Build a Tattoo Studio Booking Website with Claude Code

Create a modern tattoo studio booking website with Claude Code and accept real client appointments.

Roadmap & Resources

Choose Your Booking Niche

Choose the project type

Tattoo Studio Booking Website

Dental Clinic Booking Website

Hair Salon Booking Website

Barbershop Booking Website

Spa Booking Website

Personal Trainer Booking Website

Coaching Booking Website

Restaurant Reservation Website

Beauty Salon Booking Website

Massage Therapy Booking Website

Nail Salon Booking Website

Photography Booking Website

Pet Grooming Booking Website

Yoga Studio Booking Website

Tattoo Studio Booking Website

Dance Class Booking Website

Fitness Class Booking Website

Therapy & Counseling Booking Website

Chiropractor Booking Website

Physiotherapy Booking Website

Car Detailing Booking Website

Auto Repair Booking Website

Cleaning Service Booking Website

Home Repair Booking Website

Lawn Care Booking Website

Event Planner Booking Website

Wedding Planner Booking Website

Makeup Artist Booking Website

Esthetician Booking Website

Private Tutor Booking Website

Driving School Booking Website

Property Viewing Booking Website

Real Estate Agent Booking Website

Booking flow preview

- Select service

- Select date

- Select time

- Confirm booking

Customer details collected

- Full name

- Email

- Phone

- Optional notes

Set Up the Backend

Create a Supabase Project

Create a new Supabase project for your booking system backend.

Open Supabase

https://supabase.com/?utm_source=partner&utm_medium=social&utm_campaign=supasquad&dub_id=dfcthVHW4UOcyzr2

Create the Admin User

Create an admin user in Supabase Authentication, then copy the user ID.

Run the Full Setup SQL

Paste your admin user ID, then run this SQL code in Supabase SQL Editor. It will set up everything at once: tables, security policies, and admin access.

