EngineeringCodeCross Team
Harden a Softgen MVP before paid traffic (2026)
A 2026 wrap-in-place playbook for founders still building in Softgen: rank the blast (Secrets panel vs NEXT_PUBLIC_, preview vs Vercel auth, open signup, row rules, Softgen hostname leaks, restore), prove the doors before ads, then decide stay-harden vs exit.
Engineering
14 min
- Secrets
- Sealed
- Login
- Published host
- Ads
- After
Not chat or NEXT_PUBLIC_
Not preview only
Proof first
Citation-ready definition: Hardening a Softgen MVP before paid traffic in 2026 means you stay on Softgen. You close the doors ads will hit, then prove they are closed. Secrets sit in the Secrets panel, not chat or a `NEXT_PUBLIC_` name. Login is a real session on the published Vercel host. Signup is not an open bot door. Row rules hold. Ads and mail do not print a Softgen preview URL. You have run a restore. A Publish click is not that proof.
The expensive 2026 miss is rarely “we picked Softgen.” It is “we bought ads on a preview that still lives inside Softgen.” A founder can click Publish. A stranger can finish signup. A key still sits in chat or in a `NEXT_PUBLIC_` name the Next.js build ships to the browser. Login still works only in the Softgen preview. Ads and reset mail still print a Softgen preview host or a leftover `.vercel.app`. A converting preview hides that gap. A leaked screenshot, a bot on signup, or a restore you never tried will not.
This article is the wrap-in-place week while you still build in Softgen and ship through its Vercel path. It expands Harden a Softgen MVP before paid traffic. It is not the runtime exit on get off Softgen, not the extract on migrate from Softgen, not the overlap week on transition from Softgen, not the first useful ship on Softgen to production, not the Lovable wrap on harden a Lovable MVP before paid traffic, not the Replit wrap on harden a Replit MVP before paid traffic, and not the Bolt wrap already shipped as Bolt MVP hardening without a rewrite. Those pages move the host or redo another builder. This page asks one thing: can you buy a click while Softgen is still the process? Soft CTA: when that list turns red, book.
Use the short pages for punchy lists. Softgen MVP hardening is the wrap. Softgen to production is preview-is-not-prod. Get off Softgen is the runtime exit. Migrate from Softgen is extract. Transition from Softgen is the overlap week. The vibe coding hub maps other tools. This essay stays the pre-ads wrap on Softgen.
Stay on Softgen. Close the doors first.
Softgen is paid to make tonight live. Ads are paid to send strangers at that URL. Those jobs collide. A green Publish click feels finished. The company is unfinished if a stranger can burn quota, read a key, or land on a lab hostname.
Softgen’s own docs draw the line. The FAQ is plain: hosting for production is not included. During development you get a preview. When you go live, Softgen points you at Vercel for the frontend and at Firebase or Supabase for the backend. How Softgen works names that preview as the review step. Capabilities lists deployment as a Vercel integration. Preview is the working view. It is not the wrap.
Deploy your app with Vercel gives two doors. One: open Deployment, click Deploy with Vercel, and log into your Vercel account. Two: click Publish and let Softgen handle the deploy. Connect a custom domain repeats the split — Deploy with Softgen, or deploy with your Vercel account. Then you add a name. DNS can take up to 48 hours. Neither door is a reason to leave this week. Both are a reason to stop buying ads until you can name who owns the Vercel project, who can Publish, and which URL ads will hit.
Rank the blast. Ads make a small leak big.
Do not polish screens first. Rank what a stranger can break. Then close the worst door. Then the next. A pretty Softgen home page with an open signup is a bill, not a launch.
Blast rank — close the Softgen top layer first
Restore drill
A Pro CSV of one table is not a backup. Version history reverts code, not rows. A restore you have not run is a wish.
Softgen and vercel.app in public links
Ads, mail, sitemap, and login links that still print the preview host or a leftover .vercel.app.
Rows and files
A hidden Softgen button is not a row rule. Platform-managed Supabase still needs RLS. A public bucket is a public file.
Open signup and bots
Generated email auth with no confirm, no rate limit on reset, and a public form ads will feed.
Auth on the published host
Softgen preview login is not the Vercel URL. Redirects must match the name people type.
Secrets and env
Chat paste, Secrets panel vs NEXT_PUBLIC_ names the Next.js build ships, service-role keys in the client.
Write the rank on paper this week. Secrets first. Login second. Signup third. Row rules fourth. Public hostname fifth. Restore last. If two of those are still red and a campaign is on the calendar, pause the spend. Soft CTA: if you cannot name a human for each layer, book.
