Core Features

Platform administration

Understand NuxtStart's platform-wide admin role and how it differs from organization administration.

NuxtStart uses Better Auth's Admin plugin for application-wide user administration. The stored Better Auth role remains admin; NuxtStart calls a user with that role a Platform Admin.

Terminology

TermMeaning
Platform AdminA user authorized to administer the whole NuxtStart application through Better Auth's Admin plugin.
Platform AdministrationThe application-owned management area currently served under /admin/**.
Organization AdminA future, organization-scoped membership role provided by Better Auth's Organization plugin.
Platform Admin alert recipientAn email address configured to receive internal system alerts; it is not an authorization role.

Use the scoped terms in application-owned names and UI. Keep upstream Better Auth names unchanged when referring to its API or persisted values, including admin(), adminClient(), authClient.admin, and user.role === 'admin'.

Future organization support

NuxtStart does not install Better Auth's Organization plugin. Consumers can add it later and retain its built-in owner, admin, and member roles.

The two admin values do not conflict:

  • The Admin plugin stores the Platform Admin role on user.role.
  • The Organization plugin stores an Organization Admin role on a membership associated with one user and one organization.
  • Platform authority does not automatically grant organization membership or organization permissions.

Keep platform authorization and organization authorization behind their corresponding Better Auth APIs. Avoid a generic isAdmin helper because it hides which authority is being checked.

Internal alert recipients

Configure internal system-alert recipients with a comma-separated runtime variable:

NUXT_EMAIL_PLATFORM_ADMIN_EMAILS=operator@example.com,backup@example.com

Recipient configuration is independent of authentication. Adding an address does not grant the Platform Admin role, and granting the role does not subscribe an address.

The value is read when a request is served, not while the application builds. The email layer declares runtimeConfig.email.platformAdminEmails and leaves it empty, so Nitro fills it from the deployment's own environment under the name above. Supply it the way your platform supplies any other secret — a Cloudflare secret, a Railway variable, a Docker environment file. Nothing has to be present on the build machine.

The name is therefore not free. Nitro derives it from the config path, so a different variable name is not read at all, and delivery becomes a silent no-op rather than an error.

This replaces the earlier build variable PLATFORM_ADMIN_EMAILS, which was supplied as a module option. Because module options resolve while nuxt.config.ts is evaluated, the addresses were written into the server bundle as plain text and travelled inside every deployment artifact and build cache that held a copy. Rename the variable in each deployment environment before deploying code that expects it.

Development credentials

The starter's development forms retain these local-only defaults:

Email: admin@mail.com
Password: adminadmin

These values identify a convenient development login; they do not grant a role by themselves.

Copyright © 2026