Full Setup SQL

create table services ( id uuid primary key default gen_random_uuid(), name text not null, description text, duration_minutes integer not null check (duration_minutes > 0), price numeric(10,2), is_active boolean not null default true, created_at timestamp with time zone default now() ); create table appointments ( id uuid primary key default gen_random_uuid(), full_name text not null, email text not null, phone text not null, service_id uuid not null references services(id) on delete restrict, appointment_date date not null, start_time time not null, end_time time not null, status text not null default 'pending' check (status in ('pending', 'confirmed', 'cancelled', 'completed')), notes text, created_at timestamp with time zone default now() ); create table business_hours ( id uuid primary key default gen_random_uuid(), weekday integer not null check (weekday between 0 and 6), is_open boolean not null default true, start_time time, end_time time ); create table blocked_dates ( id uuid primary key default gen_random_uuid(), blocked_date date not null unique, reason text, created_at timestamp with time zone default now() ); create table business_settings ( id uuid primary key default gen_random_uuid(), business_name text not null default 'Ink Atelier Studio', business_email text, business_phone text, business_address text, slot_interval_minutes integer not null default 30, booking_notice_hours integer not null default 24, created_at timestamp with time zone default now() ); create table admin_users ( id uuid primary key default gen_random_uuid(), user_id uuid not null unique references auth.users(id) on delete cascade, created_at timestamp with time zone default now() ); insert into services (name, description, duration_minutes, price) values ('Tattoo Consultation', 'A one-on-one consultation to discuss your tattoo idea, placement, size, style, and next steps.', 45, 50), ('Small Tattoo Session', 'A focused tattoo appointment for small, simple designs with clean linework or minimal detail.', 90, 150), ('Custom Tattoo Session', 'A personalized tattoo session for custom artwork designed around your idea, style, and placement.', 180, 350), ('Fine Line Tattoo', 'A detailed fine line tattoo session focused on clean, delicate, and precise artwork.', 120, 250), ('Cover-Up Consultation', 'A planning consultation to discuss cover-up options, design direction, and realistic possibilities.', 60, 75), ('Tattoo Touch-Up', 'A touch-up appointment for existing tattoo work that needs small refinements after healing.', 60, 100); insert into business_hours (weekday, is_open, start_time, end_time) values (0, false, null, null), (1, false, null, null), (2, true, '11:00', '19:00'), (3, true, '11:00', '19:00'), (4, true, '11:00', '19:00'), (5, true, '11:00', '20:00'), (6, true, '11:00', '18:00'); insert into business_settings (business_name, business_email, business_phone, business_address, slot_interval_minutes, booking_notice_hours) values ('Ink Atelier Studio', 'hello@inkatelierstudio.com', '+1 555 890 2345', '842 Art District Avenue, New York, NY', 30, 24); alter table admin_users enable row level security; alter table services enable row level security; alter table appointments enable row level security; alter table business_hours enable row level security; alter table blocked_dates enable row level security; alter table business_settings enable row level security; create policy "Anyone can read active services" on services for select to anon, authenticated using (is_active = true); create policy "Admins can manage services" on services for all to authenticated using ( exists ( select 1 from admin_users where admin_users.user_id = auth.uid() ) ) with check ( exists ( select 1 from admin_users where admin_users.user_id = auth.uid() ) ); create policy "Anyone can create appointments" on appointments for insert to anon, authenticated with check (true); create policy "Admins can read appointments" on appointments for select to authenticated using ( exists ( select 1 from admin_users where admin_users.user_id = auth.uid() ) ); create policy "Admins can update appointments" on appointments for update to authenticated using ( exists ( select 1 from admin_users where admin_users.user_id = auth.uid() ) ) with check ( exists ( select 1 from admin_users where admin_users.user_id = auth.uid() ) ); create policy "Anyone can read business hours" on business_hours for select to anon, authenticated using (true); create policy "Admins can manage business hours" on business_hours for all to authenticated using ( exists ( select 1 from admin_users where admin_users.user_id = auth.uid() ) ) with check ( exists ( select 1 from admin_users where admin_users.user_id = auth.uid() ) ); create policy "Anyone can read blocked dates" on blocked_dates for select to anon, authenticated using (true); create policy "Admins can manage blocked dates" on blocked_dates for all to authenticated using ( exists ( select 1 from admin_users where admin_users.user_id = auth.uid() ) ) with check ( exists ( select 1 from admin_users where admin_users.user_id = auth.uid() ) ); create policy "Anyone can read business settings" on business_settings for select to anon, authenticated using (true); create policy "Admins can manage business settings" on business_settings for all to authenticated using ( exists ( select 1 from admin_users where admin_users.user_id = auth.uid() ) ) with check ( exists ( select 1 from admin_users where admin_users.user_id = auth.uid() ) ); create policy "Users can read their own admin row" on admin_users for select to authenticated using (auth.uid() = user_id); insert into admin_users (user_id) values ('PASTE_YOUR_AUTH_USER_ID_HERE');

Admin User ID

Enter your Supabase auth user ID

Step-by-Step SQL Setup (Optional)

Create the Database Tables

Run these SQL queries inside the Supabase SQL Editor.

Services Table

create table services ( id uuid primary key default gen_random_uuid(), name text not null, description text, duration_minutes integer not null check (duration_minutes > 0), price numeric(10,2), is_active boolean not null default true, created_at timestamp with time zone default now() );

Appointments Table

create table appointments ( id uuid primary key default gen_random_uuid(), full_name text not null, email text not null, phone text not null, service_id uuid not null references services(id) on delete restrict, appointment_date date not null, start_time time not null, end_time time not null, status text not null default 'pending' check (status in ('pending', 'confirmed', 'cancelled', 'completed')), notes text, created_at timestamp with time zone default now() );

Business Hours Table

create table business_hours ( id uuid primary key default gen_random_uuid(), weekday integer not null check (weekday between 0 and 6), is_open boolean not null default true, start_time time, end_time time );

Blocked Dates Table

create table blocked_dates ( id uuid primary key default gen_random_uuid(), blocked_date date not null unique, reason text, created_at timestamp with time zone default now() );

Settings Table

create table business_settings ( id uuid primary key default gen_random_uuid(), business_name text not null default 'Ink Atelier Studio', business_email text, business_phone text, business_address text, slot_interval_minutes integer not null default 30, booking_notice_hours integer not null default 24, created_at timestamp with time zone default now() );

Add the Starter Data

Run these starter queries.

