NestJS StarterCAUTION
Production-ready NestJS boilerplate — JWT auth, Prisma, Redis, BullMQ, Swagger, i18n, and full AI developer workflows (Claude Code + GitHub Copilot) with spec-driven feature scaffolding.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Clone. Configure. Ship.
Everything you need to build a production API — auth, database, cache, queues, logging, and tests — already wired together so you can focus on what makes your product different.
[](https://github.com/hmake98/nestjs-starter/actions/workflows/github-code-scanning/codeql)
[](https://opensource.org/licenses/MIT)
What's included
Auth JWT access + refresh tokens · argon2 hashing · RBAC Database PostgreSQL · Prisma 7 · pg Pool adapter (no binary engine) Cache Redis · ioredis · typed CacheService wrapper Queues BullMQ with shared Redis connection Logging Structured JSON via nestjs-pino · request correlation IDs API Docs Swagger / OpenAPI — dev and staging only i18n Multi-language support via nestjs-i18n Validation class-validator · whitelist · forbidNonWhitelisted Rate Limiting Per-route throttling via @nestjs/throttler Health /health endpoint via @nestjs/terminus Error Tracking Sentry integration for 5xx errors Testing Jest · SWC · 100% coverage enforced Code Quality ESLint · Prettier · Husky · Conventional Commits Docker Multi-stage image · hot reload in dev · minimal prod image
Getting started
Prerequisites: Node.js ≥ 20, PostgreSQL, Redis
# 1. Clone and install git clone https://github.com/hmake98/nestjs-starter.git cd nestjs-starter && npm install # 2. Configure cp .env.example .env # Fill in DATABASE_URL, REDIS_URL, and the two JWT secrets below openssl rand -base64 32 # → AUTH_ACCESS_TOKEN_SECRET openssl rand -base64 32 # → AU
50e1373846adOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add nestjs-starter --env AUTH_ACCESS_TOKEN_EXP=${AUTH_ACCESS_TOKEN_EXP} --env AUTH_ACCESS_TOKEN_SECRET=${AUTH_ACCESS_TOKEN_SECRET} --env AUTH_REFRESH_TOKEN_EXP=${AUTH_REFRESH_TOKEN_EXP} --env AUTH_REFRESH_TOKEN_SECRET=${AUTH_REFRESH_TOKEN_SECRET} -- npx -y [email protected]{
"mcpServers": {
"nestjs-starter": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"AUTH_ACCESS_TOKEN_EXP": "${AUTH_ACCESS_TOKEN_EXP}",
"AUTH_ACCESS_TOKEN_SECRET": "${AUTH_ACCESS_TOKEN_SECRET}",
"AUTH_REFRESH_TOKEN_EXP": "${AUTH_REFRESH_TOKEN_EXP}",
"AUTH_REFRESH_TOKEN_SECRET": "${AUTH_REFRESH_TOKEN_SECRET}"
}
}
}
}Exposed tools (2)
2 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
accessToken | read | Enter your access token |
refreshToken | read | Enter your refresh token |
Trust audit
CAUTIONgrade B · trust 83/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (7)
DATABASE_URL="postgresql://postgres:master123@localhost:5432/postgres?schema=public"
FIREBASE_PRIVATE_KEY="-----BEGIN PRIVATE KEY-----\n...\n-----END PRIVATE KEY-----\n"
.prettierignore
.swcrc
path: join(__dirname, '../../languages/'),
@faker-js/faker, @nestjs/bullmq, @nestjs/common, @nestjs/config, @nestjs/core, @nestjs/jwt, @nestjs/passport, @nestjs/platform-express
- JWT secrets are read via `ConfigService.getOrThrow` — never hardcoded or read from `process.env` directly
Gates applied: no_behavioural_pass.
50e1373846adfull audit observations/trust-audit/mcp-server/hmake98__nestjs-starter.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 50e1373846ad | CAUTION | B | 83 | first audit |
Questions
What is the NestJS Starter MCP server?
Production-ready NestJS boilerplate — JWT auth, Prisma, Redis, BullMQ, Swagger, i18n, and full AI developer workflows (Claude Code + GitHub Copilot) with spec-driven feature scaffolding.
What tools does NestJS Starter expose?
2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is NestJS Starter safe to connect to an agent?
With care. The audit graded it B (83/100) and found 7 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does NestJS Starter need?
It reads AUTH_ACCESS_TOKEN_EXP, AUTH_ACCESS_TOKEN_SECRET, AUTH_REFRESH_TOKEN_EXP, AUTH_REFRESH_TOKEN_SECRET and SEED_ADMIN_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (50e1373846ad), read on 2026-10-08. The repository is watched and re-audited when it changes.