Skip to main content

EngineeringCodeCross Team

Harden a Base44 MVP before paid traffic (2026)

A 2026 wrap for founders still shipping from Base44 Publish: rank the blast (App Visibility, secrets outside the vault, table permissions, open backend functions, anyone can Publish, no unpublish), prove the doors on the live URL, then decide stay-harden vs leave.

Engineering

14 min

Visibility
Named door

Not auto-public

Secrets
Vault only

Not chat or pages

Ads
After

Live URL proof

Citation-ready answer: Harden a Base44 MVP before paid traffic by locking App Visibility so strangers cannot write without a real sign-in, moving keys into Base44 secrets, putting Creator Only or a role check on every table that holds personal data or money, running a security scan, and proving a stranger cannot read another person’s row on the published URL. Name who can Publish. Prove you can unpublish or restore a prior version. Then buy ads.

This note is from CodeCross, an Austin, Texas app development company (Pakistan engineering on a US Central overlap). Cousin tools sit on vibe coding. Buying help is the Austin app development company page. If nobody can name an unpublish or a prior version tonight, book a conversation.

Money leaves when the campaign still lists a default `.base44.app` host, a Public app that never asked for a login, or a key that lived in chat. A stranger can read every form row because the table still says All Users on Read. Anyone who can open the editor can hit Publish. The only undo is “we will prompt it back.” A green preview is not a stranger test on the URL you would put on a billboard.

This essay is the pre-ads wrap while the app still lives on Base44 hosting. Wrap means close the risky doors while Publish still serves the live site. It expands Harden a Base44 MVP before strangers hit Publish App. It is not the first owned ship on Base44 to production, not the host compare on Base44 vs production, not the runtime exit on get off Base44, not the extract on migrate from Base44, not the overlap week on transition from Base44. Cousin wraps live later in this essay. The question here is narrower: can you buy a click while Base44 still hosts the app? When visibility, secrets, or the off switch is still red, book.

The punchy lists live on the landers. Base44 MVP hardening is the clipboard for this week. Base44 to production is publish-is-not-owned-ship. Base44 vs production is builder host vs a stack you run. Get off Base44 is the host exit. Migrate from Base44 is extract. Transition from Base44 is the overlap week. The vibe coding hub maps cousins. This essay is the pre-ads proof on a Base44-hosted app.

Stay on Base44. Close the doors first.

Base44 is paid to turn a prompt into a live app tonight. Paid traffic is paid to send strangers at a public URL. Those jobs collide. A green preview can still leave the app Public with no login, a secret in a page, or Publish open to every collaborator.

Wix announced it bought Base44 on 18 June 2025. Wix said Base44 would keep running as its own product. That is ownership context. It is not a wrap. Your doors still sit in the Base44 project: visibility, tables, secrets, and who can Publish.

Base44’s own docs draw the line. The quick start says built-in hosting makes the app shareable as soon as it exists. Publish in the top bar is how latest changes go live. That same panel copies a `.base44.app` address, connects a domain, sets App Visibility, and runs a security scan. It stays a lab until ads, mail, login, and the sitemap print the name you mean to keep.

Rank the blast. Ads make a small leak big.

Start with the blast, not a prettier prompt restyle. A stranger who dumps every order row, burns your integration credits from an open function, or copies a live Stripe secret will cost more than a new landing screen. Rank those doors. Close the worst one tonight.

Blast rank — close the Base44 top layer first

  1. Off switch and restore

    Unpublish or a prior version you can publish back — not a new prompt on one laptop.

  2. Credit-using features left public

    AI, email, or image calls a stranger can hit and spend from.

  3. Unreviewed Publish

    Any collaborator can Publish. Workspace members can join the editor on their own.

  4. Table permissions and backend functions

    All Users on Read. No signed-in check on a function. Admin hidden only in the UI.

  5. App Visibility and the advertised origin

    Public with no login, a leftover .base44.app host, or ads that do not match the live domain.

  6. Secrets in chat, pages, and the client

    Keys in prompts, page code, or anywhere a visitor can view source.

Ads multiply whatever is already open. A preview click does not seal secrets. A Public no-login site does not hide writes. “We will prompt a fix” is not an unpublish.

Put six names on paper: who owns secrets, who proves login on the advertised URL, who can Publish, who watches credits and errors, who owns the public origin, and who can unpublish or restore a prior version tonight. Two red names plus a campaign date means spend stays off. If you cannot name a human for each layer, book.

