Packages
54 independently installable packages. Open any package to inspect its real manifest, public entry points, dependency posture, and available demo.
Foundation
Scaffolding, tokens, interface primitives, localization, and rich text.
@braedonsaunders/appkit-avatars
Avatar parts library, composition model, and the composer — one full-body figure per subject, portraits derived by head viewport; plus AI image generation through the AI SDK provider layer.
@braedonsaunders/appkit-editor
Optional TipTap rich-text authoring for AppKit forms and documents.
@braedonsaunders/appkit-i18n
Tenant-aware locale policy and localized-content resolution for AppKit applications.
@braedonsaunders/appkit-scene
Animated character scene: characters walk, idle, and scale with depth over a configurable ground.
@braedonsaunders/appkit-tokens
The design foundation — semantic color, radius, elevation, and motion tokens. Light/dark. Tailwind v4, CSS-first.
@braedonsaunders/appkit-ui
Tokenized, animated UI primitives — the feel of the ecosystem.
@braedonsaunders/create-appkit
Create a production-ready Next.js application on the modular AppKit foundation.
Product building
Dashboards, records, forms, documents, reports, and design tools.
@braedonsaunders/appkit-analytics
App-agnostic semantic query compiler, formula evaluator, result contracts, and visualization registry.
@braedonsaunders/appkit-customization
Production form, custom-field, saved-view, and record-list runtime with React, memory, and Drizzle adapters.
@braedonsaunders/appkit-dashboard
Optional dashboard layouts, insight cards, visual studio, and feature-owned persistence.
@braedonsaunders/appkit-design-studio
Bounded print-design document schema, renderer, and interactive Fabric editor.
@braedonsaunders/appkit-forms
Production form designer, workflow authoring bridge, and complete fill runtime for AppKit applications.
@braedonsaunders/appkit-forms-core
Framework-neutral form schemas, evaluation, validation, scoring, localization, and automation planning.
@braedonsaunders/appkit-forms-documents
Optional form document styles and generated PDF templates over the shared companion-field contract.
@braedonsaunders/appkit-forms-pdf
Composable form-summary HTML with optional PDF, template, and design-document adapters.
@braedonsaunders/appkit-office
Office-document authoring for AI agents and applications: HTML to .docx/.pdf via headless LibreOffice, plain-text precision edits inside .docx via Flat ODT, PDF concatenation via poppler, and declarative .xlsx workbooks via the optional exceljs adapter.
@braedonsaunders/appkit-pdf
Pure-JS documents, statements, templates, and hardened HTML-to-PDF rendering.
@braedonsaunders/appkit-reports
Production report studio, governed query engine, paper and statement viewers, drill-through, exports, schedules, and durable runs.
@braedonsaunders/appkit-scheduling
Project scheduling: CPM critical path, calendars, resource leveling, baselines, and the Gantt/list/board authoring surface.
@braedonsaunders/appkit-viewspec
A closed, declarative page-composition language: pages are data that names blocks and binds already-resolved fields, so a tenant- or agent-authored layout can be stored and rendered without becoming an execution surface.
Application platform
Data, identity, authorization, events, jobs, storage, and communications.
@braedonsaunders/appkit-api
Public REST API toolkit — API-key auth, idempotent writes, typed errors, and a request wrapper. Framework-neutral.
@braedonsaunders/appkit-auth
Production authentication: durable sessions, passwords, magic links, invitation grants, reset flows, React UI, and Postgres adapters.
@braedonsaunders/appkit-crypto
Sealed secrets (AES-256-GCM, HKDF-derived key) — the single implementation for tenant credentials at rest.
@braedonsaunders/appkit-db
Multi-tenant Postgres RLS engine, schema helpers, and canonical identity persistence.
@braedonsaunders/appkit-desk
Per-agent Debian microVMs under Cloud Hypervisor — headless machines with an on-demand screen, a framed vsock guest-agent protocol, leases with idle suspend and a bounded queue, and load-bearing handover masking behind consumer-supplied policy and recording ports.
@braedonsaunders/appkit-egress-proxy
Fail-closed egress chokepoint for agent sandboxes — explicit HTTP and CONNECT proxying plus transparent DNAT interception with SNI and Host sniffing, policy and audit ports, and no TLS interception.
@braedonsaunders/appkit-email-designer
Drag-and-drop email and signature designer: GrapesJS authoring surface, merge-field blocks, and an email-safe compile pipeline.
@braedonsaunders/appkit-email-render
Framework-neutral email template rendering, sanitization, delivery input normalization, and subject handling.
