Looking to hire Laravel developers? Try LaraJobs

laravel-svelte-spa-starter-kit maintained by muradyanvano

Description
Laravel Svelte SPA starter kit with sv-router, Fortify, Sanctum, and passkeys — official-style UI without Inertia.
Last update
2026/09/17 23:36 (dev-main)
License
Downloads
6

Comments
comments powered by Disqus

Laravel Svelte SPA Starter Kit

tests Packagist Version Packagist Downloads PHP Version Laravel 13 License: MIT

A community Laravel starter kit with official-style UI and a true Svelte SPA — client-side routing with sv-router, cookie/session auth with Sanctum, and headless Fortifywithout Inertia.

Community / unofficial. This is not an official Laravel starter kit, not endorsed by Laravel, and not maintained by Laravel. See NOTICE.md.

Why this starter kit

Many Laravel + Svelte projects use Inertia to bridge server and client routing. This kit takes a different path: a first-party SPA that feels like Laravel's official starter kits while keeping client-side navigation in Svelte.

Laravel
  ↓
Fortify + Sanctum
  ↓
Blade SPA shell
  ↓
Svelte 5 + sv-router
  ↓
Axios

You get:

  • Familiar Laravel auth and settings flows
  • Svelte 5 with TypeScript
  • sv-router for client-side routes and guards
  • Sanctum cookie/session SPA authentication (no JWT in the browser)
  • Fortify headless auth endpoints
  • Laravel Wayfinder for typed route helpers
  • Vite + Vite Plus for dev, build, lint, and tests

Quick start

laravel new my-app --using=muradyanvano/laravel-svelte-spa-starter-kit

The Laravel Installer resolves the package from Packagist; it does not automatically pin v1.0.0 unless you specify a version constraint separately.

Pinned Composer install

composer create-project muradyanvano/laravel-svelte-spa-starter-kit my-app v1.0.0

These commands are not available until the first Packagist release. Until then, clone from GitHub (below).

Clone from GitHub (available now)

git clone https://github.com/muradyanvano/laravel-svelte-spa-starter-kit.git my-app
cd my-app
composer setup

Or step by step:

composer install
cp .env.example .env   # Windows: copy .env.example .env
php artisan key:generate
php artisan migrate
npm install
npm run build

Configure your web server (or Laravel Herd) to serve the application. For local development with hot reload:

composer run dev

Features

Authentication

  • Login
  • Registration
  • Password reset
  • Email verification
  • Password confirmation
  • Two-factor challenge (login)
  • Two-factor setup and management (TOTP)
  • Recovery codes (lazy-loaded on explicit view)
  • Logout

Passkeys / WebAuthn are not implemented in the SPA UI at this time.

Application

  • Svelte 5 SPA with sv-router client-side routing
  • Authenticated application shell with responsive sidebar
  • Collapsible sidebar (state persisted via cookie)
  • Mobile navigation
  • Dashboard
  • Profile settings (name, email, account deletion)
  • Security settings (password, two-factor authentication)
  • Appearance settings (Light / Dark / System)
  • UI built with Tailwind CSS 4 and bits-ui primitives
  • Accessible form patterns (aria-*, error associations)

Developer experience

  • TypeScript
  • Axios HTTP layer with normalized errors
  • Laravel Wayfinder (generated route/action helpers)
  • Vite 8 + Vite Plus (vp dev, vp build, vp check, vp test)
  • Pest (backend)
  • Vitest + Testing Library (frontend)
  • svelte-check
  • PHPStan (via Larastan)
  • Laravel Pint
  • Aggregate CI gate: composer ci:check

Architecture

Browser
  |
  +-- Blade SPA shell (app.blade.php)
        |
        +-- Svelte 5 (components, layouts, pages)
        +-- sv-router (client routes + guards)
        +-- Axios (http.ts)
              |
              +-- Sanctum CSRF + session cookies
              +-- Fortify auth endpoints
              +-- /api/v1/* JSON APIs
Layer Responsibility
Laravel Sessions, APIs, validation, authorization, persistence
Svelte Client routing, layouts, UI, forms, auth state consumption
Fortify Headless login, register, reset, verify, 2FA, profile/password
Sanctum First-party SPA cookie/session authentication
sv-router Client-side routing and navigation guards
Axios HTTP client, CSRF cookie, error normalization
Wayfinder Generated TypeScript helpers for Laravel routes/actions

Hard refreshes on frontend routes are served by Laravel (SpaController); in-app navigation is handled entirely by sv-router.

Auth and security

  • Sanctum first-party SPA authentication using session cookies
  • CSRF cookie fetched before mutating requests (/sanctum/csrf-cookie)
  • Auth state lives in memory via Svelte module runes — no bearer tokens in localStorage or sessionStorage
  • Laravel validation on all mutations
  • Email verification for protected routes
  • Password confirmation for sensitive settings
  • Two-factor authentication with TOTP; recovery codes fetched only when the user clicks View recovery codes

Consumer responsibility: You are responsible for HTTPS, production cookie settings, SANCTUM_STATEFUL_DOMAINS, CORS, secrets, mail configuration, authorization policies, dependency updates, infrastructure hardening, and security review of your own application code.

See SECURITY.md for vulnerability reporting.

Appearance

Three modes: Light, Dark, and System.

The selected theme persists (via cookie) and first-paint handling in the Blade shell reduces obvious theme flash on load. The Appearance settings page drives the shared theme store only — it makes no API calls.

Development

Command Description
composer run dev Laravel dev server + Vite + queue + logs (via artisan dev)
npm run dev Vite dev server only
npm run build Production frontend build
npm run check Frontend format + lint
npm run check:fix Auto-fix format/lint issues
npm run types:check Regenerate Wayfinder + svelte-check
npm run test Vitest
npm run test:watch Vitest watch mode
npm run wayfinder:generate Regenerate Wayfinder output
composer test Pint + PHPStan + Pest
composer ci:check Full frontend + backend quality gate
composer setup Install deps, env, migrate, npm install, build

Testing and quality

Backend tests use Pest. Frontend tests use Vitest with Testing Library.

Static analysis and formatting:

  • PHPStan (Larastan) — composer types:check
  • Pintcomposer lint / composer lint:check
  • svelte-checknpm run types:check
  • Vite Plus checknpm run check (format + lint)

Run everything before a PR:

composer ci:check

Production build verification:

npm run build

Wayfinder

Generated directories (gitignored — do not commit):

  • resources/js/actions
  • resources/js/routes
  • resources/js/wayfinder

Regenerate manually:

npm run wayfinder:generate

npm run types:check and npm run build also regenerate Wayfinder as configured. Fresh clones start without these directories; generation happens during type-check or build.

Laravel Boost (optional)

Laravel Boost is included as a dev dependency for optional AI-assisted development. It is not required to run, build, or test the application.

php artisan boost:install

Boost configuration (boost.json, AGENTS.md, etc.) is author-local and gitignored. Composer lifecycle scripts do not run boost:update.

Attribution

UI and developer experience were inspired by Laravel's official Svelte starter kit. This is a community reimplementation as a true SPA without Inertia.

See NOTICE.md for upstream reference and licensing details.

Requirements

Version
PHP ^8.3
Laravel ^13
Svelte ^5
Node.js 22+ (25 tested in CI)

Links

License

This project is open-sourced software licensed under the MIT License.