Every SaaS I've ever started began the same way: two weeks of login screens, password resets, CRUD endpoints, and permission checks — before writing a single line of the actual product. So I finally packaged my starter into a kit. Here's a walkthrough of the decisions inside it, with real code.
Why this stack
Django REST Framework on the backend, Vue 3 on the frontend. Not Next.js, not a full SPA build pipeline. The reasoning is boring on purpose: DRF is the fastest way to ship a correct API, and Vue via CDN means the frontend is one HTML file with zero build step. You can read the entire frontend in ten minutes.
Email as the username
Django's default username field is a relic for SaaS. Every project I start, I replace it with email on day one — so the kit does it from the start:
class User(AbstractUser):
username = None
email = models.EmailField("email address", unique=True)
full_name = models.CharField("full name", max_length=150, blank=True)
USERNAME_FIELD = "email"
REQUIRED_FIELDS = ["full_name"]
objects = UserManager()
Do this on day one or you'll be migrating it on day ninety — I've done both, day one is better.
Token auth, not sessions
For a decoupled frontend talking to an API, DRF token auth is the pragmatic choice: the frontend stores the token, sends it as Authorization: Token <key>, no CSRF dance, no session store to scale. For v1 of a SaaS it's the fewest moving parts that are still correct.
The pattern that actually matters: per-user permissions
Every model gets an owner foreign key to the user, and every viewset filters to request.user:
class ProjectViewSet(viewsets.ModelViewSet):
serializer_class = ProjectSerializer
permission_classes = [IsAuthenticated]
def get_queryset(self):
return Project.objects.filter(owner=self.request.user)
def perform_create(self, serializer):
serializer.save(owner=self.request.user)
get_queryset filters so a user can never even see another user's objects; perform_create stamps ownership server-side so a malicious client can't claim someone else's records. Copy these two methods for every multi-tenant model. Sixteen passing tests cover the isolation, so you can refactor with confidence.
The Vue 3 frontend: one file, zero build
The whole frontend is a single index.html with Vue 3 from a CDN: login/signup screens and a notes dashboard. No Vite, no build step. For an MVP dashboard, that's the right trade — when you outgrow it, the API is already decoupled.
What's NOT in v1 (honest scope)
No Stripe. No teams/organizations. No async. SQLite by default (Postgres-ready). V1 is the foundation every SaaS needs — auth, API, permissions, frontend, tests.
The kit
I packaged all of this as DjangoVue Launchpad: $29 one-time, unlimited projects, 30-day refund. https://rahatalikhan.gumroad.com/l/djangovue-launchpad
Top comments (0)