Hikari by CoreMVP
Getting started

Project structure

Place your next feature at the boundary that owns its behavior.

Add a page in src/app, an application API in src/api, a business rule in src/services, and database access in src/repositories. Hikari deploys them together in one Next.js runtime.

LocationJob
src/appPages, layouts, and Next.js Auth callbacks
src/apiSame-origin Hono routes, input validation, and HTTP responses
src/servicesApplication behavior and access decisions
src/repositoriesDrizzle queries and transactions
src/providersSupabase Auth and Stripe calls
src/db and supabase/migrationsTypeScript schema and database migrations
src/contentDocs and Blog MDX

Add a protected operation

For an account operation, start from GET /api/account in src/api/app.ts: it calls auth.requireUser() before returning the signed-in identity. Put resource-specific decisions in src/services and use the verified user ID in repository queries.

The browser calls the same-origin /api/* surface. Hono owns application APIs through src/app/api/[[...route]]/route.ts; the Next.js /auth/callback and /auth/confirm routes handle Auth provider protocols.

Keep credentials and access checks on the server. A successful redirect or browser cache does not authorize an operation. Read Authentication and Subscriptions before adding your own protected routes.

Customize the dashboard

Edit src/app/(protected)/dashboard/page.tsx for the overview and src/components/dashboard-shell.tsx for the shared navigation, account menu, and organization/project pickers. The chart composition is in src/components/dashboard-analytics.tsx.

Organization/project selection and chart data are visual examples. They do not persist organizations, projects, or analytics. Keep their example labels until you connect your own data and server authorization. Account and subscription summaries read the real signed-in account and stored subscription.

Add application data

Hikari’s customers table maps a Supabase user to a Stripe Customer. subscriptions records current subscription state. These tables are server-owned: Supabase browser roles have no privileges or client policies for them.

Add your own SQL migration under supabase/migrations and update src/db/schema.ts with the corresponding Drizzle model. Choose and implement authorization for your new tables before exposing them through an API. The billing tables’ permissions do not automatically protect unrelated application data.

Next, use the testing reference to verify the boundary your feature changes.

On this page