A production-ready ColdBox HMVC starter for the BoxLang language - authentication, SSO, RBAC permissions, API tokens, rate limiting, an Alpine-powered admin panel, and a real test suite, so you spend day one building features instead of scaffolding.
- Auth & RBAC, Batteries Included - Session auth via cbauth,
@securedhandler annotations, CSRF rotation, JWT support, and aresource:actionpermission model with roles and permissions admin screens. - Single Sign-On - cbSSO with a shipped Google OAuth provider (More included), account linking, auto-provisioning by allowed email domain, and full audit trail integration.
- Passkeys / WebAuthn - Passwordless sign-in backed by
cbsecurity-passkeys, with an optional policy that requires a passkey before a user can proceed. - Modern Template Structure - Application code lives in
app/, fully separated from the public webroot inpublic/- enhanced security by default. - Hibernate ORM + qb -
BaseEntity/BaseServiceconventions on top of cborm, migrations and seed data via cfmigrations, and qb for anything raw SQL does better. - Alpine.js + Bootstrap 5 UI - Server-rendered BXM views, small Alpine.js components, light/dark theme switching, and a Vite-compiled SCSS/JS pipeline with HMR.
- Audit Log & Rate Limiting - Every sign-in, sign-out, and authorization failure is written to a searchable audit trail; an IP-based rate limiter throttles login, registration, and password-reset abuse.
- API Tokens - Per-user, hashed personal access tokens with expiration and a scheduled purge job, ready for programmatic API access.
- Email Workflows - cbMailServices-powered templates for password reset, email verification, invitations, and welcome messages.
- A Real Test Suite - TestBox unit specs for every entity and service, plus integration specs that exercise real HTTP requests.
- Production Ready - A real go-live checklist, Docker support (app + MySQL/PostgreSQL/MSSQL), and a choice of CommandBox or the BoxLang MiniServer.
Full documentation lives here:
- BoxLang 1.17+ (with
bx-cli) - Node.js 22+
- ColdBox 8.2+
- MySQL/PostgreSQL/MSSQL/SQLite/Oracle/MariaDB
Easily get started with the cbGenesis template by following these 5 steps:
Install BoxLang into your operating system using our Quick Installer or the BoxLang Version Manager (BVM). Once installed, you can proceed with adding the BoxLang-native CommandBox CLI module.
Warning: Make sure you have the BoxLang-native CommandBox CLI installed, as the regular Lucee CommandBox is not supported.
# Install CommandBox
install-bx-module bx-cli
# Install the ColdBox CLI Module
box install coldbox-cliThis installs the BoxLang-native CommandBox CLI module and the ColdBox CLI module, allowing you to use the box commands specific to BoxLang.
This template requires Vite and UI elements that require Node.js 22+ to build and run properly. So make sure you have Node.js 22+ installed on your system.
Use the coldbox-cli to scaffold a new project.
box coldbox create app name="my-app" skeleton="cbgenesis"# Install BoxLang Dependencies
box install
# Install Node.js Dependencies
npm installConfigure your database connection in the .env file and run the necessary migrations to set up the database schema.
box migrate up
box migrate seed runCBGenesis comes pre-configured with AI skills to enhance your application's capabilities. These skills are located in the .agents/skills/ directory and can be customized or extended as needed. This will be done via the coldbox-cli and the coldbox ai namespace commands:
# Discover AI Integrations
coldbox ai --help
# Update AI Integrations
coldbox ai refreshYou can update/remove your AI Agents via the coldbox ai agents commands.
box server startApache 2.0 License
You can report issues and bugs related to this project on the GitHub Issues page.
You can support the development of this project by starring the repository on GitHub, contributing to the codebase, or providing financial support through platforms like Patreon or purchasing a BoxLang license. Your support helps us maintain and improve the project for the community.