Insert the Starter Services

insert into services (name, description, duration_minutes, price) values ('Tattoo Consultation', 'A one-on-one consultation to discuss your tattoo idea, placement, size, style, and next steps.', 45, 50), ('Small Tattoo Session', 'A focused tattoo appointment for small, simple designs with clean linework or minimal detail.', 90, 150), ('Custom Tattoo Session', 'A personalized tattoo session for custom artwork designed around your idea, style, and placement.', 180, 350), ('Fine Line Tattoo', 'A detailed fine line tattoo session focused on clean, delicate, and precise artwork.', 120, 250), ('Cover-Up Consultation', 'A planning consultation to discuss cover-up options, design direction, and realistic possibilities.', 60, 75), ('Tattoo Touch-Up', 'A touch-up appointment for existing tattoo work that needs small refinements after healing.', 60, 100);

Insert the Business Hours

insert into business_hours (weekday, is_open, start_time, end_time) values (0, false, null, null), (1, true, '09:00', '17:00'), (2, true, '09:00', '17:00'), (3, true, '09:00', '17:00'), (4, true, '09:00', '17:00'), (5, true, '09:00', '17:00'), (6, true, '09:00', '13:00');

Insert the Settings

insert into business_settings (business_name, business_email, business_phone, business_address, slot_interval_minutes, booking_notice_hours) values ('Ink Atelier Studio', 'hello@inkatelierstudio.com', '+1 555 890 2345', '842 Art District Avenue, New York, NY', 30, 24);

Secure the Admin Dashboard

1. Create the Admin Access Table Create a table that defines which authenticated users are allowed to access and manage the admin dashboard.

Admin Users Table

create table admin_users ( id uuid primary key default gen_random_uuid(), user_id uuid not null unique references auth.users(id) on delete cascade, created_at timestamp with time zone default now() );

2. Enable Row Level Security Enable RLS on the tables that should be protected from normal users.

Enable RLS

alter table admin_users enable row level security; alter table services enable row level security; alter table appointments enable row level security; alter table business_hours enable row level security; alter table blocked_dates enable row level security; alter table business_settings enable row level security;

3. Add the Admin Policies Allow public users to read only what is needed for the booking website, and allow only admin users to manage the protected data.

Admin Policies

create policy "Anyone can read active services" on services for select to anon, authenticated using (is_active = true); create policy "Admins can manage services" on services for all to authenticated using ( exists ( select 1 from admin_users where admin_users.user_id = auth.uid() ) ) with check ( exists ( select 1 from admin_users where admin_users.user_id = auth.uid() ) ); create policy "Anyone can create appointments" on appointments for insert to anon, authenticated with check (true); create policy "Admins can read appointments" on appointments for select to authenticated using ( exists ( select 1 from admin_users where admin_users.user_id = auth.uid() ) ); create policy "Admins can update appointments" on appointments for update to authenticated using ( exists ( select 1 from admin_users where admin_users.user_id = auth.uid() ) ) with check ( exists ( select 1 from admin_users where admin_users.user_id = auth.uid() ) ); create policy "Anyone can read business hours" on business_hours for select to anon, authenticated using (true); create policy "Admins can manage business hours" on business_hours for all to authenticated using ( exists ( select 1 from admin_users where admin_users.user_id = auth.uid() ) ) with check ( exists ( select 1 from admin_users where admin_users.user_id = auth.uid() ) ); create policy "Anyone can read blocked dates" on blocked_dates for select to anon, authenticated using (true); create policy "Admins can manage blocked dates" on blocked_dates for all to authenticated using ( exists ( select 1 from admin_users where admin_users.user_id = auth.uid() ) ) with check ( exists ( select 1 from admin_users where admin_users.user_id = auth.uid() ) ); create policy "Anyone can read business settings" on business_settings for select to anon, authenticated using (true); create policy "Admins can manage business settings" on business_settings for all to authenticated using ( exists ( select 1 from admin_users where admin_users.user_id = auth.uid() ) ) with check ( exists ( select 1 from admin_users where admin_users.user_id = auth.uid() ) ); create policy "Users can read their own admin row" on admin_users for select to authenticated using (auth.uid() = user_id);

4. Add Your Admin User Create your admin account first from the app login screen, then insert your authenticated user ID into the admin_users table.

