Skip to main content

EngineeringCodeCross Team

Harden an Emergent MVP before paid traffic (2026)

A 2026 guide for founders still shipping from Emergent Publish: rank the blast (keys in chat, sleeping preview as the ad origin, preview Mongo mistaken for prod, open FastAPI writes, anyone can Re-publish, no Shutdown), prove the doors on the live URL, then decide to stay on Emergent or leave.

Engineering

14 min

Preview
Sleeps

Not the ad host

Secrets
Pane only

Not chat or .env

Ads
After

Published URL proof

Citation-ready answer: Harden an Emergent MVP before paid traffic by moving keys out of chat into Preview → Manage → Secrets and the production secret pane. Prove preview Mongo is not the live store. Require a real sign-in on every FastAPI write. Point ads at the published host or your domain, not a sleeping preview. Name who can Publish or Re-publish. Hit Shutdown once so you know the off switch works. Then buy ads.

This note is from CodeCross, an Austin, Texas app development company (Pakistan engineering on a US Central overlap). Other tools sit on vibe coding. Buying help is the Austin app development company page. If nobody can name a Shutdown tonight, book a conversation.

Money leaves when the campaign still lists a `*.preview.emergentagent.com` link that sleeps after about 30 minutes, a leftover `.emergent.host` name after you claimed a domain, or a Stripe secret that sat in chat. A stranger can read every order because the FastAPI route never asked who they are. Anyone who can open the workspace can hit Re-publish. The only undo is “we will ask the agent to revert.” A green preview is not a stranger test on the URL you would put on a billboard.

This essay is the week before you buy ads, while the app still lives on Emergent hosting. Close the risky doors while Publish still serves the live site. It expands Harden an Emergent MVP before strangers hit Deploy. Emergent now calls that click Publish and Re-publish. The lander still says Deploy. Same job. This page is not Emergent to production, get off Emergent, migrate from Emergent, or transition from Emergent. The question here is narrower: can you buy a click while Emergent still hosts the app? When secrets, the advertised origin, or the off switch is still open, book.

The short lists live on the other Emergent pages named above. This essay is the week you prove the live URL before you buy ads.

Stay on Emergent. Close the doors first.

Emergent is paid to turn a chat into a running app tonight. Paid traffic is paid to send strangers at a public URL. Those jobs collide. A green preview can still leave a key in chat, a sleeping preview as the share link, or Re-publish open to every collaborator.

What the agent builds is a full stack. Platform documentation names the parts: React for the screens, Python FastAPI for the server, MongoDB for the store. Mobile app development adds Expo on paid plans. You do not need a new builder this week. You do need to name who can Publish, who holds secrets, and which origin ads will hit.

Put your app live draws the line in vendor words. Preview is the workspace copy. It sleeps after about 30 minutes of no use. It is not meant for real users. Publish puts the app on a permanent address such as `https://your-app-name.emergent.host`. That address stays up 24/7. Re-publish later updates the live code. It does not add a new hosting fee. The toolbar reads Publish the first time and Re-publish after that. Re-publish opens Manage Publishing first — domains, secrets, and shutdown live there.

Rank the blast. Ads make a small leak big.

Start with the blast, not a prettier prompt restyle. A stranger who dumps every order row, burns your credit balance from an open route, or copies a live Stripe secret will cost more than a new landing screen. Rank those doors. Close the worst one tonight.

Blast rank — close the Emergent top layer first

  1. Off switch and credit watch

    Shutdown you have hit once — not a new prompt on one laptop. Credits watched on one balance.

  2. Unreviewed Publish or Re-publish

    Anyone with the workspace can push live code. No named owner.

  3. FastAPI writes with no signed-in check

    A hidden admin screen in React. An open route that returns every document.

  4. Preview Mongo mistaken for production

    First Publish copies preview data once. After that the two stores diverge. Re-publish does not copy rows.

  5. Preview host vs published origin

    Ads, mail, or Auth that still print *.preview.emergentagent.com or a leftover .emergent.host after you claimed a domain.

