for apps built with appgnt

Built it with appgnt?
Connect once, we do the rest.

appgnt is the first platform with a VibeProtect integration. Instead of publishing a verification file, you approve VibeProtect in your appgnt account: it confirms which apps are yours and where they live, and, if you tick the box, hands over the source for a code scan. Every fix is a prompt you paste back into the appgnt studio.

7-day free trial. No card, no install.

what usually goes wrong

Where appgnt apps leak

Keys in the Vite bundle

appgnt apps are React and Vite: anything in a VITE_ variable or pasted into a component is built into the JavaScript every visitor downloads. Secret keys belong in a server function in the app's own backend, read from its secrets.

live app: secret keys in the built JavaScript

AI called straight from the browser

Asking for "an AI feature" can produce code that calls OpenAI from the page itself, which only works by shipping your key to every visitor. The fix moves the call into a server function.

live app: AI SDK called from the browser

A key in the source

Keys pasted into code or a committed .env travel with the project. With source access on, we read the app's files straight from appgnt and tell you which key to rotate.

source: committed secrets and .env files

Packages with known holes

Agents install whatever version they remember. We check the lockfile against OSV.dev and tell you what to bump, and to what.

source: vulnerable dependencies (OSV.dev)

the fix is a prompt

Worded for appgnt

The most common thing we find in prompted apps, and the prompt that comes with it, worded for appgnt:

highsecrets.openai-key

OpenAI API key exposed in your public JavaScript

Anyone can copy this key from your app and spend against your OpenAI account.

key
sk-proj-Ab…9xQ
found in
/a/myapp/assets/index-4f2a9c1b.js

Rotate the key at platform.openai.com first: removing it from the code does not un-leak it.

Paste into appgnt click to select

Security fix: my OpenAI key is in the front-end code.
Remove it from every front-end file and from any VITE_ variable. Move every OpenAI call into a server function in the app's own backend (declare it in appgnt.backend.json, write it in server/, apply the backend) and read the key there from the app's backend secrets.
The front end should call that function instead. Do not log the key. List every file you changed.

then rescan to confirm it is gone

verify your app

Proving it is yours, on appgnt

No file, no tag. appgnt vouches for your apps over a connection you approve once, and we ask it again every night so a deleted or moved app stops being scanned on its own.

  • Connect appgnt under Integrations in VibeProtect (or "Pick it from your account" when adding an app). You land on appgnt's permission screen.
  • Approve. "Confirm which apps are mine" is required; "read the source" is a checkbox you can leave off.
  • Pick the app. Its address comes from appgnt, and it is verified on the spot. Apps at appgnt.com/a/<slug>/ are scanned at that path and nowhere else.
Paste into appgnt click to select

Add a site verification for VibeProtect. Create the file public/.well-known/vibeprotect.txt containing exactly this single line:
vibeprotect-verify=3kQ9xZr1VbN0aT7mYw2cLp8e
Also add this tag inside <head> in index.html (or the root layout's metadata):
<meta name="vibeprotect-verification" content="vibeprotect-verify=3kQ9xZr1VbN0aT7mYw2cLp8e" />
Do not change anything else.

Your real token is in the app once you add it. The file ends up at /.well-known/vibeprotect.txt.

questions

appgnt questions

What exactly can VibeProtect do in my appgnt account?

Read two things: which apps you own and where they are published, and (only if you allowed it) a copy of an app's source for the scan. It cannot change an app, start a build, or see your keys and sign-ins. You can disconnect it from either side at any time.

My app is on appgnt.com/a/something. Does the scan touch the rest of appgnt.com?

No. Every request stays inside your app's path: its page, the scripts it loads from there, and the usual list of files that should never be public, resolved under that path. Nothing on the host outside your prefix is requested.

I left source access off. What do I lose?

Only the code scan (committed keys, vulnerable packages, database rules). The live app scan works exactly the same. Reconnect appgnt and tick the box whenever you like, or connect the project's GitHub repo instead.

My app has its own domain. Which address is scanned?

The one appgnt reports as the app's main address: your domain once it is live, with the appgnt.com address as an alternate. Add the alternate as a second app if you want both checked.

See what your appgnt app is showing strangers.

Seven days free, no card. The hardest part is asking appgnt to add a file.