Imported from xano-inc/static_template (
AGENTS.md). Install upstream withnpx skills add xano-inc/static_template. Copyright stays with the author.
AGENTS.md — start here
You are editing the Xano static-hosting starter frontend: a static-only
Vite + React + TypeScript SPA that talks directly to a user's Xano backend.
There is no server tier. Read this file first, then the focused guides in docs/.
Two load-bearing rules (read these twice)
-
Call the backend through the generated hooks, not hand-rolled
fetch. Hooks are generated from the user's Swagger intosrc/services/generated/api.generated.tsand re-exported (response-typed) fromsrc/services/responses.ts. Auth (login/signup/me) goes through the hand-written modulesrc/features/auth/authApi.ts. See docs/calling-the-backend.md. -
Every dependency must already be in
package.json. There is no CLI in the editor. Your reflex to runnpm install,npx shadcn add …, or any shell command will silently do nothing. To add a shadcn component, write its source file undersrc/components/ui/. To add a library, you cannot — pick from what's already installed. See docs/build-constraints.md.
Orientation
- Stack: Vite + React + TS, React Router, Redux Toolkit (RTK Query for server
state, slices for auth/client state), Tailwind v4 (config-in-CSS, no
tailwind.config.js), shadcn (vendored source), dark mode on by default. - Entry:
src/main.tsx→src/App.tsx(routes). Protected pages live under<ProtectedRoute>inside<AppLayout>(sidebar + header). - Config: one env var points the app at the user's instance —
VITE_XANO_API_BASE.VITE_XANO_SWAGGER_URLfeeds codegen. See.env.example.
Where things live
| Concern | File |
|---|---|
| Token attach + 401→login (transport core) | src/services/baseQuery.ts |
The one RTK Query api instance |
src/services/api.ts |
| Generated hooks (do not edit) | src/services/generated/api.generated.ts |
| Response-type overlay (edit here) | src/services/responses.ts |
| Auth: storage / slice / guard / endpoints | src/features/auth/ |
| UI primitives (vendored shadcn) | src/components/ui/ |
| Form & data-table patterns | src/components/data-table.tsx, docs/patterns.md |
| Pages | src/pages/ |
How to…
- Add a page/route → docs/patterns.md
- Build a form → docs/patterns.md
- Show backend data in a table → docs/patterns.md
- Call a new backend endpoint → docs/calling-the-backend.md
- Understand auth / sessions → docs/auth.md
- Add a UI component / theme → docs/ui.md
Security
This is a static bundle shipped to the browser. Never put secrets (API
keys, DB credentials, private tokens) in the code or in any VITE_* variable —
they would be world-readable. The only credential here is the user's own auth
token, held in localStorage after they log in.
