Skip to content
Slicekit

Operations

Demo environment

Run a public, self-healing demo: two seeded accounts to explore admin and user surfaces, protected from lockout and reset on a timer.

View .md
On this page

The demo environment lets anyone sign in and explore both the admin and the normal-user surface without registering. It is one shared environment that protects itself: the two seeded accounts cannot be locked out, and the database resets to a clean baseline on a timer. It ships disabled, so unless you turn it on the template behaves as if it were not there.

Everything lives in api/src/Slicekit.Core/Demo/ (a cross-cutting concern, like Permissions/ and Auditing/). The handful of wiring lines elsewhere are marked with demo:begin / demo:end comments so the whole feature can be stripped in one command.

Turn it on

Set the Demo section in your demo deployment’s configuration (environment variables or secrets, not the template’s appsettings.json):

"Demo": {
  "Enabled": true,
  "AdminEmail": "[email protected]",
  "AdminPassword": "<public demo password>",
  "UserEmail": "[email protected]",
  "UserPassword": "<public demo password>",
  "ResetIntervalMinutes": 30
}

Add AdminEmail to Admin:AdminEmails as well, so the admin account keeps the admin role. The passwords are public by design and must satisfy the password policy (8+ characters, an uppercase letter, a digit and a symbol) and the breach check. Keep them in sync with the demo block in src/config/site.ts on the landing site, which surfaces the “Try the live demo” popup. That popup offers one-click sign-in per account: each link opens the SPA login at /auth/login?email=...&password=..., which the login form reads and prefills (the form accepts email and password search params for exactly this). There is also an “Open without signing in” link for visitors who want to sign in by hand.

What you get

  • Two seeded accounts, created (and kept email-confirmed) at startup so they sign in immediately.
  • Lockout protection. Deleting, disabling, demoting, stripping permissions from, impersonating, or changing the password of a seed account is refused with 403 Demo.SeedAccountProtected. Visitors can still create their own throwaway users and do anything to those.
  • A periodic reset that removes every non-seed account and restores the seed baseline every ResetIntervalMinutes. It is destructive and must only ever point at the demo database.

Remove it

If you do not want a public demo, drop the whole feature:

./scripts/remove-demo.sh

This deletes the demo code, strips the wiring and the landing “live demo” links, removes this page, and verifies both the API and the landing site still build. When you scaffold a new project with new.sh, answering no to the demo prompt (or passing --no-demo) does the same automatically.

See also removing a feature and configuration.

Live demo

Explore the running app

No sign-up. Pick an account to open the demo with its credentials prefilled, or open it and sign in yourself.

Open without signing in

Credentials are prefilled. Shared password Slicekit-Demo-2026!.