Marketwright
Next.js 16 · Supabase · Cloudflare Workers

Build a marketplace where transactions actually happen.

Listings are easy. The hard part starts when someone makes an offer. Marketwright gives you the transaction layer: offers, counter-offers with turn-taking enforced in the database, acquisitions, a private deal room gated on deal state, and mutual completion.

Get it — $169 See what you get Launch price · $250 after
00001

Every marketplace kit stops at the listing

Search the market and you will find a dozen excellent SaaS boilerplates. Auth, billing, a dashboard, a settings page. Not one of them has a negotiation.

So you ship a listings grid in a weekend, and then spend three months on the part nobody wrote for you: what happens when a buyer offers less than the asking price, the seller counters, and both of them need to see the same numbers, in the right order, without either one editing the deal from underneath the other.

That is the part this kit is. It suits any marketplace where a deal is negotiated rather than checked out: business and asset brokerage, equipment, domains, high-value resale.

00002

The transaction layer

Each of these is enforced in Postgres, not just in the UI, because a marketplace where the rules live only in React is a marketplace with a REST API that ignores them.

Offers and counter-offers

Turn-taking is a column, not a convention. waiting_on decides whose move it is, so neither side can counter twice in a row or accept a stale number.

Acquisitions

An accepted offer creates a deal and moves the listing to under_offer. Leaving that state while a deal is live is refused, which is what stops two concurrent acquisitions on one listing.

Deal rooms

Confidential documents, readable only through an active acquisition. An uninvolved buyer gets nothing, and the check is a storage policy, not a hidden button.

Mutual completion

Both parties confirm the transfer happened. On the second confirmation ownership is recorded and the listing freezes, permanently.

Moderation that works

Reports reach a queue with the listing and reporter named. Removal is one transaction, and the seller cannot quietly re-publish what a moderator took down.

Deletion and consent

A real account-deletion state machine with a cancellation window, and version-tracked consent. The parts nobody writes speculatively.

The Marketwright marketplace grid showing six listings with cover images, asking prices and business models.
The public marketplace. Filters, search and listing cards.
A deal room showing an active acquisition at $82,000, two due-diligence PDFs, and a mutual completion panel where neither party has confirmed yet.
A live deal: agreed price, due-diligence documents, and the two-sided completion panel.
The admin moderation queue showing one open report against a listing, with the reporter named and remove, keep and dismiss controls.
The moderation queue. Every report names its listing and its reporter.
TRY IT

Click through it before you buy

A live copy, seeded with a full marketplace: six listings, an open negotiation, an active deal with real documents in the data room, a completed sale, and a report waiting in the moderation queue.

Sign in as any of the accounts below. It resets every night, and the handful of actions that would break it for the next visitor are switched off — everything else works.

Demo sign-ins

  • maya@example.com · password123 — a seller with listings
  • priya@example.com · password123 — a buyer mid-negotiation
Open the demo
00003

How you know it works

npm run verify:flows runs a behavioural suite against a live local stack. It signs in as ordinary users and calls the same RPCs the app calls. It is not a unit-test suite, it exercises boundaries: an uninvolved buyer cannot read a data room, an anonymous visitor cannot create an offer, a sold listing cannot be re-published.

Every fix in this repository has an assertion that fails without it. Several of those assertions exist because the test was wrong first and passed for the wrong reason.

327
behavioural assertions against a live stack
13
migrations, written to be read in order
1
file holding every GRANT and REVOKE

The security model has one sentence at its centre: row-level security picks the row, GRANT picks the column. Postgres RLS cannot restrict columns, so column-scoped grants are what stop a user writing their own role or a seller re-publishing a sold listing. They all live in 00012_privileges.sql, on purpose, and npm run verify:schema proves the live schema still matches a committed fingerprint.

The migration comments document real vulnerabilities that were found and closed, with the reasoning intact. You are buying the arguments as well as the code.

00004

What this is not

You are about to spend real money on code you have not read. Here is the part most landing pages leave out.

Not included, and deliberately so

  • Payment processing. The kit ships with early access on, which means any signed-in user has full access. Wiring Stripe or Polar is yours, and the integration points are documented.
  • Escrow. Deals complete by mutual confirmation that the transfer happened off-platform. Holding other people's money is a regulated business and not something a starter kit should pretend to do.
  • Scale testing. No load testing, no browser-level testing. It has not run under traffic.
  • A guarantee. No amount of assertions makes a codebase you have not read safe to ship. Treat it as a foundation you will review and extend.
00005

The stack

00006

Pricing

One payment, one developer, perpetual licence. Use it on unlimited projects of your own, commercial ones included.

Launch price
$250 $169

One payment. No subscription, no seat count, no expiry. The price returns to $250 when launch week ends.

Get Marketwright — $169
  • Complete source, delivered as a download
  • Unlimited projects, commercial and client work
  • Perpetual licence, one developer
  • Full refund within three days, no questions
00007

Questions

What exactly do I receive?
A zip of the complete source: the Next.js application, thirteen Postgres migrations, Edge Functions, the seed script, the behavioural suite and the documentation. No git history, so nothing of mine comes with it.
Can I use it for client work?
Yes, for unlimited projects you own or build for clients. What you cannot do is redistribute the kit itself, or sell it on as a template.
Is it really just a marketplace for buying businesses?
That is where it was extracted from, and the seed data reflects it. The transaction layer is generic: anywhere a buyer and seller negotiate a price and hand something over, the same offers, counters, deal rooms and completion flow apply. Product identity is a placeholder you replace.
How long until I have it running?
Under half an hour locally: install, start Supabase, fill in five environment variables, seed, run. The setup was tested by unpacking the archive on a clean machine and following the README as a stranger would.
Do I get updates?
The licence is perpetual, so what you buy keeps working. Updates and support are separate from the licence and may be time-limited.
What if it is not what I expected?
Full refund within three days, no questions asked. Email me from the address you bought with. After that, if the kit is materially not as described on this page, contact me whenever you find out and I will make it right.