Secrets: the panel is not a vault. NEXT_PUBLIC_ is public.
Keys are the first thing ads will leak. Softgen’s Import from GitHub page is the split. Environment variables and secrets do not travel with the clone. You add them by hand in the project Secrets panel. That is good hygiene after an import. It is not a company vault if the same key also lives in chat.
Softgen starts from a Next.js boilerplate. Next.js environment variables are blunt: a name prefixed with `NEXT_PUBLIC_` is inlined into the JavaScript the browser downloads. Treat every `NEXT_PUBLIC_` value as public. Softgen’s Supabase onboarding already lists the pair you will see: `NEXT_PUBLIC_SUPABASE_URL` and `NEXT_PUBLIC_SUPABASE_ANON_KEY`. Those two are meant to be public. `SUPABASE_SERVICE_ROLE_KEY` is not. That key bypasses row-level security. Keep it on the server. Never put it in a `NEXT_PUBLIC_` name, a committed `.env`, or a Softgen prompt.
If you pasted a live Stripe, OpenAI, or Resend key into the Softgen thread, assume it leaked. Rotate it at the issuer. Then store the new value in the Secrets panel, not in chat history. Team collaboration adds a second leak path. Invited members can work the project. They spend the owner’s tokens. If they can open Secrets or the chat, they can copy a live key. Remove anyone who does not need the drawer before ads.
The pass is simple. A viewer of the public app cannot open the Softgen editor. Customers get the published Vercel URL. The editable project stays with people you named. If “anyone with the link” can still open Secrets or the thread, you are not ready for ads.
Login must work on the hostname people type
A demo login is any path that signs a stranger in only inside the Softgen preview. Softgen’s Firebase authentication page says the quiet part: test login flows in preview, then deploy. Frontend vs Full Stack is sharper. Frontend mode has no user authentication. Full Stack adds Firebase Auth or, today, one-click platform-managed Supabase. That is the start. It is not the wrap. Preview success is not published-host proof.
Softgen can create a Supabase project for you. Credentials are auto-configured. Auth, storage, and the database console sit inside Softgen. That is fast. It is also a trap if you never prove sign-in on the Vercel URL ads will hit. Site URL and redirect lists must include that host. Google or GitHub OAuth you own also needs the new callback in the provider console. An account you made in preview may not exist on the published app. Prove it there.
Prove four things on the hostname people will type, not only in Preview:
- Sign-up and sign-in work on the published URL. Softgen preview success is not that proof.
- Sessions expire and logout is real. A “stay signed in” cookie that never dies is a gift to a shared laptop.
- Admin is not a user role the agent mixed. One stolen user session should not open the back office.
- Login redirects match the advertised host. Reset mail, magic links, and OAuth callbacks must land on the name you buy ads for.
If login still dumps people onto a Softgen preview host or a raw `.vercel.app` after you bought a name, you have not wrapped auth. You have a pretty domain on a lab callback. Stay on Softgen while you fix that. Do not start the exit just to dodge a redirect list.
Open signup is a bot door
Ads send bots. Bots finish forms. A Softgen Full Stack app often ships email signup because you asked for “login.” That form is public the moment Publish is live. Confirm emails. Turn off auto-confirm if the agent left it on. Rate-limit signup, reset, and invite on the same day you seal secrets. Add a kill switch for any paid-API route the agent left open.
Stripe payments is the sibling door. Softgen tells you to test checkout in preview, then deploy. Preview cards are not live keys. If a Stripe secret sat in chat, rotate it. Webhooks must hit the published host, not the Softgen preview. Wallet and billing is pay-as-you-go. An open form plus a live model call is a bill you did not plan.
If the project is still Frontend mode, do not buy ads that need accounts. Frontend vs Full Stack says you can upgrade later. Upgrade, wrap auth, then spend. Do not point paid traffic at a static Softgen site and hope signup appears.
Rows and files: a hidden Softgen button is not a rule
Row-level security is the wrap ads will test. Platform-managed Supabase includes row-level security in the feature list. Softgen does not prove those policies for you. Supabase’s own Row Level Security guide is the peer fact. A table in an exposed schema without RLS is readable and writable by any role with a grant on it. The `service_role` key bypasses RLS, so keep it server-side. Frontend auth state is only for UI. The server must check the session.
Open the Softgen Database console. Read the tables. Change an ID on the published URL. Confirm you cannot open another account’s row. If the app still uses Firebase, the same test applies to security rules. File storage can add uploads. A public bucket is a file anyone with the URL can fetch. Prove the bucket policy on the Vercel host, not only in preview.