  6. Secrets in chat, .env, and the client

    Keys pasted into prompts, left in frontend code, or changed only in .env after first Publish.

Ads multiply whatever is already open. A preview click does not seal secrets. A sleeping preview is not a campaign host. “We will ask the agent to revert” is not Shutdown.

Put six names on paper: who owns secrets, who proves login on the advertised URL, who can Publish or Re-publish, who watches credits and errors, who owns the public origin, and who can hit Shutdown tonight. Two red names plus a campaign date means spend stays off. If you cannot name a human for each layer, book.

Secrets: if the chat saw it, treat it as leaked

Keys are the first thing ads will leak. The agent reads what you paste. Founders then drop Stripe secrets, OpenAI keys, and webhook tokens into the same thread. A later prompt does not wipe those words from history you already shared. Rotate anything that sat in plain text.

Emergent’s own glossary is blunt. Never paste real secrets into the chat. Chat content goes to the AI provider. Ask the agent to read keys from environment variables. Enter real values under Preview → Manage → Secrets → Custom keys. The Secrets UI can edit values of keys that already exist. It cannot add or delete keys. To add a new name, the agent puts it in `.env`, then you Re-publish.

That last step has a trap. Deployment types says existing production secrets are never overwritten. A later `.env` change does not update a key that already went live. Only new key names get added. To change a live Stripe secret you must edit it in the production secret pane, not only in `.env`. If you pasted a live key into chat last week, rotate it at the issuer first. Then save the new value in that pane.

How apps work adds the frontend rule. Everything in frontend code is visible to users. Never put passwords, API keys, or secrets in React. FastAPI — the Python server — is the place those values may live, read from the environment. Stripe’s API keys guide is the same split. A publishable key (`pk_…`) can sit in the browser. A secret key (`sk_…`) cannot. Do not put a secret key in source, in a prompt, or in a page. If the only place the key still lives is a chat you are afraid to open, book.

Preview sleeps. The published host is the ad target.

Emergent gives you several addresses that look live. They are not the same job.

Three live origins — only one is the ad target

  1. 01 · Preview host

    Lab

    *.preview.emergentagent.com. Sleeps after about 30 minutes. Not for real users.

  2. 02 · .emergent.host

    Default door

    Permanent after Publish. Anyone can open it unless you built login.

  3. 03 · Your domain

    Ads

    The name you own, after you link it. The only public origin.

Preview is the lab and it sleeps. A leftover .emergent.host share is a second origin. Production is the published URL or claimed domain you buy ads for. Mixing them is how the chat becomes the company.

Platform documentation prints the three shapes. Preview looks like `app.preview.emergentagent.com` and lasts about 30 minutes with no use. Deployed looks like `app.emergent.host` and stays on. Your domain is the third. Previewing and iterating lets you share the preview with teammates. It also says the preview may reset or go away if the workspace sits idle. That is a lab link. It is not a campaign URL.

Put your app live and publishing your web app both say the published address can be shared with anyone. No login is required unless you built one. The link stays the same when you Re-publish. That is useful. It is also a public door the moment Publish finishes. If the app takes money or personal data, prove a stranger must sign in before they can write.

A custom domain is a later door. It does not close the other doors by itself. Plans and credits and Emergent pricing put custom domains on Standard ($20 / month) and Pro ($200 / month), not Free. Free also has no deployments and no GitHub. After you link a name, platform documentation tells you to update payment processors and OAuth to the new domain. Leave those callbacks on `.emergent.host` and login will bounce strangers back to the old host.

Google Ads destination mismatch rejects an ad when the display URL domain does not match the final URL. Do not advertise your domain if clicks still land on `.emergent.host`. Google Search Central wants one preferred URL when two hosts show the same app. Link ads, mail, and in-app shares to that one name. Meta’s ad review also checks the destination. One host. The one you proved.

Auth and row rules: a hidden admin page is not a gate

Rows are the next thing ads will leak. Emergent is good at wiring a sign-in screen. It is weaker at naming who may read a row after that screen. OWASP Top 10 2025 still ranks broken access control first. One of their examples is an admin check that lives only in the front end. A stranger who calls the same URL another way still gets in. Access checks belong on the FastAPI route — not in the paint of the React page.

