fullstack-nhost-starter: The Sovereign BaaS: Architecting for AI Autonomy with Nhost and Spring Boot

How galando/fullstack-nhost-starter uses Java 24 and strict AI guardrails to break the Backend-as-a-Service lock-in.

• View on GitHub • More from galando

A stone archway being constructed, with one half made of futuristic glass and the other of solid granite, joined by a mechanical hand placing a keystone.
Bridging the rapid iteration of a BaaS with the enterprise solidity of the JVM.

Creating a project on Nhost automatically sets up and deploys a Hasura instance which gives us a PostgreSQL database and GraphQL APIs. On top of this, you also get authentication (with social providers), storage, and serverless functions right out of the box.

Johan Eliasson, CEO of Nhost · Full-stack Next.js with Nhost and Hasura | Nhost

Key Takeaways

The Ghost in the Repository

Most boilerplate repositories are just collections of configuration files and generic routing logic. The galando/fullstack-nhost-starter project reveals its true nature not in its source code, but in a hidden directory: .claude/. This folder contains a highly structured "PIV-METHODOLOGY" (Plan, Implement, Validate) designed specifically to govern how an AI agent interacts with the codebase.

By providing explicit "skills" to an LLM, the repository enforces strict Test-Driven Development (TDD) and architectural consistency. It is not just a template for human developers; it is a set of cognitive rails built to allow AI agents to maintain and evolve the project autonomously without degrading the architecture over time.

The Sovereign Hybrid

The architecture makes a deliberate, contrarian choice. While the industry debates whether to use a pure Backend-as-a-Service (BaaS) like Supabase or build a custom backend from scratch, this starter does both. It uses Nhost strictly for the high-risk "scary parts" of web development: Identity, OAuth, and JWT issuance.

Portrait of Johan Eliasson

Instead of relying on Nhost's built-in Hasura GraphQL engine for business logic, the template routes authenticated requests to a custom Java 24 Spring Boot backend. This creates a "Sovereign" architecture. The business logic remains portable, type-safe, and running on the JVM, completely decoupled from the BaaS provider's proprietary ecosystem.

The JWT validation dance: Spring Boot acts as a stateless resource server, trusting Nhost's cryptographic signatures.

The JWT Handshake

The bridge between these two worlds is the NhostJwtValidator.java class. Because the Spring Boot backend is completely stateless, it must independently verify that the tokens attached to incoming requests were actually signed by Nhost.

It achieves this by fetching public keys from Nhost's JSON Web Key Set (JWKS) endpoint. The backend caches these keys, allowing it to mathematically verify the identity of the user on every request without maintaining a session or requiring a shared secret.

public Claims validateToken(String token) {
    return Jwts.parser()
        .keyLocator(keyLocator)
        .build()
        .parseSignedClaims(token)
        .getPayload();
}

Living on the Edge

The stack choices reflect an aggressive pursuit of performance and developer experience. By utilizing Java 24, the backend can leverage Virtual Threads for massive concurrency with minimal overhead. On the frontend, React 19 and Vite 7 provide the latest rendering optimizations.

A close-up of a mechanical hand following a weathered, handwritten blueprint to adjust a precise dial.
The .claude directory acts as a strict blueprint, ensuring AI agents maintain architectural integrity.

Choosing Your Constraints

This architecture is not for every team. It requires managing both a Node.js frontend ecosystem and a full JVM backend. However, for organizations that want the rapid prototyping speed of a BaaS but refuse to compromise on the long-term maintainability of their core domain logic, it presents a compelling middle path.

FeaturePure BaaS (Supabase/Firebase)Manual Stack (Express/Prisma)The Hybrid (Nhost + Spring Boot)
Identity ManagementManaged by ProviderFully Custom (High Effort)Managed by Nhost
Business LogicCloud Functions / RLSCustom ServerJava 24 Spring Boot
PortabilityLow (Vendor Lock-in)HighHigh (Logic is decoupled)
AI-ReadinessVariesVariesNative (.claude methodology)