If you later move from platform-managed Supabase to an org you own, Softgen says that needs a migration and support. That is an exit door. This week you only need the wrap: strangers cannot read each other’s rows on the URL ads will hit.
Softgen preview and vercel.app leak into public links
A Softgen preview URL is instant. A one-click Publish URL is instant. That is also how the lab leaks. Custom domains say you connect a name after deploy. DNS can take up to 48 hours. The preview host still exists. A `.vercel.app` name still exists. Stay-harden is fine if ads, mail, sitemap, and login links print the name you mean to keep. It is not fine if the campaign still lists the Softgen preview or a leftover Vercel subdomain.
Name who owns the Vercel project. Deploy with Softgen can leave that project on Softgen’s side of the glass. Deploy with your Vercel account puts the project on a team you can name. This page does not flip you off Softgen. That is get off Softgen and migrate from Softgen. Here the test is smaller. Search the tree for Softgen preview hosts, `vercel.app`, and old callback URLs. Check OAuth allowlists, Stripe webhooks, CORS, and password-reset mail. If Auth still allows the preview host as a success URL, strangers will bookmark the lab.
Vercel environment variables add a last leak. Values are visible to anyone with project access. Preview and Production are different environments. A key you set only in Softgen’s Secrets panel may not exist on the Vercel Production deploy. A key you set on Vercel Preview may not exist in Production. Change one store and republish. Then prove login and checkout on the advertised host.
Restore: a CSV export is not a drill
Softgen’s exporting your data page is honest. You can export one table as CSV from the Database console. Import and export need Pro. Empty tables still export headers. You cannot export every table in one click. That is a spreadsheet. It is not a production restore.
Getting started tracks version history. You can revert code. You can compare versions. You can export to GitHub. Rolling back a Softgen version does not restore rows. Restoring rows does not roll back code. You need both if the agent ate the schema. Supabase onboarding is also plain about cancel: export your data or transfer the Supabase project to your own org before you cancel membership. Do that drill this week even if you plan to stay. A restore you have not run is not a backup.
Race gaps are app gaps. Two strangers will hit the same write. Seat, coupon, wallet, invite code. If the write is “read, then save” with no lock or unique rule, ads will double-book. Softgen will not save you from that. Prove the primary write once, with two tabs, on the published URL.
Wrap score — mark costume vs proof
Secrets
Costume
Key in chat or NEXT_PUBLIC_
Wrap
Secrets panel only
Proof
Viewer cannot dump keys
Login
Costume
Works in Softgen preview only
Wrap
Redirects listed
Proof
Vercel host, logout works
Signup
Costume
Open form, no confirm
Wrap
Confirm on, limits on
Proof
Bot path closed or gated
Rows / files
Costume
Hidden Softgen button
Wrap
RLS listed, bucket private
Proof
ID swap fails on public URL
Public name
Costume
Ads list preview host
Wrap
Custom name, old links live
Proof
Sitemap + callbacks match
Restore
Costume
CSV exists, never opened
Wrap
Pro export known, no drill
Proof
Restore or transfer run once
Mark the cell you are in. Move one cell, not six. Yellow is allowed for one more week. Red plus a campaign date is a stop. Green on all six is the only honest “buy the click.”
The pre-ads week
A wrap without a week is a slogan. Split the work. Inventory first. Buy traffic last. Do not leave Softgen on day one. Do not add agent polish while a door is red.
Harden on Softgen — seven operator steps
01 →
Inventory the public path
Who can Publish. Softgen vs your Vercel account. Which URL ads will hit. Where keys live. Who can open the editor.
02 →
Seal Secrets and sharing
Live keys only in the Secrets panel. Project private. Rotate chat and NEXT_PUBLIC_ leaks.
03 →
Rate-limit the open doors
Signup, reset, invite, and any paid-API route. Confirm emails. Kill switch.
04 →
Prove login on the published host
Real sessions on the advertised Vercel hostname. Admin split. Logout and reset re-checked.
05 →
Test rows and files
ID-swap on lists and files. No public bucket. Service role stays server-side.
06 →
Fix the URL map
Redirects, canonical tags, sitemap origin, login deep links. No Softgen preview host in ads.
07
Restore drill, then buy
One export or transfer you ran. Two-tab write test. Then spend.
Day 0 is inventory. Write five facts. The public URL. Whether Publish used Softgen’s Vercel or yours. The person who can publish tonight. The place secrets live. Whether a stranger can open the editor. If the public origin is already taking payments and you cannot name those five, stop. You do not need a new screen. You need this list.
