for platforms
Let your builders verify and scan in one click.
If you host the apps people build by prompting, you can vouch for them. A small OAuth integration lets your users connect VibeProtect once: their apps are verified without a file or tag, and, if they allow it, their source is scanned straight from your platform. Your platform gets listed as one we work with.
live integrations
Platforms with the integration today
appgnt
The app studio: describe an app in chat and get a web app plus native builds. First platform with the integration.
Yours?
Fill in the form below. We reply with a platform id, confirm the redirect URI and your API base path, and exchange credentials. Most teams ship it in a day or two.
the protocol
Two scopes, four endpoints
VibeProtect is an ordinary OAuth 2.0 client of your platform: authorization code with PKCE, a confidential client with a secret. Your consent page shows two permissions and lets the user leave the second one off.
vibeprotect:verifylists the apps the user owns and their public addresses. Required.vibeprotect:sourcedownloads an app's source for the code scan. Optional: the user chooses.- Read only. Four
GETs, JSON, Bearer token. Nothing is written through the integration. - Path-scoped. An app at
yourplatform.com/a/slug/is scanned at that prefix and nowhere else.
GET /me
{ "account": { "id", "name"?, "email"? } }
GET /apps
{ "apps": [ { "id", "name", "url",
"alternateUrls"?, "status"?,
"sourceAvailable"?, "updatedAt"? } ] }
GET /apps/{id}
{ "app": { ...same } } 404 if not theirs
GET /apps/{id}/source needs vibeprotect:source
{ "url": "https://...signed...",
"format": "tar.gz", "revision"? }
Token endpoint answers include scope, so we learn what the user granted. Full details, limits and error semantics: ask us for the protocol document when you apply.
what your users get
No file, no tag, no copy-paste
- One approval on your consent page verifies every app on the account.
- Fix prompts worded for your builder. Every finding comes with an instruction they paste back into your chat.
- Code scans without GitHub. Committed keys, vulnerable packages, database rules: read from the source you hold.
- Nightly re-check. If an app is deleted or moves, its verification lapses automatically.
what we promise
Boundaries, in writing
- Only the owner's apps. Everything runs over the user's own grant; we never list or scan anything they did not approve.
- Only the app's prefix. Shared-host apps are never used to look at your platform itself.
- Source is not kept. Downloaded for the scan, discarded after. Secrets are stored redacted.
- Identified traffic. The scanner sends
VibeProtect-Scanner/1.0and respects a request to stop.
apply
Request the integration
Tell us about your platform. A person reads this and answers, usually within a couple of business days, with your platform id, the redirect URI to register, and how we exchange credentials.
Prefer email? support@vibeprotect.dev with "platform integration" in the subject reaches the same place.
questions
Platform questions
What does it cost?
Nothing. Integrating is free for the platform and the listing is free. Your users pay VibeProtect for scans the way everyone else does, and you get a product that keeps their apps from leaking on your domain.
Do you need write access to anything?
No. Four read-only endpoints and two scopes. We never change an app, a repo or a setting, and the source we download is discarded after the scan.
Our apps live under paths on one shared domain. Does that work?
Yes, that is the case the protocol was designed around (appgnt publishes at
appgnt.com/a/<slug>/). Every scan is scoped to the exact host and the
app's path prefix: nothing outside the prefix is requested, followed or probed.
What if a user declines source access?
Then we verify their apps through you and scan the live app only. They can connect a GitHub repo for code scans, or reconnect later and allow it. Your consent page must let them say no.
We already run an OAuth server for MCP agents.
Then you are most of the way there: add the two scopes, a pre-registered confidential client for us, and the four endpoints. appgnt did exactly that on top of its MCP server.