npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

create-sporekit

v0.1.19

Published

CLI for installing composable Sporekit developer kits.

Readme

create-sporekit

Build the parts of an application that should not have to start from zero.

Developed by Kyle Andre Lim, Software Engineer, at PiP Spore Technologies Inc.

create-sporekit is the Sporekit CLI for developers who want a real authentication foundation without repeatedly wiring providers, sessions, protected routes, database adapters, environment variables, and documentation by hand. It creates a working, framework-native Auth Kit starter or adds a safe, opt-in integration to an existing application—so developers can spend their time on their product, UI, roles, and business logic.

It is not a static authentication mockup. Fresh full-stack starters include an authentication flow that developers can run and then customize: email sign-up and sign-in, selected social providers, protected application areas, sign-out, server integration, and database setup.

What is available today

Auth Kit

The current production kit is Auth Kit. It helps developers start with a customizable authentication implementation rather than a blank framework screen. Existing projects are handled conservatively: Sporekit detects the framework and adds reviewable, opt-in files without replacing application pages, routes, or configuration.

Supported frameworks

  • Next.js
  • Vite + React
  • TanStack Start
  • Laravel
  • React Native with Expo
  • Astro

Fresh Next.js and Vite projects also support a workspace layout through --monorepo. Manual framework installation is documented in the Storefront documentation, rather than presented as a CLI framework choice.

Quick start

Authenticate your device, then initialize a project:

npx create-sporekit@latest login
npx create-sporekit@latest init

The login flow opens the Sporekit Storefront in a browser and verifies that the signed-in account has an active license before any non-dry-run installation begins.

The Sporekit roadmap

Sporekit is designed as a family of composable developer kits, not only an authentication CLI.

Planned: Payments Kit

Payments Kit will reduce the repeated work of implementing and maintaining payment gateways across providers. The goal is a consistent developer experience for payment flows, webhooks, status handling, environment setup, and provider-specific documentation—without rebuilding the same integration from scratch for every project. Planned provider research includes PayMongo, Dragonpay, Xendit, and other regional and global payment providers.

Possible future kits

The platform can expand with focused kits such as:

  • Roles and organizations — teams, permissions, invitations, and multi-tenant foundations.
  • Billing and subscriptions — plans, entitlements, invoices, and lifecycle events.
  • Email and notifications — transactional email, templates, queues, and delivery events.
  • Storage and media — uploads, signed access, transformations, and provider adapters.
  • Security and audit logs — activity history, account protection, and compliance-oriented logs.
  • Admin and operations — internal dashboards, support tools, and safe management workflows.
  • AI application foundations — provider adapters, usage controls, and application-ready patterns.

These are future directions, not current package promises. Auth Kit is the available, supported starting point today.

Local development

pnpm --filter create-sporekit build
node packages/cli/dist/index.js --help

Create a starter project

Run the CLI without a command to answer prompts for a project name, starter type, package manager, social providers, and auth features. It bootstraps Next.js using the official create-next-app defaults (TypeScript, Tailwind, ESLint, App Router, src/, and @/*), then installs the selected Sporekit kit.

npx create-sporekit my-app
npx create-sporekit my-ui --ui-only --use-pnpm --yes
npx create-sporekit my-auth-app --providers google,apple --features email-security,passkey --yes

Use --dry-run to inspect the exact plan without creating files. During local registry development, pass --registry packages/kit-source/dist/registry.json.

Initialize the current directory

Use init for a guided shadcn-style workflow. In a fresh directory it asks for a framework, authentication starter, social provider, and project name before running the framework scaffold and selected kit installer. Pass --project-name . to intentionally scaffold into the current empty directory. In an existing project, it detects the framework and writes only .sporekit/config.json; it never replaces application files. A marker conflict requires an explicit --overwrite.

For a fresh Next.js or Vite monorepo, pass --monorepo. The workspace is created at <project-name>/, with the application at <project-name>/apps/web; that app workspace receives the Sporekit marker and authentication kit.

For a fresh Next.js project, choose recommended defaults or Customize Next.js settings. The custom path presents those framework-specific choices directly: TypeScript, linter, React Compiler, Tailwind, src/, App Router, import alias, and AGENTS.md. Sporekit then passes the chosen settings to create-next-app while still using the package manager that launched it.

# Guided setup: creates a named project directory.
npx create-sporekit init

# Empty folder: scaffold directly into the current directory.
npx create-sporekit init --template next --project-name . --yes

# Automate recommended Next.js defaults. Custom setup remains interactive.
npx create-sporekit init --template next --project-name my-app --next-setup recommended --yes

# Fresh Next.js monorepo: create my-workspace/apps/web and configure that app workspace.
npx create-sporekit init --template next --project-name my-workspace --monorepo --yes

# Existing project: detect its framework and initialize safely.
npx create-sporekit init

A fresh full-stack Next.js app includes the working authentication starter by default: email sign-up and sign-in, selected Google social sign-in, a protected dashboard, and sign-out. After setting the generated .env values and migrating the database, it is an application foundation that can be customized rather than a static preview. Pass --no-demo to retain the framework's default page. For an existing Next.js application, the initializer never replaces its main page; pass --demo to add the same starter beneath src/app/sporekit-demo/ or app/sporekit-demo/, matching the project's existing layout.

The initializer infers pnpm, npm, yarn, or bun from the command used to launch it, so it does not ask the user to select a package manager. The supported framework selections are next, vite (React), tanstack-start, laravel, react-native (Expo), and astro. Every fresh selection now generates its framework-native starter; existing projects receive an opt-in, non-destructive integration instead. Manual installation belongs in the Storefront documentation, rather than the CLI selector.

Release-style package verification

Build the registry and test the packed tarball through npm exec before publishing. This does not publish anything or modify the repository:

pnpm test:cli-package

The check creates a temporary consumer project, runs the packed create-sporekit binary, and installs a UI-only kit from the locally built registry.

Local registry development

Build the registry, then point the CLI at it while developing locally:

pnpm build:registry
pnpm --filter create-sporekit build
node packages/cli/dist/index.js add auth-full --registry packages/kit-source/dist/registry.json --cwd apps/registry-fixture --skip-install --yes

The installer resolves registry dependencies, refuses to overwrite different existing files unless --overwrite is explicit, adds only missing .env.example keys, and installs dependencies through the detected package manager. Use --dry-run to inspect an install without changing files.

When an installed item needs Prisma and the consumer has no Prisma schema, the CLI installs the supported Prisma 7 toolchain and runs prisma init --output ../src/generated/prisma --no-skills. Prisma initializes a PostgreSQL datasource by default; the CLI verifies that result, then changes only its newly generated config to point to the prisma/ directory, which is required for Prisma's multi-file schema support. Existing Prisma configurations are never rewritten.

License login

Protected kit delivery uses browser-based device authorization tied to the signed-in Storefront account. Run the interactive command before installing a paid kit:

npx create-sporekit login

The CLI opens a Storefront page and shows a short device code for confirmation. An active Auth Kit license can register up to three devices; each authorization lasts 30 days, and support can reset a device when needed. Re-running create-sporekit login reports an active device instead of opening the browser again. The CLI has no logout or device-removal command. It stores a device credential outside consumer projects. On Windows, its device secret is encrypted with user-scoped DPAPI; other platforms use restrictive file permissions. It does not store the raw license key.

After login, the CLI automatically refreshes a short-lived access token for the protected Sporekit registry. Local registries passed through --registry remain useful for offline development.

Publishing

The package is released only from an approved GitHub Release through npm Trusted Publishing. Follow the repository's npm release guide for the one-time npm and GitHub environment setup, release checks, and tag procedure.