Secrets: if the chat or a page saw it, treat it as leaked

Keys are the first thing ads will leak. The agent reads what you paste. Founders then drop Stripe secrets, OpenAI keys, and webhook tokens into the same thread. A later prompt does not wipe those words from history you already shared. Rotate anything that sat in plain text.

Base44’s security overview is the vendor drawer: store API keys in the encrypted secrets vault. Those values are only for your app’s backend. They are not for people using the app. The security scan looks for keys, passwords, or tokens left where visitors could find them. The scan does not move a key for you. You remove it, store it in secrets, and rotate the old value.

Stripe’s API keys guide is blunt. A publishable key (`pk_…`) can sit in the browser. A secret key (`sk_…`) cannot. Do not put a secret key in source, in a prompt, or in a page. If Base44 created live keys after you claimed the Stripe sandbox, treat those as vault values. If you pasted keys by hand, rotate them and save the new ones in secrets.

The quick start already points payments at the Secrets tab. Setting up Stripe (the January 2026 flow) says checkout runs on the published app, not in editor preview. That is the same rule for keys: the live URL must call a backend that reads the vault. If the only place the key still lives is a chat you are afraid to open, book.

Base44 gives you several addresses that look live. They are not the same job.

Three live origins — only one is the ad target

  1. 01 · Editor preview

    Lab

    Updates as you chat. Checkout and full sign-up often fail here.

  2. 02 · .base44.app host

    Default door

    Shareable the moment the app exists. Easy to paste by mistake.

  3. 03 · Published custom domain

    Ads

    The name you own, after Publish. The only public origin.

Preview is the lab. A leftover .base44.app share is a second origin. Production is the published URL or claimed domain you buy ads for. Mixing them is how the chat becomes the company.

App Visibility is the front door. Public: anyone can open the app, no sign-in. Private: invited people only, sign-in required (paid plans). Workspace: everyone in your Base44 workspace, sign-in required. Base44 will also guess: landing-page-shaped apps start as Public with no login. Change that before ads if the app takes money or personal data.

Visibility is not the same as login methods. Visibility answers “must a person sign in at all?” The Authentication page answers “email, Google, or something else?” New apps get custom login pages (shipped 2 June 2026). The reset link is hardcoded to `/reset-password`. Do not rename that page. Custom Google login that shows your domain, not base44.com, needs the Builder plan or higher and a custom domain. Keep the privacy policy public, not behind a login.

Connecting a domain does not publish the app. Buying a domain with Wix says you can connect first, but the name only goes live after Publish. Connecting an external domain keeps DNS at your registrar. Google Ads destination mismatch rejects an ad when the display URL domain does not match the final URL. Do not advertise your domain if clicks still land on `.base44.app`. Meta’s ad review also checks the destination. One host. The one you proved.

One more public door sits on Public apps: the platform badge. It says “Edit with Base44.” Anyone who clicks it can copy the app into their own account. Private apps hide the badge. Starter and above can turn it off. Ads on a Public app with the badge still on are a remix invite. Hide the badge, or do not buy the click.

Auth and row rules: a hidden admin page is not a gate

Rows are the next thing ads will leak. Base44 is good at wiring a sign-in screen. It is weaker at naming who may read a row after that screen. OWASP Top 10 2025 still ranks broken access control first. Hiding a link in the menu is the example they call a flaw. Access checks belong on the table and in the function — not in the paint of the page.

Data permissions are that seat list. Four rule types matter: All Users (even signed-out people), Creator Only (only the person who made the row), a field match to the signed-in person, and a role check. All Users on Create is fine for a public contact form. All Users on Read of those submissions is a leak. For a user portal, start with Creator Only on Read, Update, and Delete. Rules apply to the whole table, not one field. Changes take effect at once.

The security scan flags unauthenticated backend functions as “Anyone can run this function.” If the app requires login, the recommended fix requires a signed-in user. Test after — a public webhook can break. If the app is Public with no login, require login or check a provider signature or shared secret inside the function yourself.

A demo login that only works inside preview is a costume. Custom login pages can open in preview. The login docs still say: prove the full sign-up on the published URL with a real email. Logout must work after a hard refresh. Reset must land on `/reset-password` on the advertised domain. Admin must be a role check or a function check, not a page you hid from the nav. Act as a user writes to that person’s data. Use dummy users. It is not a private-window stranger test.

One more auth fact from the security overview: Base44 stores auth tokens in the browser’s localStorage. HttpOnly cookies are not available today. Extra scripts on the page can see the session. Keep extra widgets off until you need them. Do not paste a token into chat to “debug login.”