Then seal, then login, then rows. Rate limits belong on the same day as Secrets. A bot does not wait for your custom domain. If payments exist, check webhook signatures the agent never stressed. Then fix the URL map. Then run the restore. Then buy. The Softgen MVP hardening lander is the short clipboard. This page is the week you run it.
Illustrative operator days before a Softgen ad buy
daysUnpriced Ads on a red list
3–5 wks
Campaign live. Doors still open. Cleanup later.
Illustrative operator days — not measured traffic, not a Source: Admin analytics series. Unpriced feature sprints on a public Softgen app often cost more than the wrap when the first leak hits.
Read the chart as a reservation, not a promise. Day 0 is cheap. If you cannot name the URL, the Vercel owner, and the drawer, later days thrash. The last bar is the silent kill: a “small” campaign while the list is still red. Ranges are studio-observed operator days — not a bid and not a vendor SLA.
Stay-harden vs leave. Do not mix the seats.
This page can end in stay. It can end in leave. It cannot end in both on the same week. Stay-harden means the process still lives in Softgen and its Vercel path, and the wrap is green. Leave means you open the exit and stop buying ads that need that Publish tab. Mixing those seats is how teams rewrite screens they already had.
Stay-harden vs exit — pick one seat
Stay-harden (this page)
Process still in Softgen
Preview plus Softgen or your Vercel. You accept the bill and the vendor.
Doors closed on that path
Secrets, login, signup, rows, URL map, restore.
Ads wait for green
A red layer pauses spend, not the product.
If the public origin must leave Softgen’s Vercel path, stop this wrap and open the exit. If ads are close and the origin can stay, finish the wrap first. ↓If the public origin must leave Softgen’s Vercel path, stop this wrap and open the exit. If ads are close and the origin can stay, finish the wrap first.
Leave (other pages)
Process leaves Softgen
Repo you own, backend you operate, host you pick. See get-off and migrate.
A collaborator seat is not the exit
Softgen invites you to their copy. Rows, secrets, and Publish stay until you move them.
Kill the Softgen Publish tab
Site still answers when the Softgen project is dark.
Need only the color? Open when to leave an AI builder. A layer that cannot close belongs on rewrite vs harden. A personal remote belongs on GitHub handoff. A Publish-only ship path belongs on CI/CD after an AI builder. Rows already in your own Supabase belong on Supabase hardening. The Lovable cousin is harden a Lovable MVP before paid traffic. The Replit cousin is harden a Replit MVP before paid traffic. None of those pages replace this wrap.
GitHub collaborator is not company ownership
Softgen’s GitHub integration invites you as a collaborator. You type a username. Softgen adds you to the repository. You accept an email. The FAQ says paid access includes that repo. Useful. Not a company workflow.
Import from GitHub makes the other direction clear. Softgen clones your repo, then creates a Softgen-managed copy for version control. Secrets do not come along. Rows do not come along. A collaborator seat on Softgen’s copy is not an org you control. Do not treat that invite as the GitHub handoff. This week you only ask: can a stranger open the Softgen project, and do you know where the live code actually lives?
Wrap loop — prove, then decide
01
Prove the door
One layer. One test on the published URL.
02
Close it
Rotate, replace, redirect, or restore.
03
Re-check ads list
If a layer is still red, spend stays off.
04 · loops
Stay or leave
Green wrap can stay. Red host row opens the exit.
When the list turns red
Pause the campaign — not the product — when any of these are still true:
- A live key still exists only in Softgen chat, a committed `NEXT_PUBLIC_` secret, or a shareable project.
- Login still works only in the Softgen preview, or a callback still lands on the preview host or a raw `.vercel.app`.
- Signup is open, confirm is off, and no human watches the form.
- A hidden Softgen button is the only “permission,” or a storage bucket is public.
- Ads, mail, or the sitemap still list a Softgen preview URL.
- You have never exported or transferred data — or you cannot name who would do it.
- Two people disagree about who owns the Vercel project or who can unpublish.
One of those is enough to call the week a miss. A live Publish badge is not a pass. Pause feature prompts that only ship from Softgen while a door is red. Finish the wrap. Then buy the click — or open the exit if the process itself is the red row.
Hire (or book a partner for a named gate) when the founder cannot be the second admin and cannot rotate secrets without the chat; when login still fails on the published host and traffic is close; or when the restore drill slipped past the campaign date. Hire for Secrets, login, rows, and the URL map — not for a new set of screens. Austin app development company is the studio brief. Austin mobile app development if the next door is a store binary that still points at this Softgen URL.
FAQ
Is a Softgen Publish click enough before ads?
