Full-stack engineer from Bangladesh. I build the internal platforms a company actually runs on, then keep going past the browser into desktop clients, device identity and the operating system underneath.
- Engineering at NeXbit LTD. Multi-tenant internal platforms: finance, lead, HR and POS systems
- Currently deep in identity and device trust: device keypairs, OTP unlock, challenge/response SSO
Error tracking that understands Manifest V3. Events survive service-worker death, content-script
errors group by host, and track() names the task that died. These are the failure modes MV3 introduced and
general-purpose trackers were never built for.
TypeScript · zero runtime dependencies · MIT · Docs → · Repo → ·
Typed clients for the infrastructure Bangladeshi e-commerce actually runs on: Steadfast, Pathao and RedX for delivery, bKash and Nagad for payment. Every shop writes these five integrations and most repeat the same expensive mistakes: unsettled delivery statuses treated as final, payments marked paid on a redirect that never executed, a retry that ships the parcel twice. This is one careful implementation with those designed out.
TypeScript · zero runtime dependencies · MIT · Repo → ·
An immutable, centrally-managed workstation operating system. A normal daily-use machine that happens
to be encrypted and tamper-evident: /usr mounted read-only so nothing can modify the OS at runtime,
users are not administrators, and a whole fleet updates from one signed image.
Linux · Immutable images · Fleet management · private · Install guide →
An enterprise-first browser and identity platform. The Electron client stays locked at launch until organizational OTP unlock; a device keypair is generated on first run and held in the OS keychain, then registered for challenge/response login and SSO into internal apps. Paired with an identity server and an HR/IT admin panel for devices, policies, approvals and audit. 19 signed releases so far, on an auto-update channel serving an installed fleet.
Electron · Next.js · Prisma · TypeScript · private · Signed installers →
Multi-tenant financial ledger SaaS. One user belongs to many organizations and switches between them; accounts, invoices, expenses and monthly carry-forward are isolated per tenant, with Owner / Admin / Accountant / Viewer permissions resolved per membership rather than per account.
Next.js 16 · React 19 · Prisma 7 · Neon Postgres · Auth.js v5 · Live →
Private-by-design messaging: end-to-end encrypted, with messages that delete themselves and inference
that runs on the device instead of a server. A Next.js client on a hand-written Go server: WebSockets,
JWT auth, Web Push, and web-llm in the browser.
Next.js · Go · Postgres (pgx) · shadcn/ui · Live →
Transaction tracker for Bangladeshi mobile-banking agents (bKash / Nagad / Rocket / Upay). Shopkeepers record who transacted with which ID, attach photo proof, flag suspicious entries and spot repeat numbers at a glance, a practical guard against fraud and off-book transfers.
Next.js 15 · Prisma · Neon Postgres · Tailwind · Live →
Also: Domain Guard, a Next.js admin panel for domain allowlisting with one-click approve, recorded denials and an audit trail · DevPulse, an issue-tracker API with JWT auth and role-based filtering (API →)
On these numbers. Public card services only see public repositories, so the language and
commit cards above are generated from an authenticated token instead
(scripts/gen_cards.py, refreshed weekly) and cover every
repository, private included. Language share is measured in bytes of code rather than repository count.
The streak comes from the GitHub contribution calendar, which already includes private work.
Open to backend, platform and full-stack work. GMT+6, remote. Reach me at being.sabbirhowlader@gmail.com.