Run these four checks on the advertised URL. A preview pass with your editor session does not count:

  1. Every table or backend function that holds personal data or money checks identity, and public grants are named. A hidden admin route is not that proof.
  2. A stranger account cannot read another user’s row by changing an id in the URL or the API.
  3. Sign-up and sign-in work on the published host. Preview success is not that proof.
  4. Secret, admin, or Stripe secret keys never shipped to the client. Those keys skip row rules.

Unreviewed Publish is a write API on your ship path

The agent can change many files in one prompt. Two people in the same project can race. A chat Revert is an editor undo. It is not branch protection.

Collaborators are not the same as live-app Admins. Collaborators open the editor and the dashboard. Admins only sign in to the live app. A new collaborator is also added as an Admin in App Users by default. Change that live role if they should not manage customer rows. A contractor who can Publish can change what customers run.

Who can join the editor is its own setting. Most apps start as invited only. “Workspace members” makes anyone in the workspace a collaborator when they open the app. If you switch back, people who already joined stay unless you remove them. On most plans any workspace member can also invite outsiders. Name who can invite. Name who can Publish.

Enterprise workspaces can set publishing permissions by role, or require a publish request. On a solo Free or Starter project there is no such table. Then “anyone with the editor” is the Publish seat. Ads wait until that seat is named.

Off switch: a new prompt is not a host rollback

A bad release needs an off switch you can name tonight. Chat Revert takes the editor back. It does not take the live site back by itself.

You can unpublish. Dashboard → Settings → Danger Zone → Unpublish. People cannot open the app until you publish again. Data and settings stay. That is a real off switch. Use it when the live URL is unsafe. Do not wait on a new prompt.

Version History can publish a previous version while you keep the current draft. That is the restore you want before ads. Revert to this version replaces the draft instead. Those are different buttons. If you later connect GitHub (Builder plan or higher), versions from before the connect are not in the repo. After a merge to `main`, you still click Publish.

Row undo is a different product. Data version history snapshots entity rows on Elite (7 days) and Enterprise (30 days). Most MVPs do not have it. Export a CSV of the tables that hold money or personal data before you buy traffic if that history is not on your plan.

Watching: errors, credits, and a silent Public app

Watching without an off switch is half a lock. Before ads, name three signals: sign-in failures on the advertised URL, function errors after Publish, and credit or Stripe spend. The security scan flags “Prevent unauthorized credit usage” when AI, email, or image features can be reached from outside the app. A stranger who finds those calls can spend your monthly credits. If nobody owns the first 24 hours of spend, the campaign stays off.

App analytics can show visits and Stripe sales. That is a dashboard, not an on-call. Function logs under Code → Functions are where a dead checkout shows up. Name who opens those logs after Publish. One named person and one Danger Zone unpublish is the watch.

Wrap score — mark costume vs proof

Secrets

  • Costume

    Key in chat

  • Wrap

    Moved to vault

  • Proof

    Rotated + not in pages

Public name

  • Costume

    Ads list .base44.app

  • Wrap

    Domain connected

  • Proof

    Publish + Auth match

Auth / rows

  • Costume

    Hidden admin page

  • Wrap

    Rules listed

  • Proof

    Stranger cannot find rows

Review

  • Costume

    Anyone can Publish

  • Wrap

    One owner named

  • Proof

    Invite + Publish locked

Credits

  • Costume

    Public AI or email

  • Wrap

    Scan warning seen

  • Proof

    Calls behind auth

Off / watch

  • Costume

    “Prompt it back”

  • Wrap

    Prior version known

  • Proof

    Unpublish or restore hit

A green preview is not a wrap. A Publish from the top bar is still a Base44 ship — and that is fine for this page if public links no longer print the lab host.

Score each row against the advertised URL, not preview. One red cell — a key in chat, a Public no-login write, an open function, an open Publish seat, a credit feature a stranger can hit, or a rollback you have never hit — is enough to hold the spend. Move that cell. Do not greenwash the matrix.

The pre-ads week

Treat the next seven days as operator time on the Base44 project, not a slogan. Inventory who can Publish, who holds secrets, and which origin ads will hit. Then seal. Then prove. Leave the editor-exit pages closed until that list is honest.

Harden on Base44 — seven operator steps

  1. 01 →

    Inventory the public path

    Who can Publish. Who is collaborator. Which origin ads will hit. Where secrets still live.

  2. 02 →

    Seal secrets

    Drain chat, pages, and client files. Rotate. Put new values in the vault.

  3. 03 →

    Lock auth and rows

    Stranger cannot find another user’s row. Login works on the published URL.