@braedonsaunders/appkit-emails
Email delivery — Resend, SendGrid, Mailgun, Postmark, and SMTP transports with sealed-secret config and platform→tenant policy.
@braedonsaunders/appkit-events
Audit trail (audit + diff) and a transactional outbox (recordDomainEvent) over @braedonsaunders/appkit-db.
@braedonsaunders/appkit-iam
Modular tenant IAM with roles, scoped assignments, permission overrides, audit, adapters, and production React administration.
@braedonsaunders/appkit-jobs
Production BullMQ runtime and complete reusable queue profiles for email, notifications, PDF, reports, schedules, scripts, migration, capture, and outbound work.
@braedonsaunders/appkit-mailbox
Mail engine: incremental IMAP sync + SMTP send with RFC-5322 threading, persistence-injected so the application owns the ledger, plus the three-pane operator inbox.
@braedonsaunders/appkit-notifications
Production inbox, preferences, push enrollment, tenant routing cockpit, multi-channel runtime, and optional Drizzle adapters.
@braedonsaunders/appkit-oauth
OAuth 2.1 client for connecting to MCP and other API servers — protected-resource discovery (RFC 9728), authorization-server metadata (RFC 8414), dynamic client registration (RFC 7591), PKCE, code exchange, and refresh, over hardened public-HTTPS egress.
@braedonsaunders/appkit-process-sandbox
Fail-closed Linux process isolation plus supervised execution, bounded replay, reattachment, cancellation, network policy, and resource ceilings.
@braedonsaunders/appkit-remote-sessions
Provider-neutral remote computer and terminal sessions with fenced leases, one-time viewer grants, append-only events, observable control, and executable provider conformance.
@braedonsaunders/appkit-sms
SMS delivery — five providers (Twilio, Vonage, MessageBird, Plivo, Telnyx) via fetch, sealed-secret config, platform→tenant policy.
@braedonsaunders/appkit-storage
Tenant-safe S3-compatible storage with multipart upload, streaming, ranges, promotion, lifecycle policy, and presigned access.
@braedonsaunders/appkit-superadmin
Instance-operator administration over the platform identity: manage the users who can sign in, their credentials, and active sessions, with guard rails and production React components.
@braedonsaunders/appkit-telephony
Carrier telephony — buy phone numbers and provision the SIP trunk they arrive on, via fetch, with sealed-secret config and an injectable carrier adapter.
@braedonsaunders/appkit-tenant
Request context, tenant-bound DB helper, and RBAC (permissions, roles, super-admin) on top of @braedonsaunders/appkit-db.
@braedonsaunders/appkit-voice
Voice layer seam: per-agent voice config types, speech-provider catalogs and key verification (Deepgram, ElevenLabs, OpenAI Realtime, Gemini Live), and LiveKit access-token minting — credentials injected, never env.
Automation and extensions
AI, governed code, installable apps, workflows, integrations, and sync.
@braedonsaunders/appkit-agent-tools
Governed catalogue, install lifecycle, and sandboxed execution of managed command-line tools for agents, with separate install and execution approval gates.
@braedonsaunders/appkit-ai
App-agnostic bounded agent loop and streaming assistant interface, with provider policy supplied by the host app.
@braedonsaunders/appkit-apps
Installable application bundles with immutable versions, governed QuickJS backends, opaque-origin frontends, capabilities, authoring, and distribution.
@braedonsaunders/appkit-endpoints
Programmable endpoints — run user-defined handler(request) scripts in a QuickJS sandbox with a governance budget and injected host adapters.
@braedonsaunders/appkit-integrations
Production outbound automation with authoring UI, durable publication, retry ledgers, and optional HTTP, chat, Sheets, email, SQL, and Drizzle adapters.
@braedonsaunders/appkit-mcp
Expose an app's governed tool catalogue over the Model Context Protocol — framework-neutral streamable-HTTP handling, request-boundary validation, gated tool registration with audit hooks, and static resources.
@braedonsaunders/appkit-query-console
A governed raw-SQL workbench with schema discovery, snippets, history, sortable results, CSV export, and host-owned execution.
@braedonsaunders/appkit-sandbox
Governed QuickJS isolation for user-authored JavaScript with async host capabilities, execution budgets, and structured faults.
@braedonsaunders/appkit-scripts
Governed event, scheduled, endpoint, bulk, and client scripting with QuickJS isolation, audit history, and optional React and Drizzle adapters.
@braedonsaunders/appkit-sync
Production data synchronization with transactional batches, per-record ledgers, fail-closed snapshots, connector families, and durable cursors.
@braedonsaunders/appkit-workflows
Durable workflow graphs, replay-safe actions, approval gates, and optional React and Drizzle adapters.