Insert Your Admin User

insert into admin_users (user_id) values ('PASTE_YOUR_AUTH_USER_ID_HERE');

Generate the Website with Claude Code

Use Prompt 1 to build the project

Prompt 1: Build the Full Tattoo Studio Project

Build a premium modern dental clinic website with real booking...

You are a world-class full-stack product builder, creative director, and UI/UX designer. Build a premium modern tattoo studio booking website with a real booking system and a secure admin dashboard. The final result should feel like it was designed by a top-tier creative studio and built as a real production-ready product. Do not create a generic template. Do not create a basic admin panel. Do not make small visual improvements. Create a complete, polished, premium tattoo studio booking experience from the first version. Tech stack: - React - TypeScript - Vite - Supabase for database, backend, and auth ================================================ SUPABASE CONNECTION ================================================ Create a .env.local file in your project root with your Supabase credentials: VITE_SUPABASE_URL=PASTE_YOUR_SUPABASE_URL_HERE VITE_SUPABASE_ANON_KEY=PASTE_YOUR_PUBLISHABLE_KEY_HERE Rules: - Use these values as environment variables - Do not hardcode them inside components - Create the Supabase client in src/lib/supabase.ts - Use import.meta.env.VITE_SUPABASE_URL and import.meta.env.VITE_SUPABASE_ANON_KEY - Use the official Supabase client with normal browser session persistence - Do not manually clear or remove the Supabase session - Do not sign the admin out automatically unless the user clicks a sign out button ================================================ DATABASE SCHEMA ================================================ Use this exact schema. Do not rename fields or invent new ones. services: - id - name - description - duration_minutes - price - is_active - created_at appointments: - id - full_name - email - phone - service_id - appointment_date - start_time - end_time - status - notes - created_at business_hours: - id - weekday - is_open - start_time - end_time blocked_dates: - id - blocked_date - reason - created_at business_settings: - id - business_name - business_email - business_phone - business_address - slot_interval_minutes - booking_notice_hours - created_at admin_users: - id - user_id - created_at Important: - Use business_settings for tattoo studio business information. - Use business_name, business_email, business_phone, and business_address. - Do not use clinic_settings. - Do not use clinic_name, clinic_email, clinic_phone, or clinic_address. - Do not use tattoo_settings. - Do not use studio_settings. - Do not use artist_settings. - Do not use salon_settings. - Do not use spa_settings. - Do not use dental_settings. - Do not use barbershop_settings. - Do not use trainer_settings. - Do not use coaching_settings. - Do not rename any table or field. - Use admin_users.user_id to check admin access. - Do not check admin access by email. - Do not check admin_users.id for authorization. - Do not use fake local authentication. - Do not use fake local data. ================================================ PROJECT GOAL ================================================ Create a complete tattoo studio booking website where visitors can: - view tattoo studio services - select a service - select a date - see available time slots - enter their details - submit a real appointment request - see a success confirmation Create a secure admin dashboard where the tattoo artist, studio owner, or studio manager can manage: - appointments - services - business hours - blocked dates - business settings Everything in the dashboard should be useful and editable, not just displayed. ================================================ CREATIVE DIRECTION ================================================ This project must look premium from the first version. Think like a world-class creative director for a premium tattoo studio. The public website should feel: - premium - modern - artistic - bold - clean - editorial - refined - creative - trustworthy - professional - client-friendly - realistic for a premium local tattoo studio The dashboard should feel: - premium - clean - modern - product-like - organized - smooth - easy for a tattoo studio manager to use - visually polished, not basic Design quality expectations: - Avoid generic or template-like design - Avoid flat and empty layouts - Avoid boring sections - Avoid weak spacing - Avoid basic AI-generated landing page patterns - Do not make the public website look like a simple template - Do not make the admin dashboard look like a basic starter dashboard - Keep the design artistic, premium, bold, clean, and professional - Do not make it look like a dental clinic, beauty salon, massage studio, restaurant, gym, coaching website, or generic SaaS landing page ================================================ VISUAL DESIGN SYSTEM ================================================ Use a premium tattoo studio visual style: - clean white, warm off-white, soft gray, charcoal, deep black, graphite, muted beige, and ink-inspired backgrounds - refined black, graphite, warm gold, muted red, clay, silver, and neutral accents - strong editorial contrast - polished tattoo service cards - refined borders - soft shadows - layered visuals - subtle gradients - cinematic lighting effects - artistic depth - premium buttons - minimal creative icons - high-quality tattoo studio imagery Use depth, gradients, lighting, and layered visuals