Skip to content
Norcel
Production-Grade SaaS Starter Kit

Stop rebuilding authentication for every project.

Production-ready Next.js boilerplate with auth, email, and database and other necessary features to help you launch your startup in days instead of months.

$49 LAUNCH SALE — FIRST 100 BUYERS

/ modern stack

ready

Everything wired, nothing to glue.

Modern components, beautiful UI, dark-ready by default.

  • Auth.js
    Email, OAuth, magic links, sessions
  • Prisma + Supabase
    Typed PostgreSQL with migrations
  • Resend
    Transactional email, ready to send
  • Zod + TypeScript
    Runtime-validated, end-to-end typed
  • Tailwind v4
    Modern, responsive, dark-ready UI
  • Next.js 16
    App Router, RSC, edge-ready
Norcel UI Kit free
Free with launch - 40+ premium components
$99 value
v1.0 · MIT-style license See full stack

/ the problem

52+ hours wasted.

Weeks lost before you launch. You have a great idea - but you're stuck setting up auth, database, emails, and infrastructure instead of building your product.

  • No clear roadmap for setup
  • Wasting weeks on undocumented, outdated, and complicated boilerplate code
  • Constantly debugging infrastructure issues
  • Worrying about security holes and edge cases you don't have time to audit
wasted
5+ hrs

Setting up authentication that actually works

Sessions, cookies, OAuth callbacks, password reset, email verification - every project starts the same way.

wasted
8+ hrs

Wiring your database and migrations

Schema design, Prisma setup, migration strategy, seed data, production connection pooling, row-level security.

wasted
6+ hrs

Configuring email service and templates

Resend, Postmark, or SES. React Email templates. Domain authentication. Bounce handling. Reply-to routing.

wasted

Debugging instead of launching your product

Race conditions in middleware, CORS issues, broken redirects, mysterious 500s. Hours disappear into infrastructure.

Norcel gives you a production-grade stack on day one - so you can launch, not debug.

the solution

Launch your startup in days, with production-ready code and without headaches.

Stop wasting time on setup. Get authentication, database, emails, and database pre-configured with best practices. Ship your first version in days, iterate based on real user feedback, and scale when you're ready.

norcel.dev / dashboard
MRR
$12,480
+18.2%
Customers
248
Sessions
1.2k
/ 01
10 min

From purchase to first deploy

/ 02
Ready

Production-grade code from day one

Everything configured, tested, and ready

Auth flows that work. Email templates that render everywhere. Database migrations that just run. Just clone and start building.

Launch fast, iterate faster

Focus on what makes your product unique. Get paying customers while others are still setting up auth.

/ everything you need

Everything you need to launch fast.

Five pillars, wired together. The only thing left to build is the part that makes your product yours.

01 — authentication

Authentication ready.

User sign-up and login with Auth.js. Social providers, magic links, and email/password flows all configured.

  • Google & GitHub OAuth
  • Email + password with argon2id
  • Magic links via Resend
  • Server-side sessions in DB
norcel.dev / login OAuth
or
ada@norcel.dev
••••••••••••

Forgot password? Reset it

norcel.dev / perf Edge
LCP
0.8s
good
TTFB
42ms
good
CLS
0.00
good
Edge regions ● live
us
eu
ap
sa
af
me

02 — performance

Edge-first performance.

Streaming SSR + React Server Components, Edge middleware, run anywhere except Workers Image optimization baked in Static-first caching, with opt-in for dynamic

  • Streaming SSR + React Server Components
  • Edge middleware (any runtime except Workers — argon2 needs Node)
  • Image optimization baked in (next/image with Google + GitHub avatar hosts)
  • Vercel default caching (static-first, opt-in for dynamic via revalidate)

03 — email

Email templates.

Transactional emails via Resend. Verification, welcome, magic-link, password reset, and email-change ready to send. Receipts in v1.1.

  • 5 templates (verification, welcome, reset, magic-link, change)
  • Receipts in v1.1.
  • Domain-authenticated sender
  • Reply-to handled (replies go to Norcel@contact.norcel.dev)
inbox / welcome Resend
F
Welcome to Norcel
hi@norcel.dev

You're in. Let's build.

Thanks for signing up. Your account is ready — head to the dashboard to get your first deploy live in 10 minutes.

Norcel · hi@norcel.dev · unsubscribe
Delivered · 99.4% open rate
ui / components shadcn/ui
primary
Button
soft
Card
outline
Input
soft
Dialog
primary
Toast
outline
Menu

04 — UI

Beautiful UI components.

shadcn/ui components styled with Tailwind. Dark mode, responsive, and accessible out of the box.

