Skip to content

NestJS SaaS Packages ​

nestarc publishes independent NestJS packages for production SaaS backends. Install only the modules that solve the problem in front of you, then add the next layer when the product needs it.

Use the build-vs-buy guide to decide which backend capabilities should stay custom and which are better adopted as maintained modules.

Current scope

There are 13 SaaS backend packages under the @nestarc npm scope. Developer tools such as @nestarc/mcp-guard live under Tooling instead of this package adoption path.

Status model ​

StatusMeaning
SupportedActively maintained package with documented compatibility coverage and operating guidance.
PreviewPublished package with an evolving API or operating contract; validate it against your production requirements.
LabsExperimental or developer tooling outside the SaaS backend package lineup.

Version and status are different signals

All current packages are pre-1.0. Supported describes active maintenance and compatibility coverage; it does not promise a frozen API. Review the package changelog and migration notes before upgrading.

StepAdd this layerPackagesUse when
1SaaS API foundationtenancy, safe-response, paginationYou are building tenant-scoped HTTP APIs and want consistent response and list behavior.
2Data safetysoft-delete, idempotencyDeletes, retries, payments, imports, or external callbacks can corrupt state if handled ad hoc.
3Operational traceability and release controlaudit-log, api-keys, feature-flagTeams need traceability, scoped machine access, or controlled rollout.
4Async eventsoutbox, jobs, webhookWrites need reliable event fan-out, background work, or outbound delivery.
5Privacy and compliancedata-subjectExport, erase, retention, and legal basis workflows need consistent policy handling.
6Access controlrbacControllers and services need consistent tenant-aware authorization and resource scopes.

See the Adoption Roadmap for the detailed sequence.

Package matrix ​

Foundation ​

PackageStatusVersionSolvesStart here
@nestarc/tenancySupported0.16.1Tenant context, PostgreSQL RLS, Prisma 6/7 isolation, TEXT/UUID policies, live audits, and validated RPC restoration.You need tenant data isolation enforced below application code.
@nestarc/safe-responseSupported0.15.0Consistent API envelopes, errors, field selection, pagination, Swagger helpers.Frontend teams need predictable responses across controllers.
@nestarc/paginationSupported0.3.0Prisma 7 cursor, keyset, and offset pagination with filters, sorting, and Swagger.List endpoints are gaining custom query parsing and repeated DTOs.

Data safety ​

PackageStatusVersionSolvesStart here
@nestarc/soft-deleteSupported0.7.2Prisma 5/6/7 soft delete, relation filters, cascade, bulk restore, purge, and optional atomic audit lifecycles.Deleting records must preserve auditability and avoid accidental reads.
@nestarc/idempotencyPreview0.4.0IETF draft-07-compatible Idempotency-Key, stable fingerprinting, response/header replay, Redis/Postgres storage.Retries can duplicate payments, orders, refunds, imports, or webhook receivers.

Operations and auth ​

PackageStatusVersionSolvesStart here
@nestarc/audit-logSupported0.7.0Business events and atomic-required Prisma field changes with shared configuration, actor policy, tenant-scoped queries, and export.You need to answer who changed what, when, and from where.
@nestarc/api-keysPreview0.4.0Tenant-scoped API keys, Prisma 5/6/7 storage, request authorization, atomic rotation, IP policy, and safe management APIs.Customers or integrations need scoped machine access with enforceable origin and lifecycle policy.
@nestarc/feature-flagSupported0.5.0Prisma 7 DB-backed flags, typed evaluation, cache adapters, rollout, tenant overrides, Admin API.You want gradual rollout without external flag-service dependency.
@nestarc/rbacSupported0.2.2Typed tenant-aware roles, reconciled identities, HTTP guards, resource scopes, Prisma storage, and committed-change hooks.Controllers and services have ad hoc role checks that are starting to drift.

Async and integration ​

PackageStatusVersionSolvesStart here
@nestarc/outboxPreview0.3.0Transactional outbox, renewable fenced claims, persisted retries, tenant-scoped admin, cursor pages, and publisher delivery.Database writes and event emission must succeed or recover together.
@nestarc/jobsPreview0.4.0Typed jobs, bounded local concurrency, BullMQ roles, Redis identities, portable JSON, explicit shutdown errors, retention, and outbox publishing.You need shared job handlers across local tests and Redis-backed production workers.
@nestarc/webhookSupported0.13.1Idempotent HMAC-signed delivery, retry/replay operations, worker observability, and data retention.Your app sends events to customer endpoints.

Privacy and compliance ​

PackageStatusVersionSolvesStart here
@nestarc/data-subjectPreview0.2.0GDPR/CCPA export and erase policies, retention, anonymization, outbox fan-out.Privacy requests touch invoices, audit logs, tax records, and tenant data.

Tooling ​

ToolStatusVersionPurpose
@nestarc/mcp-guardLabs0.2.0Static scanning for MCP servers and MCP client configuration files.

Install pattern ​

Each package can be installed by name:

bash
npm install @nestarc/tenancy

Replace tenancy with the package you want to adopt. Package-specific peer dependencies and setup steps are listed in each package's Installation page.

Released under the MIT License.