where appropriate. Avoid flat backgrounds. Create clear contrast and strong hierarchy. Make the interface feel intentionally designed, not assembled from default components. Typography: - improve hierarchy and readability - make headings strong, artistic, premium, and trustworthy - use modern, elegant, readable typography - avoid overly decorative fonts - dashboard should stay clean, readable, and product-like Layout: - improve spacing and composition - use modern section layouts - use editorial visual storytelling - introduce tasteful asymmetry where appropriate - create image-led creative compositions - avoid rigid boring sections - every section should feel intentionally designed Interactions: - add smooth animations and micro-interactions - enhance hover effects and transitions - make the experience feel polished and alive - keep interactions elegant and professional, not distracting ================================================ IMAGE AND VISUAL STORYTELLING REQUIREMENTS ================================================ The public website must use strong, high-quality, niche-specific tattoo studio imagery from the first version. Do not create a premium layout with no images. Do not rely only on icons, gradients, or abstract shapes. Use real, relevant imagery in the right places to make the site feel complete, creative, trustworthy, and premium. Image style: - premium tattoo studio photography - clean modern tattoo studio environment - artistic studio interior - tattoo artist sketching or preparing design - tattoo machine and ink details shown tastefully - portfolio wall or design flash sheets - consultation moment with client shown professionally - refined, realistic, and non-graphic - good cropping - consistent visual style across the website Good image subjects: - modern tattoo studio interior - tattoo artist sketching custom artwork - clean tattoo workstation without graphic procedure imagery - tattoo machine, ink caps, gloves, and tools shown neatly - design sketches, flash sheets, or portfolio wall - artist consultation with a client - studio reception or waiting area - close-up of tattoo artwork only if tasteful and non-graphic - creative workspace with drawing tablet or sketchbook - premium studio lighting and atmosphere Do not use: - dental imagery - medical clinic imagery - massage therapy imagery - beauty salon imagery - barbershop imagery - restaurant imagery - fitness imagery - graphic skin procedure imagery - blood, injury, or uncomfortable closeups - unsafe or messy tattoo scenes - aggressive or intimidating visuals - low-resolution images - awkward stock photos - broken image links - random model portraits unrelated to tattoo services Implementation: - Use reliable external image URLs if needed. - Prefer high-quality Unsplash-style imagery or other stable image sources. - Make sure image links actually load. - Use descriptive alt text. - Use object-fit: cover and intentional cropping. - Keep the layout responsive. - If an image fails, the layout should still look good. - Keep images easy to replace later by storing image URLs in a clear data structure, config object, or component-level constants. Every image should support the tattoo studio brand, improve trust, and make the section feel more premium. ================================================ BRAND DIRECTION ================================================ Use tattoo studio-specific language: - Tattoo Studio - Tattoo Artist - Custom Tattoo - Tattoo Consultation - Small Tattoo - Fine Line Tattoo - Cover-Up Consultation - Tattoo Touch-Up - Artwork - Design - Placement - Style - Client - Appointment - Session - Book your consultation - Schedule your tattoo session - Reserve your appointment Do not use: - dental - dentist - patient - oral health - massage therapy - therapist - beauty salon - stylist - medical - healthcare - barber - barbershop - restaurant - reservation - table - coaching - trainer - workout Avoid unrealistic claims. Do not promise guaranteed results. Do not use unsafe aftercare instructions. Do not show or describe graphic procedures. Do not use intimidating or extreme messaging. Focus on creativity, trust, professionalism, consultation, cleanliness, design quality, artistic direction, and a polished client experience. ================================================ PUBLIC WEBSITE ================================================ Create: - Navbar - Hero section - Services section - About section - Booking section - Success confirmation screen - Footer Public website requirements: - Load real services from the services table. - Only show active services on the public website. - Use business_settings for tattoo studio name, email, phone, and address when available. - Use business_name as the studio name. - Use business_email as the studio email. - Use business_phone as the studio phone. - Use business_address as the studio address. - Make the booking section polished and easy to follow. - Use strong tattoo studio-specific imagery throughout the public website. - The site should look like a real premium tattoo studio website, not a simple template. ================================================ PUBLIC WEBSITE QUALITY EXPECTATIONS ================================================ Navbar: - refined and premium - clean tattoo studio brand presence - elegant spacing - polished booking CTA Hero: - visually striking and premium - must include a strong, relevant tattoo studio visual - use imagery such as a modern tattoo studio interior, artist sketching, clean