PluginBench
Skill
Pass
Audit score 90

tanstack-start-best-practices

deckardger/tanstack-agent-skills

TanStack Start best practices for full-stack React: server functions, middleware, SSR, auth, and deployment.

What is tanstack-start-best-practices?

Comprehensive guidelines for building full-stack React applications with TanStack Start. Covers server functions, middleware, authentication, SSR, error handling, and deployment patterns. Use when architecting or implementing TanStack Start applications.

  • Defines best practices for server functions and data mutations
  • Provides security guidelines for input validation, auth middleware, and CSRF protection
  • Establishes middleware patterns for request/response handling and context flow
  • Covers authentication and session management implementation
  • Guides SSR configuration, hydration safety, and streaming patterns
  • Organizes error handling across client/server boundaries

How to install tanstack-start-best-practices

npx skills add https://github.com/deckardger/tanstack-agent-skills --skill tanstack-start-best-practices
Claude Code
Cursor
Windsurf
Cline

How to use tanstack-start-best-practices

  1. 1.Review the rule categories by priority (Critical, High, Medium, Low)
  2. 2.Consult specific rule files in the rules/ directory for your use case
  3. 3.Apply server function rules when creating data mutations
  4. 4.Implement security rules for input validation and auth middleware
  5. 5.Configure middleware for cross-cutting concerns like logging
  6. 6.Set up authentication with session management and route protection
  7. 7.Apply SSR rules when server-rendering content
  8. 8.Follow file organization patterns for maintainable code structure

Use cases

Good for
  • Setting up secure server functions for data mutations in full-stack apps
  • Implementing authentication middleware and route protection
  • Configuring SSR with proper data loading and hydration
  • Organizing code with .functions.ts pattern for server/client separation
  • Deploying TanStack Start applications to various platforms
Who it's for
  • Full-stack React developers
  • Backend engineers building APIs with TanStack Start
  • Teams implementing authentication and security patterns
  • Developers deploying to production environments

tanstack-start-best-practices FAQ

When should I use createServerFn?

Use createServerFn for server-side logic that needs to be called from the client, such as data mutations, database operations, or sensitive computations that shouldn't run in the browser.

How do I protect routes with authentication?

Use the beforeLoad hook with auth middleware to verify user sessions before rendering routes, and verify auth again in server functions for additional security.

What's the .functions.ts pattern?

The .functions.ts naming convention separates server-only code from client code, making it clear which functions run on the server and improving code organization.

How do I prevent hydration mismatches in SSR?

Ensure server and client render the same content by using consistent data loading, avoiding browser-only APIs in initial render, and properly managing state during hydration.

What environment variables should I configure for deployment?

Use environment functions to manage configuration like database URLs, API keys, and feature flags, keeping secrets server-side and only exposing necessary values to the client.

Full instructions (SKILL.md)

Source of truth, from deckardger/tanstack-agent-skills.


name: tanstack-start-best-practices description: TanStack Start best practices for full-stack React applications. Server functions, middleware, SSR, authentication, and deployment patterns. Activate when building full-stack apps with TanStack Start.

TanStack Start Best Practices

Comprehensive guidelines for implementing TanStack Start patterns in full-stack React applications. These rules cover server functions, middleware, SSR, authentication, and deployment.

When to Apply

  • Creating server functions for data mutations
  • Setting up middleware for auth/logging
  • Configuring SSR and hydration
  • Implementing authentication flows
  • Handling errors across client/server boundary
  • Organizing full-stack code
  • Deploying to various platforms

Rule Categories by Priority

PriorityCategoryRulesImpact
CRITICALServer Functions5 rulesCore data mutation patterns
CRITICALSecurity4 rulesPrevents vulnerabilities
HIGHMiddleware4 rulesRequest/response handling
HIGHAuthentication4 rulesSecure user sessions
MEDIUMAPI Routes1 ruleExternal endpoint patterns
MEDIUMSSR5 rulesServer rendering patterns
MEDIUMError Handling3 rulesGraceful failure handling
MEDIUMEnvironment1 ruleConfiguration management
LOWFile Organization3 rulesMaintainable code structure
LOWDeployment2 rulesProduction readiness

Quick Reference

Server Functions (Prefix: sf-)

  • sf-create-server-fn — Use createServerFn for server-side logic
  • sf-input-validation — Always validate server function inputs
  • sf-method-selection — Choose appropriate HTTP method
  • sf-error-handling — Handle errors in server functions
  • sf-response-headers — Customize response headers when needed

Security (Prefix: sec-)

  • sec-validate-inputs — Validate all user inputs with schemas
  • sec-auth-middleware — Protect routes with auth middleware
  • sec-sensitive-data — Keep secrets server-side only
  • sec-csrf-protection — Implement CSRF protection for mutations

Middleware (Prefix: mw-)

  • mw-request-middleware — Use request middleware for cross-cutting concerns
  • mw-function-middleware — Use function middleware for server functions
  • mw-context-flow — Properly pass context through middleware
  • mw-composability — Compose middleware effectively

Authentication (Prefix: auth-)

  • auth-session-management — Implement secure session handling
  • auth-route-protection — Protect routes with beforeLoad
  • auth-server-functions — Verify auth in server functions
  • auth-cookie-security — Configure secure cookie settings

API Routes (Prefix: api-)

  • api-routes — Create API routes for external consumers

SSR (Prefix: ssr-)

  • ssr-data-loading — Load data appropriately for SSR
  • ssr-hydration-safety — Prevent hydration mismatches
  • ssr-streaming — Implement streaming SSR for faster TTFB
  • ssr-selective — Apply selective SSR when beneficial
  • ssr-prerender — Configure static prerendering and ISR

Environment (Prefix: env-)

  • env-functions — Use environment functions for configuration

Error Handling (Prefix: err-)

  • err-server-errors — Handle server function errors
  • err-redirects — Use redirects appropriately
  • err-not-found — Handle not-found scenarios

File Organization (Prefix: file-)

  • file-separation — Separate server and client code
  • file-functions-file — Use .functions.ts pattern
  • file-shared-validation — Share validation schemas

Deployment (Prefix: deploy-)

  • deploy-env-config — Configure environment variables
  • deploy-adapters — Choose appropriate deployment adapter

How to Use

Each rule file in the rules/ directory contains:

  1. Explanation — Why this pattern matters
  2. Bad Example — Anti-pattern to avoid
  3. Good Example — Recommended implementation
  4. Context — When to apply or skip this rule

Full Reference

See individual rule files in rules/ directory for detailed guidance and code examples.