Adapted from the black-candle-technologies/chitin-dashboard repository docs.
Public self-serve dashboard for Chitin tenants.
Read first: spec/public-dashboard.sped.md, spec/tech-stack-nextjs.md, spec/adr/README.md, CONTRIBUTING.md, AGENTS.md.
Ships the app foundation plus the BFF auth/session layer:
/signup and authenticated dashboard surfacesHttpOnly session cookie helpersThe dashboard home route is data-backed through the dashboard BFF (loading, empty, error, manual refresh states). Signup works through the BFF with server-owned session bootstrap and one-time API key reveal.
CHITIN_API_BASE_URL=http://localhost:8080
NEXT_PUBLIC_APP_ENV=development
Validated on the server before authenticated app routes render.
pnpm install
pnpm dev
pnpm lint
pnpm typecheck
pnpm test
pnpm test:e2e
pnpm build
pnpm verify # standard pre-merge workflow: lint + typecheck + tests + build
Public/app: /signup, /, /budgets, /settings/providers, /settings/api-keys, /settings/webhooks.
Internal BFF: /api/auth/signup, /api/auth/signout, /api/dashboard, /api/budgets/report, /api/settings/provider-keys, /api/settings/api-keys, /api/settings/webhooks/budget.
Next.js 15, React 19, strict TypeScript, Tailwind CSS, Radix UI, TanStack Query, React Hook Form, Zod, Recharts, TanStack Table, Vitest, Playwright. Recorded in spec/adr/0001-use-nextjs-bff.md. Do not change casually; major changes require an ADR (spec/adr/).
Clarity over cleverness. Explicit contracts over implicit behavior. Security over convenience. Accessibility by default. Incremental delivery over speculative architecture. Documented decisions over tribal knowledge.
A change is not ready unless: it matches (or updates) the spec and ADR set, includes appropriate tests, does not weaken security or secret handling, adds no unjustified dependencies, and is understandable without tribal knowledge.
Target: Vercel. Production env: CHITIN_API_BASE_URL, NEXT_PUBLIC_APP_ENV, SENTRY_DSN, NEXT_PUBLIC_SENTRY_DSN (plus build-time Sentry release vars). Monitoring via Sentry client/server instrumentation; page-view and API-failure telemetry on /api/telemetry.