Back

Multi-Tenant SaaS MVP Backend — Prisma, JWT, Query-Level Tenant Isolation

codingPrompt

Turns a one-line product idea into a production-grade backend scaffold: a Prisma schema with Tenant, User, Membership and a tenant-scoped domain model; JWT middleware that extracts tenant context per request; RBAC for Admin and Member; centralized error handling with typed exceptions. Isolation is enforced in the query layer, not the application layer. Output arrives split by file path — schema, middleware, service, controller. Replace the stack line if you are not on TypeScript and Postgres.

A
by Andrei Badulescu
0copies
gemini-3.7-flash
100%quality
Published22 Aug 2026
optimized_prompt.txt
<role>
Lead Full-Stack Cloud Architect and SaaS Engineer specializing in scalable, production-ready MVP foundations using modern TypeScript, Next.js / Node.js, and PostgreSQL.
</role>

<context>
The target system is a greenfield Multi-Tenant Software-as-a-Service (SaaS) minimum viable product (MVP). The codebase must provide a solid architectural foundation that supports rapid feature development while remaining horizontally scalable, secure, and maintainable under growing multi-tenant load.
</context>

<task>
Design and implement the core backend architecture and API scaffold for the SaaS MVP in TypeScript using Node.js/Express (or Next.js API routes) with Prisma ORM and PostgreSQL. Deliver a clean modular structure featuring multi-tenant data isolation, JWT-based authentication/authorization, scalable tenant routing, and structured API error handling.
</task>

<objective>
Create a production-grade, highly scalable SaaS MVP foundation that enforces tenant isolation at the database query level, implements secure authentication workflows, provides structured request validation, and allows independent horizontal scaling of stateless application nodes.
</objective>

<requirements>
- Language & Framework: TypeScript (strict mode enabled), Node.js, Express / Fastify or Next.js App Router.
- Database & ORM: PostgreSQL with Prisma ORM, utilizing tenant ID scoping on all user-facing domain models.
- Authentication & Multi-Tenancy: JWT verification middleware, role-based access control (RBAC: Admin, Member), and tenant context extraction per request.
- Error Handling: Centralized error handling middleware with typed domain exceptions and consistent JSON response schemas.
- Performance & Scalability: Stateless request design, database connection pooling configuration, and indexing on `tenant_id` and unique business keys.
- Exclusions: Avoid monolithic coupling, stateful in-memory sessions, hardcoded secrets, and raw unparameterized database queries.
</requirements>

<instructions>
1. Define the PostgreSQL database schema via Prisma with core SaaS models: `Tenant` (Organization), `User`, `Membership` (roles), and a core domain `Resource` model demonstrating tenant scoping.
2. Implement tenant-isolation middleware that parses authentication tokens, extracts the active `tenantId`, and injects a scoped context into the request object.
3. Write a production-ready API controller and service layer implementing CRUD operations for the scoped resource.
4. Provide structured error handling middleware and configuration for environment variables and database clients.
</instructions>

<output_format>
```typescript
// path/to/file.ts
// Skeleton and production implementation
```
Provide the core implementation split by file paths (`prisma/schema.prisma`, `src/middleware/tenant.ts`, `src/services/resource.service.ts`, `src/controllers/resource.controller.ts`).
</output_format>

<examples>
```typescript
// Tenant-scoped database query pattern
export async function getTenantResource(tenantId: string, resourceId: string) {
  return await prisma.resource.findFirstOrThrow({
    where: {
      id: resourceId,
      tenantId: tenantId, // Strict tenant isolation enforced
    },
  });
}
```
</examples>

<verification>
- [ ] Code compiles / parses without errors and follows the stated coding standards.
- [ ] Edge cases listed in <requirements> are handled (null, empty, boundary, concurrency).
- [ ] Error handling matches the contract (no silent failures, no broad catch-all).
- [ ] No new dependencies, secrets, or banned APIs introduced beyond what was authorized.
- [ ] Output answers the user's question directly without preamble
- [ ] Format matches the shape requested in <output_format>
- [ ] Length stays within the bounds stated in <requirements>
- [ ] Code parses without syntax errors and is runnable as written
</verification>

Details

Category
coding
Model
gemini-3.7-flash
Quality Score
100%

Use in Optimizer

Want to refine this prompt further? Open it directly in the optimizer and customize it for your needs.

Launch in Optimizer

More coding prompts

View all coding prompts →