An operations hub, a portfolio site, a multimodal SaaS, two enterprise sites, a design system and an asset library — the same core underneath each.
Community
Search
Channels
# general
# models
# showcase
# help
general
Online
Free to build on. Pay only if you need us on the hook.
Building a commercial product on Nebutra costs nothing — no fee, no licence key, no registration, no copyleft. Paid tiers sell support, SLAs, indemnification, and trademark rights, never permission.
COMMUNITY
Free/ forever
Everyone. Any team size, any revenue. Closed-source commercial use included, with no registration and no attribution requirement.
Complete Next.js 16 SaaS core, all packages included
Closed-source commercial use at any team size or revenue
Full stack: Auth, Payments, Organizations, API, Email, i18n, Background Jobs, Storage & more
Marketing features: Blog, Landing page, SEO, Analytics
Public issues, Discussions, and Discord — best-effort, no response guarantee
Sailor is an opinionated Next.js + Tailwind v4 SaaS foundation with auth, billing, multi-tenancy, AI, queues, search, and email already wired up. You clone it, configure providers, and ship — typically within a week.
Founders and product engineers who want to spend their time on the differentiator — not on rebuilding the same auth/billing/tenancy plumbing for the fifth time.
Full source ships under FSL-1.1-ALv2 — free to build and ship any commercial product with it, no copyleft, no fee. The only thing the license doesn't permit is offering Sailor itself as a competing product or service, and that restriction lapses to Apache-2.0 two years after each release. Every plan includes the complete feature set (auth, billing, multi-tenancy, AI, audit); paid tiers add support SLAs, indemnification, and trademark rights, not features.
FSL-1.1-ALv2 (Functional Source License), converting irrevocably to Apache-2.0 two years after each release. Free for every use except offering Sailor itself as a competing product or service. Paid commercial tiers add support SLAs, indemnification, and trademark rights — not extra permission. Full source is included on every plan.
No. Source updates are included with every commercial license — pull from main whenever you want and rebase your fork. The paid tier is the right to use Sailor in commercial production, not the right to receive code. Each minor release ships a CHANGELOG and an upgrade guide for any breaking change.
Free customers get community Discord + GitHub Issues. Pro adds priority email with a 1-business-day response SLA. Enterprise gets a dedicated Slack channel and an onboarding engineer.
Anywhere Node 22+ runs. Sailor ships portable output — Next standalone builds and Dockerfiles — and stays agnostic about where they run; the marketing site, dashboard, gateway, and Python services all run on Docker / PM2 (we run them on Fly Machines and Aliyun ECS today, with full Kubernetes manifests under infra/iac/k8s/ for clusters). Enterprise customers also deploy inside their own VPCs.
Yes. Payments (WeChat Pay/Alipay alongside Creem), SMS (Aliyun alongside Twilio Verify), and storage (OSS alongside R2, one S3-compatible client) each keep a China-market adapter, plus Aliyun-compatible CDN and ICP-friendly domains — so the same codebase deploys cleanly inside the Great Firewall.
Next.js 16 (App Router) on React 19, TypeScript 5.9, Tailwind v4, Prisma 7 over Postgres (with pgvector + RLS), Hono for the BFF gateway, FastAPI for ML/heavy services, and a curated component library on Radix, Nebutra UI primitives, and the shared Motion layer. AI features go through the Vercel AI SDK with provider portability (OpenAI / OpenRouter / SiliconFlow / Azure / local).
Sailor is 10 apps + 104 shared packages under packages/*/* + 4 backend lanes (Hono gateway, FastAPI/Python, Go, Rust) — far past the point where a single Next.js mega-app stays maintainable. Turborepo gives us affected-only builds, transparent remote caching, and a single source of truth for shared design tokens, auth, billing, and observability — without forcing every team into the same Next.js process.
Two layers. Request-scoped tenant context via @nebutra/tenant (AsyncLocalStorage propagates the active org through every server call, including DB queries and outbound webhooks), and database-enforced isolation via Postgres Row-Level Security policies (packages/platform/db/prisma/generated/rls.sql) bound to a session-local app.current_tenant_id. Service-role connections bypass RLS only inside trusted internal services; all user-facing routes go through the tenant-scoped client.
Better Auth is the only auth backend Sailor ships — it is what production runs, so it is the one that is tested, documented, and kept current. There is no Clerk, NextAuth, or Supabase Auth adapter to flip between anymore; @nebutra/auth still exposes a single interface (session, React hooks, middleware), so if you need a different provider you implement one adapter (~80 LOC) behind it instead of picking one off a list.
Each integration (auth, queue, search, email, payments, storage, billing) still sits behind its own interface, but the shipped adapter is the one Nebutra runs in production — Better Auth, QStash, Postgres, Resend, Creem. Payments, SMS, and storage keep a second adapter (WeChat Pay/Alipay, Aliyun, OSS) only where mainland China needs it. Bringing your own means implementing that interface yourself; nothing in application code couples to a specific provider.
Application-layer envelope encryption for secrets (@nebutra/vault), Postgres RLS for tenant isolation, RBAC/ABAC via CASL (@nebutra/permissions), HMAC-signed inter-service tokens, signed outbound webhooks, and a SOC 2-aligned audit pipeline (@nebutra/audit) included in every plan. Pro and Enterprise add SOC 2 attestation support, dedicated incident response, and longer audit-log retention.