Skip the scaffolding, keep the repository.
Master writes the parts you would rather not: the CRUD, the auth wiring, the admin screen, the migration. You keep the review, the architecture and the code.
A layout your team would have chosen anyway.
Conventional structure, typed boundaries, no generated spaghetti. Clone it and run it locally with the tooling you already use.
Server code stays on the server.
Typed server functions validate their input, read secrets at call time and never leak into the client bundle. Webhooks live in explicit HTTP routes.
export const createCheckout = createServerFn({ method: 'POST' })
.inputValidator((d) => z.object({ priceId: z.string() }).parse(d))
.handler(async ({ data }) => {
const key = process.env['STRIPE_SECRET_KEY']!;
return startCheckout(data.priceId, key);
});What makes it safe to adopt.
Two-way GitHub
Push from Master, pull from your IDE. It is your repository, with normal commits.
A stack you already know
React, TypeScript, Vite, Tailwind and Postgres — no proprietary runtime to learn or escape.
Migrations, not magic
Schema changes are SQL migration files you can review in a pull request.
Server functions
Typed RPC for app logic and HTTP routes for webhooks, with secrets kept server-side.
Security review built in
A scanner flags missing policies, exposed data and weak access rules before you publish.
Integrations and MCP
Connect external services, or drive Master itself from your own agent over MCP.
Not a replacement for your team — a replacement for the boring half.
Drive Master from your own tooling.
Frequently asked.
Is the output code we would accept in review?+
It is idiomatic React and TypeScript with a conventional layout, typed boundaries and SQL migrations. You review it like any other contribution.
Can we keep working in our IDE?+
Yes. Connect GitHub and work in both directions — Master picks up your commits and you pick up its.
How are secrets handled?+
They are stored encrypted and read on the server at call time. Nothing sensitive is bundled into the client.
What runs the backend?+
Postgres with row-level security, plus server functions on an edge runtime. Standard pieces you can operate yourself.