workstation, tattoo artwork portfolio, flash sheets, or premium creative studio atmosphere - use image overlays, gradients, lighting, or layered composition for depth - maintain strong text readability - strong headline hierarchy - artistic and trustworthy supporting text - polished CTA buttons - not generic - not flat - not basic Services: - should not look like a plain list - make services feel premium, creative, clean, and visually engaging - use strong layout, refined typography, beautiful spacing, and polished cards or premium list design - include relevant visual treatment for services - service cards should include niche-relevant images or image areas where appropriate - show service name, description, duration, price, and booking affordance - services should be dynamic from Supabase Suggested image direction for services: - Tattoo Consultation: artist consultation, sketchbook, or design planning moment - Small Tattoo Session: clean minimal artwork or tidy workstation - Custom Tattoo Session: artist sketching or custom design process - Fine Line Tattoo: delicate artwork or design detail, not graphic procedure imagery - Cover-Up Consultation: design planning or portfolio review - Tattoo Touch-Up: clean studio setup or professional artist workspace Keep service images consistent in crop, quality, and style. Do not use graphic procedure images, blood, injury, or uncomfortable closeups. About: - creative, professional, and intentional - visually balanced - should reinforce trust, experience, cleanliness, artistic direction, design quality, and professional tattoo service - include a strong tattoo studio-related image or layered visual - avoid awkward empty layouts Booking: - polished and product-like - easy to follow - clear steps - strong selected states - premium time slot UI - clean client details form - clear appointment summary - elegant success state - may include subtle supporting imagery or visual accents, but do not make the booking form harder to use Footer: - refined - premium - consistent with the brand - use business_settings where relevant ================================================ BOOKING FLOW ================================================ Step 1: Select a tattoo service or consultation Step 2: Select a date and available time Step 3: Enter: - full name - email - phone - optional notes Step 4: Show a success confirmation with appointment summary Booking UI should include: - clear step indicator - nice selected states - clean date selection - polished time slots - appointment summary - strong CTA buttons Use client-focused language in the booking flow. Do not use patient-focused language. ================================================ AVAILABILITY LOGIC ================================================ Available time slots must be generated using: - business_hours - services.duration_minutes - business_settings.slot_interval_minutes - business_settings.booking_notice_hours - blocked_dates - existing appointments Rules: - Only show slots inside working hours - Skip blocked dates - Skip overlapping appointments - Ignore cancelled appointments - Respect booking notice time - Use the selected service duration to calculate end_time - New active services added from the dashboard must work in the booking flow Overlap rule: new_start < existing_end AND new_end > existing_start All slots should be normalized as: { start: Date, end: Date, label: string } Time safety: - Only format real Date objects - Never pass invalid strings to format() - Never use strings like "yyyy-MM-ddT10:30:00" - Always combine the selected date and time correctly - Save appointment_date as a Supabase-compatible date - Save start_time and end_time as Supabase-compatible time values Important booking insert rule: - When creating an appointment, do not use .insert(...).select() or .insert(...).select().single(). - Public users are allowed to insert appointments, but they are not allowed to read all appointments. - Use insert only, then show the success screen from the local booking data already available in the form. - Do not add a public SELECT policy for appointments. - Do not insert id manually. - Do not insert created_at manually. - service_id must be the selected service id from the services table. ================================================ ADMIN AUTH ================================================ Create a real admin login using Supabase Auth. Admin login flow: 1. Admin enters email and password. 2. Sign in with supabase.auth.signInWithPassword(). 3. If login fails, show a clear error message. 4. After successful sign in, get the authenticated user. 5. Use the authenticated user's id. 6. Check if user.id exists in admin_users.user_id. 7. If the user exists in admin_users, allow access to dashboard. 8. If the user is authenticated but not found in admin_users, show: "You are signed in, but you are not authorized as an admin." 9. Add a loading state while checking session and admin access. 