and authentication kit.
For a fresh Next.js project, choose recommended defaults or Customize Next.js settings. The
custom path presents those framework-specific choices directly: TypeScript, linter, React
Compiler, Tailwind, src/, App Router, import alias, and AGENTS.md. Sporekit then passes the
chosen settings to create-next-app while still using the package manager that launched it.
# Guided setup: creates a named project directory.
npx create-sporekit init
# Empty folder: scaffold directly into the current directory.
npx create-sporekit init --template next --project-name . --yes
# Automate recommended Next.js defaults. Custom setup remains interactive.
npx create-sporekit init --template next --project-name my-app --next-setup recommended --yes
# Fresh Next.js monorepo: create my-workspace/apps/web and configure that app workspace.
npx create-sporekit init --template next --project-name my-workspace --monorepo --yes
# Existing project: detect its framework and initialize safely.
npx create-sporekit initA fresh full-stack Next.js app includes the working authentication starter by default: email
sign-up and sign-in, selected Google social sign-in, a protected dashboard, and sign-out. After
setting the generated .env values and migrating the database, it is an application foundation
that can be customized rather than a static preview. Pass --no-demo to retain the framework's
default page. For an existing Next.js application, the initializer never replaces its main page;
pass --demo to add the same starter beneath src/app/sporekit-demo/ or
app/sporekit-demo/, matching the project's existing layout.
The initializer infers pnpm, npm, yarn, or bun from the command used to launch it, so it does not
ask the user to select a package manager. The supported framework selections are next, vite (React), tanstack-start, laravel,
react-native (Expo), and astro. Every fresh selection now generates its framework-native
starter; existing projects receive an opt-in, non-destructive integration instead. Manual
installation belongs in the Storefront documentation,
rather than the CLI selector.
Release-style package verification
Build the registry and test the packed tarball through npm exec before publishing. This
does not publish anything or modify the repository:
pnpm test:cli-packageThe check creates a temporary consumer project, runs the packed create-sporekit binary,
and installs a UI-only kit from the locally built registry.
Local registry development
Build the registry, then point the CLI at it while developing locally:
pnpm build:registry
pnpm --filter create-sporekit build
node packages/cli/dist/index.js add auth-full --registry packages/kit-source/dist/registry.json --cwd apps/registry-fixture --skip-install --yesThe installer resolves registry dependencies, refuses to overwrite different existing files unless --overwrite is explicit, adds only missing .env.example keys, and installs dependencies through the detected package manager. Use --dry-run to inspect an install without changing files.
When an installed item needs Prisma and the consumer has no Prisma schema, the CLI installs the supported Prisma 7 toolchain and runs prisma init --output ../src/generated/prisma --no-skills. Prisma initializes a PostgreSQL datasource by default; the CLI verifies that result, then changes only its newly generated config to point to the prisma/ directory, which is required for Prisma's multi-file schema support. Existing Prisma configurations are never rewritten.
License login
Protected kit delivery uses browser-based device authorization tied to the signed-in Storefront account. Run the interactive command before installing a paid kit:
npx create-sporekit loginThe CLI opens a Storefront page and shows a short device code for confirmation. An active Auth Kit
license can register up to three devices; each authorization lasts 30 days, and support can reset
a device when needed. Re-running create-sporekit login reports an active device instead of
opening the browser again. The CLI has no logout or device-removal command. It stores a
device credential outside consumer projects. On Windows, its device secret is encrypted with
user-scoped DPAPI; other platforms use restrictive file permissions. It does not store the raw
license key.
After login, the CLI automatically refreshes a short-lived access token for the protected Sporekit
registry. Local registries passed through --registry remain useful for offline development.
Publishing
The package is released only from an approved GitHub Release through npm Trusted Publishing. Follow the repository's npm release guide for the one-time npm and GitHub environment setup, release checks, and tag procedure.
