{"repo":"mzubair481/express-boilerplate","free":true,"listed":false,"github":"https://github.com/mzubair481/express-boilerplate","clone":"git clone https://github.com/mzubair481/express-boilerplate.git","description":"Production-ready Express 5 and TypeScript API boilerplate with Drizzle ORM, PostgreSQL, secure authentication, OpenAPI, Vitest, Docker, Prometheus, and Grafana.","language":"TypeScript","stars":151,"topics":["api","argon2","authentication","biome","boilerplate","docker","drizzle-orm","express","grafana","nodejs"],"license":"MIT","category":"saas-starters-boilerplates","readme_excerpt":"Express + PostgreSQL Boilerplate A clean-slate, production-oriented API boilerplate built with Express 5, TypeScript, PostgreSQL, and Drizzle. It uses a modular monolith, feature-first folders, ports and adapters at useful boundaries, and a manual composition root. This repository does not contain a legacy compatibility layer. PostgreSQL and the committed Drizzle migrations are the source of truth. System at a glance Read architecture.md for visual request flows, dependency rules, alternatives, and architectural tradeoffs. Included - Express 5 with strict Zod request validation and stable response envelopes. - PostgreSQL 18, Drizzle ORM, and reviewed Drizzle Kit migrations. - Registration, email verification, login, password reset, user administration, and role/status changes. - Short-lived JWT access tokens. - Rotating opaque refresh tokens stored only as SHA-256 hashes, with family-level reuse detection. - A short concurrent-refresh grace window that preserves the winning rotated session. - PostgreSQL-backed password-reset and verification-email requests with retries and recipient cooldowns. - HttpOnly refresh cookies, a 12-character/four-class password policy, native asynchronous Argon2id hashing, strict CSP, clickjacking/feature-policy headers, CORS, and co-located route rate limits. - Manual constructor injection in one composition root—no decorators or service locator. - Pino structured logging with recursive secret, URL-query, and embedded SQL-parameter redaction. - Re","default_branch":null,"files":null,"tree":[],"storefront":"/r/mzubair481","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/mzubair481/express-boilerplate/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}