  • 40+ accessible primitives
  • Dark mode tokens baked in
  • Tailwind v4 + Radix under the hood
  • Drop-in for any Next.js 16 project

05 — database & beyond

Database & beyond.

Postgres with Supabase, SEO optimization, blog system, user dashboard, AI integration, and legal pages. Everything you need.

  • Postgres + Prisma ORM
  • Production-ready migrations
  • SEO + blog + legal pages
  • AI integration hooks (In V1.2)
prisma / schema Postgres
User
248 rows
id
email
role
Project
142 rows
id
userId
status
Session
1.2k rows
id
userId
expires
Account
89 rows
id
userId
provider
npx prisma migrate deploy ✓ ready

/ comparison

Why choose Norcel?

An honest comparison with the alternatives.

Norcel best
  • Time to Launch Days
  • Cost $99 $49 one-time
  • Authentication Auth.js configured
  • Type Safety End-to-end typed
  • Email Templates Resend ready
  • UI Components shadcn/ui
  • SEO Setup Complete
  • Blog System MDX included
  • Documentation Clear & updated
  • Support Developer help (Norcel@contact.norcel.dev)
  • Updates Lifetime
From Scratch
  • Time to Launch 2–3 months
  • Cost Your time
  • Authentication Build yourself
  • Type Safety Type as you go
  • Email Templates Build yourself
  • UI Components Build yourself
  • SEO Setup Setup yourself
  • Blog System Build yourself
  • Documentation None
  • Support None
  • Updates You maintain
Open source
  • Time to Launch Weeks (setup)
  • Cost Free*
  • Authentication Basic example
  • Type Safety Partial coverage
  • Email Templates None / outdated
  • UI Components Inconsistent
  • SEO Setup Partial
  • Blog System Varies
  • Documentation Often outdated
  • Support GitHub only
  • Updates If maintained

/ the bottom line

An honest verdict.

Norcel

Recommended

Best for speed. Launch in days with everything configured. One-time purchase, lifetime updates, and developer support.

Get Norcel

From Scratch

Maximum control

Maximum control but months of setup time. You'll build auth, database, emails, and everything else yourself.

Open Source

Free to start

Free to start but often outdated or abandoned. Expect to debug integrations and fix broken features yourself.

* Open-source starters are free to download — factor in the 20–60 hours of integration work before "free" feels free.

Limited launch offer

$49 LAUNCH SALE FIRST 100 BUYERS.

We're launching Norcel to the first 100 founders at a special price - and we're throwing in a free UI kit to help you ship even faster.

Free gift included
for the first 50 customers
$99 value

Norcel UI Kit

A premium component library you can drop into any Next.js project. Marketing, dashboard, and auth flows - all dark-ready.

  • 40+ production-ready components
  • Marketing, dashboard, and auth flows
  • Dark mode tokens baked in
  • Drop-in for any Next.js 16 project
Offer remaining 32 / 50 left

/ code showcase

Code worth reading.

Small, curated snippets — each one a design decision that makes the whole stack safer, faster, or easier to extend.

lib / auth.ts — jwt callback TypeScript
                // lib/auth.ts — the rotation step inside the jwt callback
const iatMs = (token.iat ?? 0) * 1000;
const ttlMs = token.rememberMe
  ? REMEMBER_ME_SESSION_MS
  : DEFAULT_SESSION_MS;

if (iatMs && shouldRotateJwt(iatMs, ttlMs)) {
  // Bump iat so the cookie TTL is effectively extended.
  token.iat = Math.floor(Date.now() / 1000);
}
              
Active users get a continuously-extending session; idle users are forced back through /login at the TTL.

/ screenshots

A real look at what ships.

Four real screens from the Norcel template — every one is a route you can run locally in under five minutes.

norcel.dev / /
Norcel marketing landing page
Norcel marketing landing page
features /02
Norcel features module
/02 Features

Every module on one page — auth, sessions, RBAC, design system.

Norcel features module
production-grade /03
Norcel production-grade module
/03 Production-grade

Everything wired up — sessions, RBAC, audit log, billing-ready data.

Norcel production-grade module
admin panel /04
Norcel admin panel
/04 Admin panel

Live user list, role management, security log out of the box.

Norcel admin panel

/ why norcel

Built for real SaaS businesses.

Enterprise Security

Built using modern authentication best practices - secure cookies, CSRF, rate limiting, verified email flows.

Production Architecture

Structured for long-term maintainability with a clear separation of routes, services, and data access.

Launch Faster

Save weeks of development time. Skip the email flows, OAuth wiring, and admin panel - it's all here.