  4. 04 →

    Lock Publish

    Named owners only. Invited-only editor. Review before Publish.

  5. 05 →

    Fix the URL map

    Custom domain live. Visibility named. No .base44.app in ads. Badge off if Public.

  6. 06 →

    Name watch and credits

    Who sees function errors, sign-in fails, and credit or Stripe spend.

  7. 07

    Rollback + watch, then buy

    Unpublish or prior version restored once. Then spend.

Do not buy ads in step one. Do not start the builder exit while a wrap step is red. Pair with the Base44 MVP hardening lander.

Day 0 is inventory. Write five facts. The public origin. The person who can Publish. Whether a live key still sits in chat or a page. Whether a stranger can read another user’s row. Whether you can unpublish or bring back a prior version tonight. If the public origin is already taking leads and you cannot name those five, stop. You do not need a new screen. You need this list.

Seal secrets first. Then rows. Then review. Bots do not wait for a nicer landing page. If a public table or function exists, prove it fails closed without a session. Then strip leftover `.base44.app` shares. Then unpublish once in a safe window, or publish a prior version once, so you know the off switch works. Then spend. The Base44 MVP hardening clipboard is the short list. This page is the week you run it.

Illustrative operator days before a Base44 ad buy

days

Unpriced Ads on a red list

3–5 wks

Campaign live. Doors still open. Cleanup later.

08162432Studio-observed calendar (not a bid, not a vendor SLA)Day 0–1Inventory + seats1 dayDays 1–3Secrets + vault1–3 daysDays 2–5Auth, rows, review2–5 daysDays 3–7Origin + rollback3–7 daysUnpricedAds on a red list3–5 wks

Illustrative operator days — not measured traffic, not a Source: Admin analytics series. Unpriced feature sprints on a public Base44 app often cost more than the wrap when the first leak hits.

Reserve these days before paid traffic. Overlap is allowed. Skipping inventory to “buy a small test” is how the default host becomes the company.

Treat those bars as calendar you reserve, not a vendor promise. If you cannot name the advertised origin, who can Publish, and who can restore a prior ship, the later days will thrash. The long bar is the expensive miss: a “small” test while a Public table or an open function is still the company.

Stay-harden vs leave. Do not mix the seats.

Pick one seat for this week. Stay-harden keeps Base44 as the host, with secrets in the vault, a published domain as the origin, locked Publish, and a rollback already proved. Leave opens get-off Base44 and stops buying clicks that need that editor window. Running both seats at once is how teams rebuild screens they already had.

Stay-harden vs exit — pick one seat

Stay-harden (this page)

  1. Studio still in Base44

    Chat still plans. You accept the agent and the bill.

  2. Doors closed on that path

    Secrets, visibility, auth, review, credits, rollback.

  3. Ads wait for green

    A red layer pauses spend, not the product.

If the public origin must leave Base44 hosting, stop this wrap and open the exit. If ads are close and the origin can stay on a published URL you control, finish the wrap first. ↓

Leave (other pages)

  1. Process leaves Publish App

    ZIP or GitHub plus a host you run. See get-off and migrate.

  2. A live Publish is not the exit

    The top-bar Publish is still that vendor path until your host owns ship.

  3. Kill the editor-only ship

    App still answers when the chat is closed.

This article is the left column. Get off Base44 and migrate from Base44 are the right. To-production is the first owned ship. Do not paste them here.

If you only need a leave date, use when to leave an AI builder. A door that will not close belongs on rewrite vs harden. A personal Git remote belongs on GitHub handoff. A Publish-only ship path belongs on CI/CD after an AI builder. Cousin wraps: a0, Windsurf, Bubble, Framer, v0, Lovable, Replit. Those pages are not this Publish week.

Wrap loop — prove, then decide

  1. 01

    Prove the door

    One layer. One test on the advertised URL.

  2. 02

    Close it

    Rotate, redirect, add identity checks, lock Publish, or restore a prior version.

  3. 03

    Re-check ads list

    If a layer is still red, spend stays off.

  4. 04 · loops

    Stay or leave

    Green wrap can stay. Red host row opens the exit.

Do not buy ads inside the loop. Do not leave Base44 inside the loop. Exit the loop when the wrap is green or the ship path must move.

When the list turns red

Leave the product up. Kill the campaign if any of these are still true:

  • A live key still exists only in Base44 chat, a prompt, a page, or the client bundle.
  • A table or function that holds personal data or money is still readable without a named identity check.
  • Ads, mail, or the sitemap still list a preview host or a leftover `.base44.app` name you do not mean to keep.
  • Anyone with the editor can still Publish, or workspace members can join the editor on their own.
  • A credit-using feature is still reachable without a signed-in user.
  • The off switch is “we will write a new prompt,” or you have never unpublished or restored a prior version.
  • Two people disagree about who can Publish or who holds admin.