Mongo on Emergent is two stores after the first Publish. Preview vs published says the first Publish copies preview data once into the new production database. After that the two databases are independent. Re-publish copies code, config, and assets. It does not touch the live Mongo. Rows you typed in preview after that first Publish do not appear in production. Rows strangers create on the live URL do not appear in preview. Mix those stores and you will test the wrong data.

The glossary adds two operator facts. The managed Mongo cluster only accepts Emergent-internal connections. You cannot point an outside client at that URI. Edits in the workspace Database Manager are live and cannot be undone. Platform documentation says the agent cannot see the deployed database unless you share logs. A preview pass with your workspace session is not a stranger test on production rows.

If you later move the store, Database (MongoDB) is the remap: Preview → Manage → Secrets, then `MONGO_URL` — not `DATABASE_URL`. Do not point live Auth at a preview URI.

Run these four checks on the advertised URL. A preview pass with your workspace session does not count:

  1. Every FastAPI route that holds personal data or money checks identity, and public grants are named. A hidden admin route in React is not that proof.
  2. A stranger account cannot read another user’s row by changing an id in the URL or the API.
  3. Sign-up and sign-in work on the published host. Preview success is not that proof.
  4. Secret, admin, or Stripe secret keys never shipped to the React bundle. Those keys skip row rules.

Unreviewed Publish can change the live app

The agent can change many files in one prompt. Two people in the same project can race. A chat undo is an editor undo. It is not branch protection.

GitHub integration exists on Standard and Pro. Free does not get it. Save to GitHub, pick a repo, pick a branch, then PUSH TO GITHUB. That is a backup and a second pair of eyes. It does not lock who can Publish. Ads can still run on Emergent hosting after a Push. The smaller question is this: who may click Publish or Re-publish today? Name that person. If two people can race a Re-publish, spend stays off.

Mobile is a second way to put the app live. It is not a second check. Publishing to the stores says native builds come from your last published code. Emergent runs EAS for you. It does not support over-the-air updates. A JavaScript-only change still needs Re-publish, a new build, and a store submit. Prove the URL ads hit. Do not mix the store listing and the web host.

Off switch: a new prompt is not Shutdown

A bad release needs an off switch you can name tonight. Asking the agent to revert takes the draft back. It does not take the live site back by itself.

Put your app live names the real stop. In the Overview tab, use Take app offline → Shutdown. The app stops answering at its web address. The monthly publish charge stops. Your project, code, chat history, subscription, and credit balance stay. That is a real off switch. Use it when the live URL is unsafe. Do not wait on a new prompt.

Shutdown has a catch. If a custom domain is linked, shutting down removes the link. It does not come back when you Publish again. Re-add the domain in the Domain tab. A revived Publish starts on the base hosting tier. If you had raised the tier, set it again. Publishing your web app adds one more fact: Shutdown does not delete Mongo or outside services. Data stays until you delete it on purpose.

Re-publish is not rollback. Preview vs published says a failed Re-publish leaves the live app alone. That is a safety net for a bad push. It is not last Tuesday’s code after a good push already landed. Name the GitHub tag or Replace job you would use tonight. Hit Shutdown once in a safe window before ads so you know the button works.

Watching: errors, credits, and a silent public host

Watching without an off switch is half a lock. Before ads, name three signals: sign-in failures on the advertised URL, FastAPI errors after Re-publish, and credit burn. Managing credit usage puts agent runs, published versions, and outside API calls on one balance. The workspace shows that balance in the top right. Account Settings → Credit Usage breaks it down. You can set a maximum credits per prompt so a long agent plan must ask before it overruns.

Hosting is a second burn on that same wallet. Put your app live prices a live app at 50 to 1,100 credits per month, by publishing tier. Starter is 50. Shutdown stops that charge at once. The glossary values credits at 1 USD = 5 credits. There is no overage bill. When the balance hits zero, the current job pauses. If nobody owns the first 24 hours of spend, the campaign stays off.