Commercial Quality

Built to be sold, extended, and scaled. License it across your client work or your own product line.

/ trusted by

Built for builders, by builders.

The project structure is easy to understand, and I was able to customize the authentication flow without fighting the framework.
Hrishabh Shah
Software Developer
Having authentication, organizations, and RBAC already wired together would save me a significant amount of setup time on a new SaaS project.
Jhanat
Software Developer
This is the kind of starter I look for—modern tooling, sensible architecture, and fewer decisions to make before I can start building features.
Priya Subramanian
Founding Engineer

/ faq

Questions, answered.

Anything we missed? Email us at hello@norcel.dev and we'll get back fast.

  • Next.js 15 (App Router) with React 19 and TypeScript in strict mode, Auth.js v5 (NextAuth) for sessions, Prisma 5 on Supabase Postgres, Tailwind CSS v4 with a Vercel-inspired design-token system, Resend or SMTP for transactional email, and shadcn/ui primitives re-skinned to the brand. Every layer is decoupled — swap Postgres for Neon, Resend for Postmark, or extend the role model without fighting the framework.

  • Email + password with argon2id hashing, Google and GitHub OAuth, passwordless magic-link sign-in, email verification on signup, forgot/reset password, two-step email change with old sessions revoked, and a server-side session list users can revoke from /settings. Every flow is implemented as a typed server action — no hand-rolled fetch calls in the client.

  • Yes. Passwords are hashed with argon2id (memory-hard, OWASP-recommended), reset and verification tokens are stored as SHA-256 fingerprints rather than plaintext, sessions use HttpOnly + SameSite cookies with constant-time token comparison, and per-IP and per-account rate limiting is in place on sign-in, sign-up, forgot-password, and magic-link. The forgot-password and magic-link endpoints return identical responses for known and unknown emails to prevent user enumeration. A Dockerfile, GitHub Actions CI, and a typed, fail-fast env-var parser ship in the box.

  • Yes — USER, ADMIN, and SUPER_ADMIN roles seed out of the box, with requireAuth, requireAdmin, requireRole, and hasRole server guards you can call from any RSC, route handler, or server action. Edge middleware fast-fails unauthenticated traffic before the database is hit, and a full /admin panel lists users, lets you impersonate or soft-delete, and surfaces the security event log.

  • Everything. The brand tokens (colors, typography, spacing, radii, shadows) live in app/globals.css as Tailwind v4 @theme variables, so you re-skin the entire app by editing one file. The mesh-gradient hero, 100px pill CTAs, and Geist-on-canvas surfaces are utilities, not hard-coded values. Replacing the email provider, swapping Supabase for Neon or RDS, or extending the role model is a single config change rather than a refactor.

  • Yes — the complete Next.js project: every auth page, the admin panel, the Prisma schema and migrations, seed scripts, the design system, tests, the Dockerfile, and the CI workflow. Nothing is obfuscated, nothing is locked behind a runtime, and nothing phones home. You can read, modify, and self-host it.

  • Google and GitHub OAuth are wired in by default — drop the client IDs and secrets into .env and they work. Magic-link sign-in via Resend (or the SMTP or console provider) is included for passwordless flows. Adding more providers (Discord, Apple, etc.) is a single config entry; SAML is a larger integration and is on the roadmap.

  • Yes. The license is a standard commercial SaaS starter license — build and sell as many products as you like, including client work. See the /license page for the binding terms and a plain-language summary.

  • Phase 1 (this release) is the authentication, authorization, admin, and design-system module. The v1.1 backlog covers the enterprise-leaning additions buyers ask for: TOTP / WebAuthn two-factor authentication, OAuth-token encryption at rest, GDPR hard-delete, multi-tenant organizations with team invitations, a public REST or tRPC API, and a Sentry integration. Future modules such as billing and audit-log exports are planned for the 1.x line.

  • Security headers (CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy) are set in middleware. Accounts lock for 15 minutes after 5 failed sign-ins in a 15-minute window with exponential backoff on repeat lockouts. A SecurityEvent log records every sign-in, sign-out, password change, email change, and lockout for your admin audit trail. Accounts can be soft-deleted and restored by a super-admin, and the v1.1 release adds a GDPR-compliant hard-delete path.

  • Issues, setup questions, and bug reports are handled through the project repository. Because the product is source code that is yours the moment you download it, sales are final once the repository has been cloned. See the /license page for the full terms.

/ ship it

Launch your SaaS faster.

Skip weeks of authentication development and start building your product today.

Instant access · Lifetime updates · Commercial license