NestJS SaaS Packages
nestarc publishes independent NestJS packages for production SaaS backends. Install only the modules that solve the problem in front of you, then add the next layer when the product needs it.
Use the build-vs-buy guide to decide which backend capabilities should stay custom and which are better adopted as maintained modules.
Current scope
There are 13 SaaS backend packages under the@nestarc npm scope. Developer tools such as @nestarc/mcp-guard live under Tooling instead of this package adoption path. Status model
| Status | Meaning |
|---|---|
| Supported | Actively maintained package with documented compatibility coverage and operating guidance. |
| Preview | Published package with an evolving API or operating contract; validate it against your production requirements. |
| Labs | Experimental or developer tooling outside the SaaS backend package lineup. |
Version and status are different signals
All current packages are pre-1.0. Supported describes active maintenance and compatibility coverage; it does not promise a frozen API. Review the package changelog and migration notes before upgrading.
Recommended adoption path
| Step | Add this layer | Packages | Use when |
|---|---|---|---|
| 1 | SaaS API foundation | tenancy, safe-response, pagination | You are building tenant-scoped HTTP APIs and want consistent response and list behavior. |
| 2 | Data safety | soft-delete, idempotency | Deletes, retries, payments, imports, or external callbacks can corrupt state if handled ad hoc. |
| 3 | Operational traceability and release control | audit-log, api-keys, feature-flag | Teams need traceability, scoped machine access, or controlled rollout. |
| 4 | Async events | outbox, jobs, webhook | Writes need reliable event fan-out, background work, or outbound delivery. |
| 5 | Privacy and compliance | data-subject | Export, erase, retention, and legal basis workflows need consistent policy handling. |
| 6 | Access control | rbac | Controllers and services need consistent tenant-aware authorization and resource scopes. |
See the Adoption Roadmap for the detailed sequence.
Package matrix
Foundation
| Package | Status | Version | Solves | Start here |
|---|---|---|---|---|
@nestarc/tenancy | Supported | 0.16.1 | Tenant context, PostgreSQL RLS, Prisma 6/7 isolation, TEXT/UUID policies, live audits, and validated RPC restoration. | You need tenant data isolation enforced below application code. |
@nestarc/safe-response | Supported | 0.15.0 | Consistent API envelopes, errors, field selection, pagination, Swagger helpers. | Frontend teams need predictable responses across controllers. |
@nestarc/pagination | Supported | 0.3.0 | Prisma 7 cursor, keyset, and offset pagination with filters, sorting, and Swagger. | List endpoints are gaining custom query parsing and repeated DTOs. |
Data safety
| Package | Status | Version | Solves | Start here |
|---|---|---|---|---|
@nestarc/soft-delete | Supported | 0.7.2 | Prisma 5/6/7 soft delete, relation filters, cascade, bulk restore, purge, and optional atomic audit lifecycles. | Deleting records must preserve auditability and avoid accidental reads. |
@nestarc/idempotency | Preview | 0.4.0 | IETF draft-07-compatible Idempotency-Key, stable fingerprinting, response/header replay, Redis/Postgres storage. | Retries can duplicate payments, orders, refunds, imports, or webhook receivers. |
Operations and auth
| Package | Status | Version | Solves | Start here |
|---|---|---|---|---|
@nestarc/audit-log | Supported | 0.7.0 | Business events and atomic-required Prisma field changes with shared configuration, actor policy, tenant-scoped queries, and export. | You need to answer who changed what, when, and from where. |
@nestarc/api-keys | Preview | 0.4.0 | Tenant-scoped API keys, Prisma 5/6/7 storage, request authorization, atomic rotation, IP policy, and safe management APIs. | Customers or integrations need scoped machine access with enforceable origin and lifecycle policy. |
@nestarc/feature-flag | Supported | 0.5.0 | Prisma 7 DB-backed flags, typed evaluation, cache adapters, rollout, tenant overrides, Admin API. | You want gradual rollout without external flag-service dependency. |
@nestarc/rbac | Supported | 0.2.2 | Typed tenant-aware roles, reconciled identities, HTTP guards, resource scopes, Prisma storage, and committed-change hooks. | Controllers and services have ad hoc role checks that are starting to drift. |
Async and integration
| Package | Status | Version | Solves | Start here |
|---|---|---|---|---|
@nestarc/outbox | Preview | 0.3.0 | Transactional outbox, renewable fenced claims, persisted retries, tenant-scoped admin, cursor pages, and publisher delivery. | Database writes and event emission must succeed or recover together. |
@nestarc/jobs | Preview | 0.4.0 | Typed jobs, bounded local concurrency, BullMQ roles, Redis identities, portable JSON, explicit shutdown errors, retention, and outbox publishing. | You need shared job handlers across local tests and Redis-backed production workers. |
@nestarc/webhook | Supported | 0.13.1 | Idempotent HMAC-signed delivery, retry/replay operations, worker observability, and data retention. | Your app sends events to customer endpoints. |
Privacy and compliance
| Package | Status | Version | Solves | Start here |
|---|---|---|---|---|
@nestarc/data-subject | Preview | 0.2.0 | GDPR/CCPA export and erase policies, retention, anonymization, outbox fan-out. | Privacy requests touch invoices, audit logs, tax records, and tenant data. |
Tooling
| Tool | Status | Version | Purpose |
|---|---|---|---|
@nestarc/mcp-guard | Labs | 0.2.0 | Static scanning for MCP servers and MCP client configuration files. |
Install pattern
Each package can be installed by name:
npm install @nestarc/tenancyReplace tenancy with the package you want to adopt. Package-specific peer dependencies and setup steps are listed in each package's Installation page.