A practical guide
Vibe coding: from a working prototype to an app you can run a business on.
Tools like Lovable, Bolt and Replit let founders and teams build working software by describing it. That is a real shift, and for many ideas it is the right way to start. This page covers what vibe coding does well, the gaps that usually appear before launch, and how to close them without starting again.
What is vibe coding?
Vibe coding means building software by describing what you want in plain language and letting AI write the code, with tools like Lovable, Bolt, Replit, v0, Cursor and Figma Make. You test what comes back, describe the next change, and repeat. The term was coined by Andrej Karpathy in early 2025, and it has opened software building to people who do not write code.
What it does well
Speed to something real. In a day or two you can have an app people can click through, a demo for investors or an internal tool that replaces a spreadsheet. Several of these tools now include hosting, a database and login out of the box, so a prototype can go live quickly.
Where AI-built apps usually need work
The tools are good at producing software that runs. What they do less reliably is the work that keeps it safe and dependable once real customers, data and money are involved. That work is mostly invisible in a demo, which is why it gets missed. The gaps we see most often:
- Security: API keys visible in the browser, login checks that only exist in the interface, and database tables with no access rules.
- Data: no tested backups, and a data model that gets harder to change as features pile up.
- Reliability: little error handling, no automated tests and no monitoring, so problems surface through customer complaints.
- Payments and integrations: checkout and webhook flows that work in testing but are not built to handle failed or duplicate events.
- Handover: code nobody has reviewed, which makes it slow and risky for the next developer to change.
None of this means the app was a mistake. A prototype that proved people want the product has done its job; it now needs an engineering pass before it carries the business.
How to take a vibe-coded app to production
Work in order of risk. Close the security gaps first, then move data and authentication onto a footing you trust, then add error handling, tests, monitoring and proper deployment. A small, focused app can often reach a careful first launch in about four weeks; apps with payments, many integrations or tangled code take longer. The free tools below show where yours stands.
Free tools & guides for AI-built apps
AI App Production-Readiness Scorecard
12 questions, a letter grade and the gaps to close first. Runs in your browser.
The Vibe-Coder’s Security Checklist
15 security checks for AI-built apps, each one something you can test yourself.
Which AI Builder Should You Use?
Lovable, Bolt, Replit, v0, Cursor and Figma Make compared by who each one suits.
AI App Handoff Kit + 30-Day Launch Plan
What to give engineers so they can start quickly, and a four-week launch plan.
FAQ
Frequently asked questions
What is vibe coding?
Vibe coding is building software by describing what you want in plain language and letting an AI tool write the code, using tools such as Lovable, Bolt, Replit, v0, Cursor or Figma Make. You steer by testing the result and refining your prompts rather than writing most of the code yourself. The term was coined by AI researcher Andrej Karpathy in February 2025.
Is vibe coding good or bad?
Neither, on its own. It is very good for prototypes, internal tools and testing an idea with real people quickly. The difficulty comes when the app starts holding customer data or taking payments, because the things that make software safe to run (access rules, backups, error handling, monitoring) are easy to miss when nobody has read the code. Those gaps are normal and fixable.
Can you build a real product by vibe coding?
You can build a working product, and some teams launch straight from these tools. For anything handling personal data, money or meaningful traffic, expect a further stretch of work on security, data, authentication, reliability and deployment. How much depends on the app, and a code review is the quickest way to find out.
What are the risks of vibe coding?
The ones we see most often are API keys exposed in the browser, login checks that exist in the interface but not on the server, database tables without access rules, no backups, and code that becomes hard to change as it grows. Each can be checked for and fixed. The free security checklist and readiness scorecard are a good first pass.
Getting ready to put real users on a vibe-coded app?
Send us the app or the repo. We will review it and tell you plainly what needs fixing before launch, what can wait, and whether hardening or a partial rebuild makes more sense.