10. Do not redirect back to login before the admin check finishes. Important admin session rules: - On admin route load, call supabase.auth.getSession(). - If there is no session, stop loading and show the login form. - If there is a session, get the current user with supabase.auth.getUser(). - Query admin_users where user_id equals user.id. - Use maybeSingle(), not single(), when checking admin_users. - If a matching row exists, set isAdmin to true and show the dashboard. - If no matching row exists, set isAdmin to false and show the unauthorized message. - Always stop the loading state in a finally block. - The UI must never stay stuck on "Verifying access..." forever. - Use supabase.auth.onAuthStateChange to respond to sign in, sign out, token refresh, and session changes. - Do not sign the admin out automatically because of a temporary query error. - Do not clear local storage or remove the Supabase session manually. - Keep the admin logged in as long as Supabase has a valid session. - If a token refresh event happens, keep the dashboard available and re-check admin access if needed. Rules: - Protect all admin routes. - Public website should stay accessible without login. - Do not check admin access by email. - Do not check admin_users.id. - Do not use fake local authentication. - Do not rely only on hiding buttons. - Do not use business_settings for admin authentication. - Do not use services or appointments for admin authentication. - Admin access is only controlled by admin_users.user_id. Important: - The admin_users table contains user_id values from Supabase Auth. - The login email and password belong to a Supabase Auth user. - After login, always compare auth.user.id with admin_users.user_id. - Do not compare user.email with anything in admin_users. ================================================ ADMIN DASHBOARD ================================================ Create a complete dashboard with these pages: 1. Overview 2. Appointments 3. Services 4. Business Hours 5. Blocked Dates 6. Business Settings The dashboard must feel like a polished premium product dashboard, not a basic admin template. Dashboard visual requirements: - refined sidebar - polished page headers - beautiful cards - clean tables - premium forms - clear modals or drawers - elegant buttons - refined badges - smooth hover states - good empty states - strong spacing and hierarchy - consistent design system 1. Overview: - show useful stats - upcoming appointments - pending appointments - completed appointments - active services - use polished metric cards and useful layout 2. Appointments: - show all appointments from Supabase - show client name, service, date, time, phone, email, status, and notes - allow filtering by status - allow updating status: - pending - confirmed - cancelled - completed - make appointment tables/cards clean, readable, and premium 3. Services: This page must be fully manageable, not read-only. The admin must be able to: - add new services - edit existing services - activate services - deactivate services Each service row should have clear actions. Service fields: - name - description - duration_minutes - price - is_active Important: - Existing services must have an Edit action. - Editing should open a polished pre-filled form, modal, drawer, or panel. - Saving should update the service in Supabase. - Inactive services should stay visible in the admin dashboard. - Inactive services should not appear on the public booking page. - Prefer deactivate instead of hard delete because appointments can reference services. - New or updated active services must appear automatically in the booking flow. 4. Business Hours: - allow editing each weekday - allow open/closed days - allow editing start_time and end_time - changes must affect available booking slots - make the editor clear and easy to use 5. Blocked Dates: - allow adding blocked dates - allow removing blocked dates - show reason - blocked dates must prevent bookings - make the interface simple and polished 6. Business Settings: Allow editing: - business_name - business_email - business_phone - business_address - slot_interval_minutes - booking_notice_hours In the UI, these fields can be labeled as: - Studio Name - Studio Email - Studio Phone - Studio Address - Slot Interval - Booking Notice Important: - Save updates back to business_settings. - Updated business settings should appear on the public website where relevant. ================================================ QUALITY REQUIREMENTS ================================================ - Full working app - Clean code structure - Supabase fully connected - Booking flow working - Appointment insert works without requiring public appointment read access - Admin login working - Admin session handling working - Admin verification never gets stuck forever - Protected dashboard working - Services management fully working - Appointments management working - Business hours editing working - Blocked dates working - Business settings editing working using business_settings - Public website uses high-quality tattoo studio-specific imagery - Hero section includes a strong relevant tattoo studio visual - Services section includes relevant niche-specific visual treatment or images - About section includes authentic tattoo studio imagery or visual storytelling - Images are properly cropped, responsive, and not broken - Image URLs are easy to replace later - No placeholder fake data - No disconnected dashboard pages - No read-only admin pages where editing is expected - Premium tattoo studio visual direction from the start - Public website should feel top-tier, not template-like - Dashboard should feel like a polished premium product - Admin auth must work using Supabase Auth user.id and admin_users.user_id - Keep functionality and visual quality strong from the first version FINAL RESULT: Create a complete, working, premium tattoo studio booking platform with a high-end public website, strong niche-specific imagery, working admin login, stable session handling, real appointment booking, and a polished admin dashboard.

