The repository is a pnpm workspace run with Turborepo. Apps live in apps/, shared code in packages/, and scripts in tooling/.
apps/ web/ Next.js app: marketing site, sign-in, the app, admin, API routes native/ Expo app for iOS and Android e2e/ Playwright end-to-end tests dev-tool/ Local developer tool on port 3010 packages/ features/ accounts, auth, team-accounts, admin, notifications billing/ core, gateway, stripe, lemon-squeezy supabase/ Supabase clients, generated database types, auth helpers next/ Server action clients and the route handler wrapper ui/ Shared web UI components (@repo/ui) mobile-ui/ Shared React Native components mailers/ Nodemailer, Resend and log-only mailers email-templates/ Invitation, one-time code and account deletion emails cms/ Keystatic and WordPress content clients otp/ One-time codes for sensitive actions i18n/ analytics/ monitoring/ database-webhooks/ policies/ shared/ mcp-server/ tooling/ scripts/ Install checks, agent skill sync and check typescript/ Shared TypeScript config docs/ The full reference docs (Markdoc files)
apps/web/ app/[locale]/(marketing)/ Landing page, pricing, FAQ, blog, changelog, showcase, contact, legal pages app/[locale]/auth/ Sign-in, sign-up, password reset, two-step verification, OAuth callback app/[locale]/home/(user)/ Personal account: home, settings, billing app/[locale]/home/[account]/ Team account: home, members, settings, billing app/[locale]/admin/ Super-admin panel app/[locale]/join/ Accept a team invitation app/[locale]/docs/ These docs app/api/ Billing webhook, database webhook, healthcheck, /api/v1 for the phone app config/ App, auth, billing, feature flags, paths, navigation, demo, kit offer content/ Blog posts, docs, changelog and the showcase list i18n/messages/en/ Interface copy (English is the only language that ships) supabase/ Schemas, migrations, database tests, seed, auth email templates, live demo
app/api/v1 holds the route handlers the phone app calls (accounts, me, otp). They accept a Supabase access token in an Authorization: Bearer header, and fall back to the browser session cookie. Either way, queries run as that user, so row-level security applies.
apps/web/supabase/ schemas/ 18 SQL files, 00-privileges.sql to 17-roles-seed.sql, in dependency order migrations/ The migrations applied to every database tests/database/ 23 pgTAP test files plus the shared helper file seed.sql Local test users and data (never push it to production) templates/ Supabase Auth email templates demo/ The public live demo: sample data, guards, hourly reset, tests config.toml Local Supabase settings
See Database for what each table holds.
| File | Purpose |
|---|---|
AGENTS.md (root) | The rules every agent follows: patterns, verification steps, where to look |
16 more AGENTS.md files | Rules for one app or package, such as apps/web/supabase/AGENTS.md |
CLAUDE.md | Imports AGENTS.md for Claude Code |
.github/, .cursor/, .junie/, .agents/, .devin/, .kiro/, .clinerules/ | Pointer files that send other agents to AGENTS.md |
.agents/skills/, .claude/skills/, .cursor/skills/ | The same 49 agent skills, one copy per folder |
docs/troubleshooting/agent-known-issues.md | 17 written fixes for setup and runtime errors |
Details: Coding agents.