NestJS

Connect portable Playstack capabilities to dependency injection, guards, decorators, request context, workers, and lifecycle hooks.

Visit NestJS ↗

Supported features

Authentication

Compose credentials, magic links, sessions, passkeys, MFA, and connected-provider access without handing application identity to a framework.

Email and password · Magic links · Sessions · Split-origin browser sessions · Passkeys and MFA · OAuth connections

Accounts and tenancy

Model organizations, memberships, invitations, ownership, active-account switching, and fail-closed data scope.

Memberships and roles · Invitations · Active-account switching · Ownership transfer · Recoverable deletion

Email delivery

Render typed application email and deliver it through explicit SES, Mailgun, Postmark, Resend, SendGrid, SMTP, or capture-test providers.

Rendered application email

Events and workflows

Carry typed domain events, operation context, transactional delivery, and replay-safe processing across application boundaries.

Domain events · Event storage and replay · Background jobs and workflows

Feeds and syndication

Publish RSS, Atom, JSON Feed, sitemaps, and related discovery surfaces from portable feed contracts.

RSS, Atom, and JSON Feed

Rate limiting

Apply fail-closed limits with trustworthy subjects and explicit Redis, Prisma, or Durable Object storage.

Request limits

Analytics

Collect consent-aware application events and deliver them through explicit browser and server boundaries.

Server delivery

Connections

Authorize, encrypt, refresh, and revoke third-party credentials without moving provider APIs or product workflows into a generic abstraction.

OAuth connections · AT Protocol sessions

Devices and trusted sessions

Register application devices, manage push destinations, establish bounded trust, and revoke device-backed access from one explicit identity boundary.

Device registration and inventory · Push destinations · Trusted-device sessions

Client authentication

Authenticate browser extensions, CLIs, desktop apps, and mobile clients through system-browser authorization, PKCE, rotation, and device-aware revocation.

Authorization code with PKCE · Native and extension callbacks · Device authorization flow · Token rotation and revocation

Device pairing

Establish same-user peer trust across mobile, desktop, and extension surfaces through a versioned protocol with selectable discovery and transport profiles.

Peer trust establishment · Transport profiles

Billing and entitlements

Synchronize subscription state, project purchased access into stable grants, and enforce capabilities without scattering plan-name checks through application code.

Subscription lifecycle · Entitlement projection · Request enforcement · No-card product trials · Billing operations

API keys and audit trails

Issue scoped machine credentials, authenticate them at the server boundary, and record security-relevant actions without turning logs into policy.

API key lifecycle · Scoped machine authentication · Structured audit recording

Commerce

Compose server-authored products, one-time checkout, finite stock, immutable orders, and physical fulfillment without turning one provider into the domain model.

Catalog and quotes · One-time checkout · Refunds and reconciliation · Physical fulfillment

Notifications and delivery

Define typed notifications, resolve recipient preferences, deliver across explicit channels, and retain one provider-independent history of every send.

Typed notification definitions · In-app inbox · Multi-channel delivery · Delivery history and feedback

Audiences and subscriber lifecycle

Build waitlists, newsletters, release lists, and preference centers with explicit consent, segmentation, confirmation, and delivery boundaries.

Subscription lifecycle · Consent and preferences · Segmentation · Broadcast delivery

Content and AI

Model portable content operations and compose AI-assisted generation through explicit providers, schemas, policy, and application-owned publication workflows.

Content contracts · Structured AI generation · Content workflows

Caching

Use namespaced portable caches with typed serialization, tag invalidation, and explicit stampede-protection capabilities across Redis, Workers, and local runtimes.

Namespaced key-value caching · Stampede-protected remember · Tag invalidation

File storage

Store and retrieve application objects through explicit filesystem, S3, or R2 providers with validated keys, metadata, streaming bodies, and signed access.

Portable object storage · Signed download and upload access · Local and test storage

Search

Build product-specific search on portable query, ranking, transport, and framework contracts without coupling records to a provider.

Weighted lexical search · MiniSearch indexing · Next and Nest bindings

Webhooks

Verify provider requests from raw bytes, claim events transactionally, enqueue normalized work exactly once, and keep provider parsing outside domain handlers.

Raw-request verification · Transactional receipt claims · Provider normalization

Error handling

Carry stable application errors across server and client boundaries, report normalized failures, and retain framework-native recovery without leaking sensitive context.

Stable application errors · NestJS error boundary · Provider-independent reporting

GitHub App access

Authenticate GitHub App installations and compose application-owned repository access workflows with scoped, short-lived tokens.

Installation authentication · Repository access provisioning · Reconciliation workflows

Realtime and WebRTC

Compose authenticated realtime channels, resumable client state, WebRTC session control, and ICE or relay infrastructure without conflating events, signalling, and media.

Authenticated realtime channels · WebRTC sessions and signalling · ICE and relay coordination

Licensing

Issue signed licenses, activate device-bound seats, verify access offline, rotate refresh credentials, and revoke grants without coupling product policy to the token protocol.

Issuance and activation · Refresh and revocation · Entitlement projection

Localization

Share locale policy and message catalogs across application UI, APIs and delivery without choosing a translation vendor.

UI and API composition

Package reference

@playstack/nest-i18n

Keep module ownership visible

Every Playstack NestJS module receives an application-configured service or factory. Applications retain database clients, queues, provider SDKs, global guard placement, and shutdown order.

Compose request boundaries in order

Authentication establishes identity before account scope, authorization, rate limits, and handlers. Guards and decorators expose that order rather than hiding it in global registration.

Name infrastructure explicitly

@playstack/nest-storage registers multiple named stores with stable injection tokens. @playstack/nest-queues discovers typed handlers, registers named queues, and owns optional worker startup and shutdown. @playstack/nest-search exposes an application-configured search service through a controller boundary without choosing product records, authentication, or route policy.

These modules preserve provider-native configuration and clients. Nest owns dependency injection and lifecycle; portable Playstack packages continue to own capability contracts.

Integration and migration boundaries

Package-authored integration manifests expose module/provider, route, environment, raw-body, health and test requirements to Megamono. Generated wiring is ejectable application code, not automatically completed controllers. The optional Queuebert bridge reuses reviewed native queues; see Queuebert.

Auth now supports device authorization and transactional code issuance; account guards can use a validated request-account resolver while still rechecking membership and permissions. Account administration policies and live API-key authorization remain explicit service hooks. UI packages do not register Nest routes or global guards.

Stateless localization

nest-i18n registers a locale policy and request/recipient resolver through ordinary sync/async DI. It adds no global locale state, routes or database. Applications own authorized account preferences, headers and cache isolation.

Go

Playstack Pro tag
OriginsPricingBlogNewsletterChangelogStatusRoadmap
ContributorsCommunityIn Use ShowcaseCase StudiesPartnersSponsors
FAQsSupportContact

© 2026 Playstack. All rights reserved.

With OSS
Terms of ServicePrivacy PolicyCookie PolicyImprint

By

Commune Software