for platforms

Let your builders verify and scan in one click.

If you host the apps people build by prompting, you can vouch for them. A small OAuth integration lets your users connect VibeProtect once: their apps are verified without a file or tag, and, if they allow it, their source is scanned straight from your platform. Your platform gets listed as one we work with.

live integrations

Platforms with the integration today

appgnt

The app studio: describe an app in chat and get a web app plus native builds. First platform with the integration.

Yours?

Fill in the form below. We reply with a platform id, confirm the redirect URI and your API base path, and exchange credentials. Most teams ship it in a day or two.

the protocol

Two scopes, four endpoints

VibeProtect is an ordinary OAuth 2.0 client of your platform: authorization code with PKCE, a confidential client with a secret. Your consent page shows two permissions and lets the user leave the second one off.

  • vibeprotect:verify lists the apps the user owns and their public addresses. Required.
  • vibeprotect:source downloads an app's source for the code scan. Optional: the user chooses.
  • Read only. Four GETs, JSON, Bearer token. Nothing is written through the integration.
  • Path-scoped. An app at yourplatform.com/a/slug/ is scanned at that prefix and nowhere else.
GET /me
  { "account": { "id", "name"?, "email"? } }

GET /apps
  { "apps": [ { "id", "name", "url",
                "alternateUrls"?, "status"?,
                "sourceAvailable"?, "updatedAt"? } ] }

GET /apps/{id}
  { "app": { ...same } }         404 if not theirs

GET /apps/{id}/source           needs vibeprotect:source
  { "url": "https://...signed...",
    "format": "tar.gz", "revision"? }

Token endpoint answers include scope, so we learn what the user granted. Full details, limits and error semantics: ask us for the protocol document when you apply.

what your users get

No file, no tag, no copy-paste

  • One approval on your consent page verifies every app on the account.
  • Fix prompts worded for your builder. Every finding comes with an instruction they paste back into your chat.
  • Code scans without GitHub. Committed keys, vulnerable packages, database rules: read from the source you hold.
  • Nightly re-check. If an app is deleted or moves, its verification lapses automatically.

what we promise

Boundaries, in writing

  • Only the owner's apps. Everything runs over the user's own grant; we never list or scan anything they did not approve.
  • Only the app's prefix. Shared-host apps are never used to look at your platform itself.
  • Source is not kept. Downloaded for the scan, discarded after. Secrets are stored redacted.
  • Identified traffic. The scanner sends VibeProtect-Scanner/1.0 and respects a request to stop.

apply

Request the integration

Tell us about your platform. A person reads this and answers, usually within a couple of business days, with your platform id, the redirect URI to register, and how we exchange credentials.

We only use your address to reply. Nothing here goes on a mailing list.

Prefer email? support@vibeprotect.dev with "platform integration" in the subject reaches the same place.

questions

Platform questions

What does it cost?

Nothing. Integrating is free for the platform and the listing is free. Your users pay VibeProtect for scans the way everyone else does, and you get a product that keeps their apps from leaking on your domain.

Do you need write access to anything?

No. Four read-only endpoints and two scopes. We never change an app, a repo or a setting, and the source we download is discarded after the scan.

Our apps live under paths on one shared domain. Does that work?

Yes, that is the case the protocol was designed around (appgnt publishes at appgnt.com/a/<slug>/). Every scan is scoped to the exact host and the app's path prefix: nothing outside the prefix is requested, followed or probed.

What if a user declines source access?

Then we verify their apps through you and scan the live app only. They can connect a GitHub repo for code scans, or reconnect later and allow it. Your consent page must let them say no.

We already run an OAuth server for MCP agents.

Then you are most of the way there: add the two scopes, a pre-registered confidential client for us, and the four endpoints. appgnt did exactly that on top of its MCP server.