Codapult gives you a complete foundation for building and operating a production SaaS. This overview connects the major capabilities with their built-in verification and the configuration choices that shape each deployment.
Every capability is implemented in the source, covered by the appropriate automated checks, and designed to move from local development to production with the providers and policies that fit your product.
| Capability | Included foundation | Verification | Production path | Best fit |
|---|---|---|---|---|
| Core SaaS foundation | Auth, organizations, permissions, admin, settings, notifications, audit, i18n, and onboarding | Unit, integration, and E2E coverage | Ready for production deployment | Every Codapult product |
| Authentication | Better-Auth and Kinde adapters with password, OAuth, magic links, passkeys, and 2FA paths | Auth route and adapter tests | Select a provider and configure credentials and callbacks | Public SaaS and enterprise products |
| Billing | Stripe, LemonSqueezy, and Polar adapters with checkout, subscriptions, webhooks, idempotency, and customer billing flows | Adapter, webhook, and billing lifecycle tests | Configure signed webhooks and complete provider acceptance checks | Paid SaaS products |
| Organizations and permissions | Multi-tenant organizations, roles, invitations, membership, and scoped access | Isolation, permission, and route tests | Ready for organization-based products with product-specific policy | B2B and team SaaS |
| Enterprise identity | SAML SSO and SCIM provisioning through the enterprise identity surface | Route, adapter, lifecycle, and rate-limit tests | Connect the customer's identity provider and verify the target organization | Enterprise deployments |
| AI foundation | Shared gateway for chat, agents, tools, batch, RAG, metering, guardrails, routing, retries, and cost controls | Unit, integration, and evaluation coverage | Configure model providers, quotas, policies, and operational limits | AI-enabled products |
| Agents, tools, batch, and RAG | Tool permissions, prompt versioning, embeddings, vector storage, streaming, cancellation, and audit context | Module tests and runtime evaluations | Choose providers and define product-specific evaluations | AI workflows and automation |
| Storage | Local, S3, and R2 adapters with upload and object lifecycle integration | Adapter and route tests | Use durable object storage and configure lifecycle policy for production | Products with user-generated files |
| Background jobs | In-memory and BullMQ/Redis adapters with retries and worker boundaries | Adapter and job lifecycle tests | Use BullMQ/Redis for durable retries and multi-instance workers | Async workflows and scheduled work |
| MCP project integration | Project context, environment, database, generation, deployment, and verification tools | MCP surface and contract tests | Connect the CLI to the AI client used by the team | AI-assisted development |
| Guard architecture verification | Discovery, approved policy, impact evidence, changed-code verification, baselines, contracts, waivers, and CI integration | Guard fixtures, unit tests, and golden-path tests | Configure project policy and add the CI gate that fits the repository | Teams using AI coding agents |
| Vector storage | SQLite and memory adapters behind the vector-store boundary | Integration tests | Use SQLite for bounded deployments and select a durable strategy for larger workloads | RAG and semantic search |
How to read this overview
- Included foundation shows the product capability already present in the source.
- Verification shows the evidence available in the automated test and evaluation layers.
- Production path describes the configuration step that turns the capability into a deployment-ready part of your product.
- Best fit helps you choose the capabilities that support your first valuable workflow.
Use this overview with the Provider Matrix, Choosing Modules, E2E Evidence, and Production Readiness.