Score — mark pretend vs proof

Secrets

  • Costume

    Key in chat

  • Started

    Moved to pane

  • Proof

    Rotated + not in React

Public name

  • Costume

    Ads list preview

  • Started

    Domain linked

  • Proof

    Publish + Auth match

Auth / rows

  • Costume

    Hidden admin page

  • Started

    Routes listed

  • Proof

    Stranger cannot find rows

Review

  • Costume

    Anyone can Re-publish

  • Started

    One owner named

  • Proof

    Publish locked + GitHub saved

Credits

  • Costume

    No owner, no cap

  • Started

    Balance watched

  • Proof

    Cap + 24h owner

Off / watch

  • Costume

    “Ask the agent”

  • Started

    Shutdown known

  • Proof

    Shutdown hit once

A green preview is not proof. A Publish from the toolbar still uses Emergent hosting — and that is fine for this page if public links no longer print the sleeping host.

Score each row against the advertised URL, not preview. One red cell — a key in chat, a preview host in ads, an open FastAPI write, an open Re-publish seat, a credit burn nobody watches, or a Shutdown you have never hit — is enough to hold the spend. Move that cell. Do not greenwash the matrix.

The week before you buy ads

Treat the next seven days as operator time on the Emergent project, not a slogan. Inventory who can Publish, who holds secrets, and which origin ads will hit. Then seal. Then prove.

Harden on Emergent — seven operator steps

  1. 01 →

    Inventory the public path

    Who can Publish. Which origin ads will hit. Where secrets still live. Preview vs prod Mongo named.

  2. 02 →

    Seal secrets

    Drain chat and React files. Rotate. Put new values in the secret pane. Do not trust a later .env edit.

  3. 03 →

    Lock auth and rows

    Stranger cannot find another user’s row. Login works on the published URL.

  4. 04 →

    Lock Publish

    Named owners only. Save to GitHub if the plan allows it. Review before Re-publish.

  5. 05 →

    Fix the URL map

    Custom domain live if you have one. No preview host in ads. OAuth and Stripe point at the same name.

  6. 06 →

    Name watch and credits

    Who sees FastAPI errors, sign-in fails, and the one credit balance.

  7. 07

    Shutdown + watch, then buy

    Hit Shutdown once in a safe window, or prove the prior job you would Replace. Then spend.

Do not buy ads in step one. Do not start the builder exit while a step is still open.

Day 0 is inventory. Write five facts. The public origin. The person who can Publish. Whether a live key still sits in chat or React. Whether a stranger can read another user’s row. Whether you can hit Shutdown tonight. If the public origin is already taking leads and you cannot name those five, stop. You do not need a new screen. You need this list.

Seal secrets first. Then rows. Then review. Bots do not wait for a nicer landing page. If a public FastAPI route exists, prove it refuses the write when nobody is signed in. Then strip leftover preview shares. Then Shutdown once in a safe window so you know the off switch works. Then spend. This page is the week you run that list.

Illustrative operator days before an Emergent ad buy

days

Unpriced Ads on a red list

3–5 wks

Campaign live. Doors still open. Cleanup later.

08162432Studio-observed calendar (not a bid, not a vendor SLA)Day 0–1Inventory + seats1 dayDays 1–3Secrets + pane1–3 daysDays 2–5Auth, rows, review2–5 daysDays 3–7Origin + Shutdown3–7 daysUnpricedAds on a red list3–5 wks

Illustrative operator days — not measured traffic, not a Source: Admin analytics series. Unpriced feature sprints on a public Emergent app often cost more than this week when the first leak hits.

Reserve these days before paid traffic. Overlap is allowed. Skipping inventory to “buy a small test” is how the sleeping preview becomes the company.

Treat those bars as calendar you reserve, not a vendor promise. If you cannot name the advertised origin, who can Publish, and who can hit Shutdown, the later days will thrash. The long bar is the expensive miss: a “small” test while a preview host or an open FastAPI route is still the company.

