Production-ready project skeleton generator for 27 frameworks — one command scaffolds a runnable app with health checks, Docker, and (optionally) a full authentication layer with RBAC.
- 27 frameworks across backend, frontend, fullstack, and mobile
- Latest stable versions (2026) for every stack
- Optional auth — bare skeleton by default,
--authadds register/login, refresh-token rotation, logout, RBAC, and users CRUD - Batteries included — Docker + docker-compose,
.env.example,.gitignore, README, and password hashing per stack - Zero dependencies — pure Bash
| Framework | Stack |
|---|---|
| go | Go 1.25+, Fiber v3, GORM, PostgreSQL, Redis, Zap, Viper, JWT |
| gin | Gin, Go 1.25, GORM, PostgreSQL, JWT, Zap, Viper |
| laravel | Laravel 13, PHP 8.3+, Sanctum, Spatie, Pest, PostgreSQL |
| rails | Rails 8, Ruby 3.3, API-only, PostgreSQL, JWT, bcrypt |
| springboot | Spring Boot 4.1, Java 21, Spring Security, JPA, PostgreSQL, JWT |
| aspnet | ASP.NET Core, .NET 9, EF Core, PostgreSQL, JWT, BCrypt |
| fastapi | FastAPI, Python 3.13, SQLAlchemy 2, Alembic, Pydantic v2, JWT |
| flask | Flask 3, Python 3.13, SQLAlchemy 2, Flask-Migrate, JWT, bcrypt |
| django | Django 6.0, DRF, SimpleJWT, Python 3.13, PostgreSQL |
| axum | Axum 0.8, Rust 2024, Tokio, SQLx, PostgreSQL, argon2, JWT |
| actix | Actix-web 4, Rust 2024, Tokio, SQLx, PostgreSQL, argon2, JWT |
| hono | Hono v4, Node 24, Drizzle ORM, PostgreSQL, Zod, JWT |
| express | Express 5, Node 24, TypeScript, Drizzle ORM, PostgreSQL, Zod, JWT |
| nestjs | NestJS 11, Node 24, TypeORM, PostgreSQL, JWT, class-validator |
| adonisjs | AdonisJS 7, Lucid ORM, VineJS, PostgreSQL, Redis |
| elysia | Elysia 1, Bun, Drizzle ORM, PostgreSQL, JWT, Bun.password |
| nextjs | Next.js 16, React 19, Prisma, NextAuth v5, Tailwind v4 |
| nuxt | Nuxt 4, Vue 3.5, Nitro, Drizzle ORM, PostgreSQL, Zod, Tailwind v4 |
| sveltekit | SvelteKit 2, Svelte 5, Drizzle ORM, PostgreSQL, Zod, Tailwind v4 |
| react | React 19, Vite, TypeScript, TanStack Query, Zustand, Tailwind v4 |
| vue | Vue 3.5, Vite, TypeScript, Pinia, VueUse, Tailwind v4 |
| angular | Angular 22, TypeScript, standalone, signals, zoneless, RxJS |
| solid | SolidStart 1, SolidJS, Vinxi/Vite, TypeScript, file routing |
| astro | Astro 7, island architecture, content collections, Tailwind v4 |
| qwik | Qwik 1, QwikCity, resumable, Vite, TypeScript |
| expo | Expo SDK 53, React Native, Expo Router, TypeScript, secure-store |
| flutter | Flutter 3, Dart 3, go_router, Material 3, http |
Install with one command:
curl -fsSL https://raw.githubusercontent.com/zenmz/skeleton-code/main/install-remote.sh | bashOr from a clone:
git clone https://github.com/zenmz/skeleton-code.git
cd skeleton-code
./install.shThe installer is user-local (no sudo): it copies the tool to ~/.skeleton
(self-contained — safe to delete the clone afterward) and links skeleton into
~/.local/bin. If that directory isn't on your PATH, the installer prints the
exact line to add.
- Upgrade: re-run the installer.
- Uninstall:
skeleton's installer supports./install.sh --uninstall. - Custom location:
SKELETON_HOME=/opt/skeleton SKELETON_BIN=/usr/local/bin ./install.sh. - Requirements:
bash,git,sed,curl. On Windows use WSL or Git Bash.
skeleton new # interactive wizard
skeleton list # list frameworks
skeleton make <framework> --name=<name> # generate
# examples
skeleton make go --name=my-api # bare skeleton
skeleton make go --name=my-api --auth # with auth + RBAC
skeleton make nestjs --name=api --auth --install # + npm install
skeleton make react --name=web --git --ci # + git init + CIBy default make generates a bare skeleton: health check, folder structure,
DB config, Docker, .env, README — no user model, no auth. Add --auth for a
full auth layer.
| Flag | What you get |
|---|---|
(none) / --no-auth |
Bare runnable skeleton — health + structure + DB + Docker |
--auth |
Everything above plus User model, users CRUD, register/login/refresh/logout, RBAC (roles + permissions), password hashing (bcrypt/argon2/scrypt), and server-side refresh-token rotation |
Frontend/mobile targets (react, vue, angular, solid, astro, qwik, flutter) implement auth client-side (token storage + protected routes + role gating); the server remains the authority. Static-only targets treat
--authas base.
| Flag | Effect |
|---|---|
--name=<name> |
Project name (required) |
--auth / --no-auth |
Include auth (default: off) |
--git |
git init + first commit in the generated project |
--install |
Install dependencies after generating (needs the toolchain) |
--ci |
Emit a .github/workflows/ci.yml tailored to the framework |
--db (mysql/sqlite swap) is not yet implemented — every backend targets PostgreSQL.
skeleton/
├── bin/skeleton # CLI entry point
├── templates/*.sh # one generator per framework (27)
├── install.sh # user-local installer
├── install-remote.sh # one-line remote installer
├── test.sh # verification harness
├── .github/workflows/ # CI
└── README.md
Each generator is a self-contained Bash function that emits real, runnable
boilerplate via heredocs. test.sh generates every framework in both auth modes
and syntax-checks the output; CI runs it on every push.
MIT — see LICENSE.