fullstack-nhost-starter: The Sovereign BaaS: Architecting for AI Autonomy with Nhost and Spring Boot
How galando/fullstack-nhost-starter uses Java 24 and strict AI guardrails to break the Backend-as-a-Service lock-in.

Creating a project on Nhost automatically sets up and deploys a Hasura instance which gives us a PostgreSQL database and GraphQL APIs. On top of this, you also get authentication (with social providers), storage, and serverless functions right out of the box.
- The repository uses a structured PIV-METHODOLOGY in the .claude directory to enforce strict architectural guardrails on AI agents.
- A hybrid architecture delegates identity management to Nhost while keeping core business logic in a decoupled Spring Boot backend.
- The system maintains a stateless connection between services by verifying Nhost JWTs via a public JSON Web Key Set endpoint.
- The stack leverages Java 24 virtual threads and React 19 to combine enterprise-grade concurrency with modern frontend performance.
The Ghost in the Repository
Most boilerplate repositories are just collections of configuration files and generic routing logic. The galando/fullstack-nhost-starter project reveals its true nature not in its source code, but in a hidden directory: .claude/. This folder contains a highly structured "PIV-METHODOLOGY" (Plan, Implement, Validate) designed specifically to govern how an AI agent interacts with the codebase.
By providing explicit "skills" to an LLM, the repository enforces strict Test-Driven Development (TDD) and architectural consistency. It is not just a template for human developers; it is a set of cognitive rails built to allow AI agents to maintain and evolve the project autonomously without degrading the architecture over time.
The Sovereign Hybrid
The architecture makes a deliberate, contrarian choice. While the industry debates whether to use a pure Backend-as-a-Service (BaaS) like Supabase or build a custom backend from scratch, this starter does both. It uses Nhost strictly for the high-risk "scary parts" of web development: Identity, OAuth, and JWT issuance.
Instead of relying on Nhost's built-in Hasura GraphQL engine for business logic, the template routes authenticated requests to a custom Java 24 Spring Boot backend. This creates a "Sovereign" architecture. The business logic remains portable, type-safe, and running on the JVM, completely decoupled from the BaaS provider's proprietary ecosystem.
The JWT Handshake
The bridge between these two worlds is the NhostJwtValidator.java class. Because the Spring Boot backend is completely stateless, it must independently verify that the tokens attached to incoming requests were actually signed by Nhost.
It achieves this by fetching public keys from Nhost's JSON Web Key Set (JWKS) endpoint. The backend caches these keys, allowing it to mathematically verify the identity of the user on every request without maintaining a session or requiring a shared secret.
public Claims validateToken(String token) {
return Jwts.parser()
.keyLocator(keyLocator)
.build()
.parseSignedClaims(token)
.getPayload();
}
Living on the Edge
The stack choices reflect an aggressive pursuit of performance and developer experience. By utilizing Java 24, the backend can leverage Virtual Threads for massive concurrency with minimal overhead. On the frontend, React 19 and Vite 7 provide the latest rendering optimizations.
Choosing Your Constraints
This architecture is not for every team. It requires managing both a Node.js frontend ecosystem and a full JVM backend. However, for organizations that want the rapid prototyping speed of a BaaS but refuse to compromise on the long-term maintainability of their core domain logic, it presents a compelling middle path.
| Feature | Pure BaaS (Supabase/Firebase) | Manual Stack (Express/Prisma) | The Hybrid (Nhost + Spring Boot) |
|---|---|---|---|
| Identity Management | Managed by Provider | Fully Custom (High Effort) | Managed by Nhost |
| Business Logic | Cloud Functions / RLS | Custom Server | Java 24 Spring Boot |
| Portability | Low (Vendor Lock-in) | High | High (Logic is decoupled) |
| AI-Readiness | Varies | Varies | Native (.claude methodology) |