Three Cloudflare Workers define the product shape
React Starter Kit deploys 3 Cloudflare Workers: an Astro marketing site, a React 19 application, and a Hono plus tRPC API. The web worker routes application and API traffic through service bindings. Drizzle connects the API to PostgreSQL through Cloudflare Hyperdrive, while Better Auth covers email codes, passkeys, Google sign-in, and organizations. Stripe billing is present but optional. This is a specific SaaS architecture, not a neutral collection of React defaults.
That specificity is useful when it matches your plan. Types flow through Drizzle, tRPC, and the React client, so an API contract is not copied between packages. TanStack Router and Query handle navigation and server state, Jotai covers shared client state, and Tailwind CSS 4 plus shadcn/ui supplies the interface layer. A team otherwise choosing these pieces gets a coherent starting point instead of a week of wiring.
A 322-file template still installs 1,167 packages
The checkout was only 1.4 MB, with 322 files and about 9,710 lines of source. It still expanded to 1,675 MB after Bun installed 1,167 packages. That is a large local footprint for a starter, though far smaller in source scope than an established application. The cost buys four apps, shared packages, database code, Terraform, documentation, and scripts that build or deploy the parts in order.
Bun 1.4 or newer is the documented runtime and package manager. The root scripts use workspace filters for the email templates, Astro site, API, and React app. There is no root Dockerfile in our scan, and the README leads with Bun plus Cloudflare rather than a container deployment. Teams standardized on Node package managers or Docker should count conversion work before they adopt the template.
What happened when we ran it
Our sandbox installed commit dbdb0d4 in 35 seconds, built it in 18 seconds, and completed the test command in another 18 seconds. Vitest reported 93 passed and 0 failed out of 93. The unprivileged Debian container had 3 CPUs, 8 GB of RAM, Node 22 as the base image, and no secrets. Bun handled the repository commands, and every measured step finished successfully.
The run proves the source tree can install, compile, and pass its available automated checks in a clean container. It does not prove that a production Worker can reach your database, deliver an email, finish an OAuth exchange, or process a Stripe webhook. Our scan found 4 CI workflow files and no top-level tests directory; the 93 passing tests live inside the workspace rather than in one root tests folder.
Two required secrets are only the start of production setup
The API Worker refuses deployment without BETTER_AUTH_SECRET and RESEND_API_KEY. Email sign-in also needs RESEND_EMAIL_FROM set to a verified domain address, because the default Resend sender only delivers to the API-key owner's inbox. Local work needs DATABASE_URL; production uses two Hyperdrive bindings, one cached and one uncached, whose IDs come from the Terraform step.
Google OAuth can remain disabled, and Stripe billing activates only when its related secrets and price IDs are supplied. That restraint is good: unused integrations do not block deployment. Cloudflare account credentials, Worker names, service bindings, database migrations, and sender verification still belong to your team. The 35-second install gets the code ready. It does not provision the services the code expects.
The merge-seed skill treats template updates as code changes
Forking a starter creates an awkward maintenance problem after your product diverges. This repository includes a merge-seed skill for Codex and Claude Code. It asks the agent to preserve local names, routes, product scope, migrations, and configuration while adopting upstream framework and dependency changes. Its verification command runs installation, type checks, lint, tests, and the build before landing an update.
The skill is careful about dirty worktrees and migration history, but it does not make conflict resolution automatic. It explicitly stops when upstream changes live-data meaning or clashes with documented product scope. That is the right boundary. Once your fork owns customer data and billing, a template update is a reviewed integration job, even when an agent prepares the branch.
A 2026 push matters more than the 2015 release tag
GitHub showed 23,688 stars, 9 open issues and pull requests combined, and a last push on October 2, 2026. That push fixed development environment variables reaching tRPC procedures. September work moved the toolchain to TypeScript 7 and Oxc, while August commits changed CI, database testing, Better Auth, and deployment scripts. The branch is active even though the latest GitHub release remains v0.4.0 from August 2015.
The stale tag means consumers should follow commits and the documented seed-merge process instead of waiting for semantic releases to describe the current template. React Starter Kit is a strong shortcut for the exact stack it contains. If three Workers, Hyperdrive, Bun, and Better Auth already appear in your architecture note, the 93 passing tests are a reassuring start. If those names would be new constraints, choose a smaller or more portable base.

