CBGenesis
The official ColdBox starter

Scaffold. Build.
Accelerate.

A production-ready ColdBox HMVC starter for BoxLang — authentication, Multi-Provider SSO, RBAC permissions, API tokens, rate limiting, an Alpine-powered admin panel, and a real test suite, so you spend day one building features instead of scaffolding auth.

$coldbox create app name=myApp skeleton=cbGenesis
BoxLang 1.17+ Node 22+ CommandBox 7+ ColdBox 8+
RBAC · resource:action
app.local/admin/permissions
Dashboard
Access
Users
Permissions
Audit Log

Roles & Permissions

resource:action grants, per role
Resourcevieweditadmin
users✓✓–
roles✓––
settings✓✓✓
CSRF protected by default
See it in action

Watch the walkthrough.

A guided tour of the login flow, the admin panel, and the developer experience — all in a couple of minutes.

youtube.com/watch?v=XjnZauPflq4
Request lifecycle

Browser to database, in six hops.

Browser
Router
Handler
Service
ORM / qb
View / Layout

The same request path cbGenesis's own login screen runs on — convention over ceremony, every hop.

Everything included

Day one, not sprint six.

Core workflows are wired and tested; configure production providers where your deployment requires them.

Get Started in Minutes

Install BoxLang, clone the template, run migrations, and be looking at the login screen in under ten minutes.

Modern Template Structure

Application code lives in app/, fully separated from the public webroot in public/ — enhanced security by default.

Auth & RBAC, Batteries Included

Session auth via cbauth, @secured handler annotations, CSRF rotation, JWT support, IP-based rate limiting, and a resource:action permission model.

Passkey Security & Management

WebAuthn passkey enrollment, optional required-enrollment gating, and profile tools to list and remove credentials.

User Preferences

Per-user preferences persist with the account and can be updated from the profile or managed from the admin user detail view.

Multi-Provider Single Sign-On

Google OAuth is the shipped example; cbSSO can register additional providers, with account linking and provisioning governed by cbGenesis.

Multi-Provider CBFS Storage & Avatars

Configure named cbfs disks with the storage providers your app needs. This template uses a private local assets disk for user avatars and branding-logo uploads.

BoxLang Image Library

bx-image crops and resizes avatar and logo uploads into small and large variants, ready to serve at the size each UI needs.

Email Templates & Mail Providers

Token-based account emails use cbmailservices, with file delivery in development and configurable production mail protocols such as SMTP, Postmark, or SendGrid.

BoxLang ORM + qb

BaseEntity/BaseService conventions on top of bx-orm, migrations, and qb for anything raw SQL does better.

Alpine.js + Bootstrap 5 UI

Server-rendered BXM views, sprinkled with small Alpine components, compiled by Vite with hot module reload.

A Real Test Suite

TestBox unit specs for every entity and service, plus integration specs that exercise real HTTP requests.

Easy Configuration

Environment variables for the essentials, DB-backed admin settings for everything else — no redeploy needed to change them.

Production Ready

A real go-live checklist, Docker support, and a choice of CommandBox or the BoxLang MiniServer.

Admin User Management

Invite users, manage account status, assign roles and permissions, and administer tokens and profile settings from the admin panel.

Searchable Audit Trail

Automatically record sign-ins, sign-outs, and access failures; filter and inspect activity, export CSV, and manage log retention.

Built for the age of AI

Don't make your AI agent guess your conventions.

Every serious app today gets built with an AI coding agent somewhere in the loop. Starting from a blank repo means it re-derives your auth, RBAC, and CSRF handling from scratch, every session — and sometimes gets the subtle parts wrong. cbGenesis ships those conventions as machine-readable skills an agent loads instead of guessing.

AGENTS.md, loaded automatically

Claude Code, Copilot, Cursor, and others read it before writing a line of code — structure, handlers, and conventions, up front.

6 cbGenesis-specific skills

The resource:action permission model, the CSRF frontend contract, and the exact CRUD vertical slice this app uses — not generic framework advice.

90+ framework skills, live MCP docs

BoxLang, ColdBox, TestBox, and every bundled module, plus documentation servers so an agent checks current docs instead of a training cutoff.

Same task, two agents
129,672tokens Exploration only
vs
113,995tokens Skill-assisted
12% fewer tokens 42% fewer tool calls 34% less time

Real, measured run adding an identical CRUD resource to this codebase — not a projection. Full methodology →

Already wired up

A stack you already know how to run.

No separate build system to learn — one CLI, from a fresh clone to a running server.

Works with
✓ coldbox create app name=my-app skeleton=cbgenesis
✓ migrate up --seed
✓ 7 migrations run · admin user seeded
✓ server start
Secured by convention

Built-in firewall, not an if-check.

@secured, everywhere

Every admin handler extends BaseSecureHandler and carries a @secured( "resource:action,resource:admin" ) annotation — enforced before the handler ever runs.

CSRF, deny by default

Any non-GET request must carry a valid rc.csrf token, rotated per session — no hand-rolled checks scattered through controllers.

JWT & API tokens

First-class token auth alongside sessions — issue, list, and revoke tokens straight from a user's profile.

Multi-Provider SSO via cbSSO

Local password, passkeys, and SSO all share the same cbauth session authority — account linking, provisioning, and identity rules enforced by a dedicated interceptor.

Rate limiting, by IP

A RateLimiter interceptor throttles login, registration, and password-reset attempts per IP, with a configurable max attempt count and window.

Roles · live in the admin panel
Roleusersrolessettingsaudit
Admin✓✓✓✓
Manager✓––✓
Support✓–––
Member––––
How we compare

Batteries included, on purpose.

Full-color checks are wired into cbGenesis. Muted checks mark framework or official-package support that is not included by Breeze or Devise and needs setup; crosses mean no comparable capability in the named baseline.

 
cbGenesis
Laravel + Breeze Rails + Devise
Auth + sessions out of the box ✓ ✓ ✓
RBAC permission model ✓ ✗ ✗
API tokens included ✓ ✗ ✗
Admin UI included ✓ ✗ ✗
Audit log services ✓ ✗ ✗
Passkey security & management ✓ ✗ ✗
User preferences ✓ ✗ ✗
Multi-provider SSO ✓ ✓ ✓
Avatar management workflow ✓ ✗ ✗
Multi-provider file storage ✓ ✓ ✓
Image resizing & transformations ✓ ✗ ✓
Email templates & configurable mail providers ✓ ✓ ✓
ORM + migrations ✓ ✓ ✓
Real test suite included ✓ ✓ ✓
Docker included ✓ ✓ ✗
Production go-live checklist ✓ ✗ ✗
Built on the ColdBox platform

Not a one‑off template. A whole platform.

ColdBox Modules extend the platform for app design
cbSecurity cbORM qb cbMailServices cbSSO cbFS
ColdBox
The MVC application platform — built from three core engines
WireBox Dependency Injection
CacheBox Caching
LogBox Logging
BoxLang
The modern, dynamic JVM language it all runs on
bx-orm bx-mail bx-image bx-esapi bx-mysql bx-postgresql bx-mssql bx-oracle bx-sqlite bx-derby

Language, platform, and modules — three real layers, not marketing copy. Energy flows bottom‑up: BoxLang powers ColdBox's three core engines, which app‑facing modules extend.

Free & open source

Ready to scaffold your next ColdBox app?

Clone it, run three commands, and start building on top of auth that's already done.

Need a hand building on cbGenesis?

Need Help?

Ortus Solutions builds and maintains ColdBox, and offers professional services for custom builds, migrations, and production hardening.