Optional: Start from a ready-made project

Tattoo Studio Booking Website

Start faster with the ready-made project

PROJECT

https://profitstudio.app/template/tattoo-studio-booking-website

Add Supabase environment variables

Add your Supabase Project URL and Publishable Key in a .env.local file for local testing.

Deploy the Website Live

Install Git

Make sure Git is installed on your computer before pushing the project to GitHub.

Download Git

https://git-scm.com/

Connect VS Code to GitHub

Sign in to your GitHub account inside VS Code.

Create a GitHub Repository

Create a new private GitHub repository and copy the repository URL.

Push the Project to GitHub

Open Claude Code inside VS Code, paste the Safe GitHub Push Prompt, and add your GitHub repository URL. After Claude prepares the project, open Source Control in VS Code, then commit and sync the changes.

Safe GitHub Push Prompt

Add your GitHub repository URL below, then use the customized prompt in Claude Code.

I already created an empty GitHub repository. GitHub repository URL: {{GITHUB_REPOSITORY_URL}} Please prepare and push this local project to that GitHub repository. Rules: - Do not change the app code, UI, design, routes, database logic, backend logic, Supabase logic, or functionality. - Only handle Git and GitHub publishing. - Check Git status, branch, remotes, .gitignore, and tracked files first. - Make sure .env and .env.local are not committed. - Make sure generated files like node_modules, dist, dist-ssr, *.tsbuildinfo, .DS_Store, and log files are ignored. - If unnecessary files are already tracked, remove them from Git tracking only. Do not delete real project files. - Use main for a new repository, unless an existing branch should be preserved. - Connect this project to the GitHub repository URL. - Create a clean commit if needed. - Push the project to GitHub. If the push fails, diagnose and fix only the Git/GitHub setup. Do not change app functionality. Before any destructive action, explain what you found and what you plan to do.

GitHub repository URL

https://github.com/username/repository-name.git

Create a Hostinger Node.js Web App

Open Hostinger, create a new Node.js web app, and choose your domain.

Open Hostinger

Publish this project with the same setup shown in the video.

RECOMMENDED

https://www.hostg.xyz/SHJe0

Import the Repository and Deploy

Import your GitHub repository, add the required environment variables, then click Deploy.

VITE_SUPABASE_URL VITE_SUPABASE_ANON_KEY

VITE_SUPABASE_URL

Project URL

VITE_SUPABASE_ANON_KEY

Anon (public) key

Get these values from Supabase

Open API Settings

https://supabase.com/dashboard/project/_/settings/api

Upgrade — Email Notifications

Send Appointment Emails Automatically

Make the booking system more professional with automatic appointment emails.

- Send a new booking email to the admin

- Send a confirmation email to the patient

Optional upgrade after deployment.

Make Your AI Website Send Emails Automatically (Supabase Tutorial)

Watch Tutorial

https://www.youtube.com/watch?v=NK6ztA_-0cE

Upgrade — SMS Notifications

Send Appointment SMS Automatically

Make your booking system more professional with automatic SMS confirmations after each booking.

- Send an SMS confirmation to the customer

- Optionally notify the business owner by SMS

Add SMS Notifications to Your AI Booking Website

Watch Tutorial

https://youtu.be/AoR1FDcUuK4?si=O1Bi5azhJW7jJezF