No. Deploy with Vercel and one-click Publish put a snapshot on a live URL. The FAQ already says production hosting is not included with Softgen. That URL is uptime shape, not a wrap. Ads need sealed secrets, a real login on the published host, a closed bot door, row rules, a clean hostname, and a restore you have run. A live Publish badge is a lab with a better URL.
Does a Softgen GitHub collaborator seat finish the wrap?
No. GitHub integration invites you as a collaborator on Softgen’s repository. Import from GitHub then makes a Softgen-managed copy. Secrets and rows stay behind. A collaborator seat is not a company org. That proof lives on GitHub handoff. This page only asks: did the invite move rows or keys? It did not.
Does Softgen preview login count if the Vercel URL fails?
No. Firebase authentication tells you to test in preview, then deploy. Preview success is not published-host proof. Site URL, redirect lists, and OAuth callbacks must match the hostname ads will hit. An account you made in the Softgen preview may not exist on Vercel Production. Prove sign-in, logout, and admin split there.
Can I copy Softgen Secrets into NEXT_PUBLIC_ and buy ads?
No. Softgen’s Supabase onboarding puts public names in `NEXT_PUBLIC_` and the service role in `SUPABASE_SERVICE_ROLE_KEY`. Next.js inlines every `NEXT_PUBLIC_` value into the browser bundle. A service role key in that prefix, in chat, or in a committed file is a leak. Rotate it. If a viewer of the app can open the Softgen editor, sharing is still red. Do not buy ads on a red drawer.
Does a custom domain on a Softgen Vercel deploy finish the wrap?
No. Connect a custom domain still sits on Softgen’s Publish path or your Vercel account. DNS can take 48 hours. The Softgen preview host and the `.vercel.app` name still exist. Setting a primary domain is fine for stay-harden. It does not finish the wrap if ads, mail, sitemap, or login links still print the preview host. Leaving Softgen’s deploy path is the get-off job, not this page.
What Softgen data proof is enough before paid traffic?
You know whether the backend is platform-managed Supabase or Firebase. You have exported at least the money tables — CSV export is Pro and one table at a time — or you have a restore you have actually run. You know who would transfer the Supabase project if membership ended. The primary write survives two tabs. Storage files are not in a CSV. A version-history revert is code, not rows.
How is this different from hardening Lovable or Replit?
This page keeps the process in Softgen and closes doors before ads. Softgen does not host production. Vercel does. Secrets use a panel plus `NEXT_PUBLIC_`, not Lovable Cloud Secrets or a Replit Secrets pane. GitHub is a collaborator seat on a Softgen-managed copy, not Git sync and not a Repl. Harden a Lovable MVP before paid traffic is the wrap on Lovable hosting. Harden a Replit MVP before paid traffic is the wrap on Replit Deployments. Do not paste those playbooks here. Open them when that is the actual gap.
Is there a short CodeCross Softgen lander I should use instead?
Yes. Use Softgen MVP hardening for the wrap clipboard. Use get off Softgen when Publish-as-runtime is the risk. Use migrate from Softgen for extract. Use transition from Softgen for the overlap week. Use Softgen to production for the first useful ship beyond the wrap. This essay stays the pre-ads wrap.
Next steps
Walk the gates in order. Inventory the public URL, the Vercel owner, the Secrets panel, and who can publish. Seal Secrets and hide the editable Softgen project. Rate-limit signup and reset. Prove login on the advertised host. Test rows and files with an ID swap. Strip Softgen preview hosts and leftover `.vercel.app` names from ads, mail, sitemap, and callbacks. Run an export or transfer drill. Then buy the click — or open the exit if the process itself must leave Softgen. Pause any prompt that only ships from Softgen while a gate is red.
CodeCross LLC is an Austin-registered product studio (1606 Headway Cir STE 9212, Austin, TX). We help operators wrap a converting Softgen app before strangers show up: Secrets first, login second, signup third, row rules fourth, hostname fifth, restore last. The Austin app development company page is the studio brief. Austin mobile app development is the store-binary engagement if the next door is a signed build that still points at this Softgen URL. Company-level evidence lives on proof. When the list is still red and the campaign is close, book a conversation.
The goal is not to punish vibe coding. It is to stop treating a Softgen Publish click as proof that ads are safe. Hardening is a wrap you can show. Stay is allowed. Leave is a later door. Get the wrap right and most teams never need a second codebase.
Directional range in a few questions — not a binding quote.
Ready to price an Austin build?
Bring the problem, the users, and a budget ceiling. We’ll tell you whether an app is the right next spend — and what the first year actually costs.
Prefer writing? Send project details on the contact page.