A single red door is a miss, even if preview is green. Stop adding screens until secrets, row rules, locked Publish, and the rollback are honest. Finish that wrap. Then spend — or open get-off Base44 if the editor is still the company.

Bring a second pair of hands when the founder cannot rotate a key without pasting it back into chat, when a stranger can still find another user’s row, or when nobody has unpublished or restored a prior version before the date. Hire for secrets, table locks, collaborator seats, and the URL map — not a prettier Base44 screen. Austin app development company is the studio brief. Austin mobile app development if the next door is a store binary that still points at this Base44 URL.

Next steps

Walk the gates in order. Inventory the public origin, the person who can Publish, and who holds collaborator access. Drain chat and page secrets into the vault. Rotate anything that appeared there. Fail-close identity checks on every table or function that holds personal data. Lock Publish. Strip leftover `.base44.app` shares from ads, mail, sitemap, and Auth. Turn the platform badge off if the app is Public. Prove a stranger test on the live URL. Unpublish or restore a prior version once. Then buy the click — or open the exit if the process itself must leave Base44.

CodeCross LLC is an Austin-registered product studio (1606 Headway Cir STE 9212, Austin, TX). The Base44 week we run is vaulted secrets, published-domain origin, auth and row locks, locked Publish, then an unpublish or Version History restore. The Austin app development company page is the studio brief. Austin mobile app development is the store-binary door if a signed build still points at this Base44 URL. Company-level evidence lives on proof. When the off switch, secret drawers, or the advertised origin is still red, book a conversation.

Base44 is allowed to stay the host. Ads are not allowed to treat a preview pass, a Public no-login write, or an unreviewed Publish as that proof. Show an unpublish or a prior version you can restore, tables that fail closed for strangers, and keys that never lived in chat. Most teams never need a second codebase once those three exist.

FAQ

When preview looks good, did the published URL receive the same data?

No. Preview updates as you chat. Publish is what puts the latest snapshot on the live address. Stripe checkout and the full sign-up flow are meant to be proved on the published URL. Local rows, a warm editor session, and laptop preview do not move with that click. Prove the money path on the advertised host with stranger-like accounts.

Does clicking Publish finish the wrap?

No. Publish puts your latest changes on the live URL. That is a ship path, not a wrap. Stay-harden is fine if ads, mail, sitemap, and Auth redirects print the name you mean to keep. It is not fine if the campaign still lists the lab host. Leaving Base44 as the ship path is the get-off job, not this page.

If preview can find a row, does that search exist on the published URL for a stranger?

Not as proof. Your editor session is not a stranger. Data permissions apply on the table, not in a hidden screen. A preview pass can look closed while All Users on Read still returns every document. Act as a user is still you inside the project. Prove a private-window account on the published URL cannot find another user’s row.

Can I paste keys into Base44 prompts and buy ads?

No. The security overview says keys belong in the secrets vault and only the backend should read them. The security scan will flag credentials left where visitors can find them. Stripe says secret keys are never safe in front-end code. Rotate anything that appeared in chat or a page. Do not buy ads on a red drawer.

Does hiding the admin page stop a stranger from writing Base44 rows?

Hiding a link is not a lock. Table permissions and backend checks govern read and write. A public function or an All Users grant the agent left on a money table is a write API. OWASP calls a front-end-only admin gate a flaw: the same URL still answers if you ask another way. Use Creator Only, a field match, or a User Property Check on the table, and require a signed-in user in the function. A shared admin login is a miss.

Is “we will write a new prompt” an off switch?

No. Chat Revert changes the draft in the editor. It does not take the live site down. Unpublish from Settings → Danger Zone is the real stop. Version History can publish a previous version without replacing your current draft. Name the publish owner. Hit one of those once before ads.

Does a green preview plus Publish mean ads are safe?

No. The quick start already says the app is shareable as soon as it exists. Publish only updates what that door shows. App Visibility can still be Public with no login. The security scan can still be out of date. A green preview on one machine is a lab. Lock who can Publish. Require a stranger test on the live URL. Then talk about spend.

Book a call

Thirty minutes with a senior teammate — honest next steps.

Ready to price an Austin build?

Bring the problem, the users, and a budget ceiling. We’ll tell you whether an app is the right next spend — and what the first year actually costs.

Prefer writing? Send project details on the contact page.