Stay on Emergent, or leave. Do not mix the two jobs.

Pick one job for this week. Stay keeps Emergent as the host, with secrets in the pane, a published domain as the origin, locked Publish, and a Shutdown already proved. Leave opens get-off Emergent and stops buying clicks that need that workspace window. Running both jobs at once is how teams rebuild screens they already had.

Stay or leave — pick one job

Stay (this page)

  1. Studio still in Emergent

    Chat still plans. You accept the agent and the credit bill.

  2. Doors closed on that path

    Secrets, origin, auth, review, credits, Shutdown.

  3. Ads wait for green

    A red layer pauses spend, not the product.

If the public origin must leave Emergent hosting, stop this page and open the exit. If ads are close and the origin can stay on a published URL you control, finish these doors first. ↓

Leave (other pages)

  1. Process leaves Publish

    GitHub plus a host you run. See get-off and migrate.

  2. A live Publish is not the exit

    The toolbar Publish is still that vendor path until your host serves the live app.

  3. Kill the workspace-only ship

    App still answers when the agent UI is closed.

This article is the left column. Get off Emergent and migrate from Emergent are the right. To-production is the first host you run yourself. Do not paste them here.

If you only need a leave date, use when to leave an AI builder. A door that will not close belongs on rewrite vs harden. A personal Git remote belongs on GitHub handoff. A Publish-only live path belongs on CI/CD after an AI builder. Other builder pages: Base44, a0, Windsurf, Bubble, Framer, v0, Lovable, Replit. Those pages are not this Publish week.

Check loop — prove, then decide

  1. 01

    Prove the door

    One layer. One test on the advertised URL.

  2. 02

    Close it

    Rotate, redirect, add identity checks, lock Publish, or hit Shutdown.

  3. 03

    Re-check ads list

    If a layer is still red, spend stays off.

  4. 04 · loops

    Stay or leave

    Closed doors can stay. An open host row opens the exit.

Do not buy ads inside the loop. Do not leave Emergent inside the loop. Exit the loop when the doors are closed or the live path must move.

When the list turns red

Leave the product up. Kill the campaign if any of these are still true:

  • A live key still exists only in Emergent chat, a prompt, a React file, or an `.env` you never copied into the production pane.
  • A FastAPI route that holds personal data or money is still readable without a named identity check.
  • Ads, mail, or the sitemap still list a preview host or a leftover `.emergent.host` name you do not mean to keep.
  • Anyone with the workspace can still Publish or Re-publish.
  • Nobody owns the credit balance, or the wallet can hit zero with no named person.
  • The off switch is “we will ask the agent,” or you have never hit Shutdown.
  • Two people disagree about who can Publish or who holds admin.

A single red door is a miss, even if preview is green. Stop adding screens until secrets, row rules, locked Publish, and the rollback are honest. Finish those doors. Then spend — or open get-off Emergent if the workspace is still the company.

Bring a second pair of hands when the founder cannot rotate a key without pasting it back into chat, when a stranger can still find another user’s row, or when nobody has hit Shutdown before the date. Hire for secrets, FastAPI locks, Publish seats, and the URL map — not a prettier Emergent screen. Austin app development company is the studio brief. Austin mobile app development if the next door is a store binary that still points at this Emergent URL.

Next steps

Walk the gates in order. Inventory the public origin, the person who can Publish, and who holds workspace access. Drain chat and React secrets into the pane. Rotate anything that appeared there. Add identity checks that refuse the write when nobody is signed in, on every FastAPI route that holds personal data. Lock Publish. Strip leftover preview shares from ads, mail, sitemap, and Auth. Prove a stranger test on the live URL. Hit Shutdown once in a safe window. Then buy the click — or open the exit if the process itself must leave Emergent.

CodeCross LLC is an Austin-registered product studio (1606 Headway Cir STE 9212, Austin, TX). The Emergent week we run is vaulted secrets, published-domain origin, auth and row locks, locked Publish, then a Shutdown you have already hit. The Austin app development company page is the studio brief. Austin mobile app development is the store-binary door if a signed build still points at this Emergent URL. Company-level evidence lives on proof. When the off switch, secrets, or the advertised origin is still open, book a conversation.

