verifying your app
Prove it's yours.
One prompt does it.
We only scan apps whose owners have proved they control them. It keeps VibeProtect from being a way to poke at other people's apps, including yours. You publish a token we give you, in one of three ways, and you are done. Your builder can do it for you.
the easy way
Paste this into your builder
When you add an app, we show you this prompt with your own token in it, worded for the builder that made the app. It asks for both the file and the meta tag. Either one is enough.
- Then publish or redeploy, so the change is live.
- Click Verify in VibeProtect. It takes a few seconds.
- If it fails, we tell you exactly what we saw at the address, so you know what to fix.
Add a site verification for VibeProtect. Create the file public/.well-known/vibeprotect.txt containing exactly this single line:
vibeprotect-verify=3kQ9xZr1VbN0aT7mYw2cLp8e
Also add this tag inside <head> in index.html (or the root layout's metadata):
<meta name="vibeprotect-verification" content="vibeprotect-verify=3kQ9xZr1VbN0aT7mYw2cLp8e" />
Do not change anything else.
The token above is an example. Yours is in the app.
three ways
Exactly what we look for
We fetch this address, and the token has to be a line of the response on its own:
https://myapp.lovable.app/.well-known/vibeprotect.txt
In most projects (Lovable, Bolt, Vite, Next.js) that means a file at public/.well-known/vibeprotect.txt containing just the token:
vibeprotect-verify=3kQ9xZr1VbN0aT7mYw2cLp8e
If the address returns your app's home page instead, your app is answering every path itself. Put the file in the public folder, which is served as-is, or use the meta tag.
We load https://myapp.lovable.app/ and look for this tag in the HTML (attribute order does not matter):
<meta name="vibeprotect-verification" content="vibeprotect-verify=3kQ9xZr1VbN0aT7mYw2cLp8e" />
It has to be in the HTML the server sends, so put it in index.html, or in Next.js in the root layout's metadata (other: { "vibeprotect-verification": "..." }). A tag added later by JavaScript is not seen.
If your app is on your own domain, add a TXT record with the token as its value:
_vibeprotect.app.example.com TXT "vibeprotect-verify=3kQ9xZr1VbN0aT7mYw2cLp8e"
Not available on platform addresses like lovable.app, replit.app or netlify.app: only the platform controls their DNS.
the rules
What verification covers
The exact address
Verifying myapp.lovable.app covers that address and its www. twin. Not other apps on lovable.app, not other subdomains of your domain. Each one is verified on its own.
Re-checked every night
The proof has to stay published. If it disappears, the app goes back to unverified and scans stop until you put it back.
Changing the address starts over
If you edit an app's address, it gets a new token and needs verifying again. The old proof says nothing about the new address.
Repo scans use GitHub instead
Scanning a repo needs no token: installing our GitHub App on that repo is the proof. We only read repos you installed it on.
questions
Verification questions
Can I remove the file once I'm verified?
Please don't. We re-check every night, and an app whose proof has gone stops being scanned until it is back. It is a few bytes and does nothing else.
Is the token a secret?
No. It is meant to be published. It only proves that whoever controls the app also controls your VibeProtect account. It gives nobody access to anything.
Why not just verify by email, like other tools?
Because on an address like myapp.lovable.app there is no mailbox that could prove anything, and on your own domain the file is no harder for whoever deployed the app.
My app redirects to www. Is that a problem?
No. Redirects are followed as long as they stay on the same app: the address you added or its www. twin. A redirect to a different site does not count.
Does verifying give you access to my database or hosting?
No. Verifying lets us scan your app's public address, read-only, and nothing else. It gives us no access to your database, your hosting account or your code. Code access only ever comes from installing our GitHub App on a repo. See what our scanner does.