Emergent is allowed to stay the host. Ads are not allowed to treat a preview pass, an open FastAPI write, or an unreviewed Re-publish as that proof. Show a Shutdown you can hit, routes that refuse a stranger who is not signed in, and keys that never lived in chat. Most teams never need a second codebase once those three exist.

FAQ

Which Emergent URL should the ad open?

Put your app live says Publish puts the app on a permanent address such as `https://your-app-name.emergent.host`. That address stays up 24/7. Preview looks like `*.preview.emergentagent.com`. Previewing and iterating says it may reset or go away if the workspace sits idle. It sleeps after about 30 minutes. Do not put that link in an ad. After you claim a domain, platform documentation says update payment processors and OAuth to the new name. Google Ads destination mismatch rejects an ad when the display URL domain does not match the final URL. Do not advertise your domain if clicks still land on `.emergent.host`. Google Search Central wants one preferred URL. Meta’s ad review also checks the destination. One host. The one you proved.

Does Re-publish copy preview Mongo onto the live store?

No. Preview vs published copies preview data once on first Publish. After that the two Mongo stores are separate. Re-publish copies code, config, and assets. It does not copy rows. Rows you type in preview after that first Publish do not appear on the live URL. Rows strangers create on the live URL do not appear in preview. The glossary says the managed Mongo cluster only accepts Emergent-internal connections. Platform documentation says the agent cannot see the deployed database unless you share logs. Prove the money path on the advertised host.

Do I need to hit Shutdown before I spend?

Yes. Hit it once in a safe window so you know the button works. Put your app live names the real stop. In the Overview tab, use Take app offline → Shutdown. The app stops answering at its web address. The monthly publish charge stops. Your project, code, chat history, subscription, and credit balance stay. If a custom domain is linked, shutting down removes the link. It does not come back when you Publish again. Re-add the domain in the Domain tab. A revived Publish starts on the base hosting tier. Publishing your web app says Shutdown does not delete Mongo or outside services. Asking the agent to revert is not this button.

How do I cap credits the week ads go live?

Managing credit usage puts agent runs, published versions, and outside API calls on one balance. The workspace shows that balance in the top right. Account Settings → Credit Usage breaks it down. Set a maximum credits per prompt so a long agent plan must ask before it overruns. Put your app live prices a live app at 50 to 1,100 credits per month. Starter is 50. Shutdown stops that charge at once. The glossary values credits at 1 USD = 5 credits. There is no overage bill. When the balance hits zero, the current job pauses. Name who watches the first 24 hours. If nobody owns that, keep spend off.

If I ask the agent to roll back, do the ads stop?

No. A chat undo changes the draft in the workspace. It does not take the live site down. Shutdown from Take app offline is the real stop. Re-publish is not rollback. Preview vs published says a failed Re-publish leaves the live app alone. That is a safety net for a bad push. It is not last Tuesday’s code after a good push already landed. Name the GitHub tag or Replace job you would use tonight. Hit Shutdown once before ads.

Who may click Re-publish on the day ads start?

Name one owner. Anyone who can open the workspace can hit Re-publish today unless you change that. GitHub integration exists on Standard and Pro. Free does not get it. Save to GitHub is a backup and a second pair of eyes. It is not a lock on who can Publish. If two people can race a Re-publish, keep spend off.

What should I check on the live URL the morning ads start?

Sign-in must work on the published host. Preview success is not that proof. Every FastAPI route that holds personal data or money must check who the person is. If nobody is signed in, the route must refuse the write. Ads, mail, and Auth must point at one host — the published URL or your domain, not the sleeping preview. The credit cap must be set. You must have already hit Shutdown once. Then buy the click.

Book a call

Thirty minutes with a senior teammate — honest next steps.

Ready to price an Austin build?

Bring the problem, the users, and a budget ceiling. We’ll tell you whether an app is the right next spend — and what the first year actually costs.

Prefer writing? Send project details on the contact page.