Vibe Coding Guide: From AI Prototype to Production App

Vibe coding is building software by describing what you want to an AI and iterating on the result. Great for prototypes; production still needs engineering.
Most of my work in 2026 starts the same way: a founder has built something with Lovable, Bolt, Cursor or Claude Code. It looks great and mostly works, and now real users are coming. My job is turning that into software that is secure, deployed properly and maintainable. I also vibe code myself every day. This guide is what I've learned from both sides: what vibe coding is, which tools fit which job, where AI-generated apps break, and the exact steps from prototype to production.
Key takeaways
- Vibe coding means prompting instead of typing code. The term was coined by Andrej Karpathy in February 2025 and was Collins Dictionary's Word of the Year 2025.
- There are two kinds of tools: app builders (Lovable, Bolt, Replit, v0) for non-developers, and AI coding agents (Cursor, Claude Code, Codex) for people who read code.
- It's excellent for prototypes, internal tools, UI and well-known CRUD patterns.
- It breaks at security (auth, database rules, secrets), architecture, deployment and long-term maintenance.
- Going to production means: own the code in GitHub, review security, add tests and CI, deploy to a real server, and set up backups and monitoring.
What is vibe coding?
Andrej Karpathy, a co-founder of OpenAI and former head of AI at Tesla, described vibe coding in a February 2025 post as giving in to the vibes and forgetting the code even exists: you describe what you want, accept what the AI writes, paste error messages back, and keep going. By November 2025 the phrase was Collins Dictionary's Word of the Year.
In practice the term now covers a range. At one end, someone with no coding background builds a whole app by chatting with Lovable. At the other, a senior engineer uses Claude Code to write most of a feature, then reviews every diff. Both are "vibe coding", but only the second one includes someone who understands what was built. That difference decides whether the app survives contact with real users.
Which vibe coding tools should you use?
App builders: for founders and non-developers
Lovable, Bolt, Replit and v0 generate a full app from a description, usually React with a hosted backend such as Supabase, and give you a live preview. They're the fastest way from idea to something clickable. The trade-off: you get less control over the architecture, and hosting, auth and database setup follow the tool's defaults. I compared them to custom builds in AI website builder vs custom website.
AI coding agents: for developers
Cursor, Claude Code, OpenAI Codex, Windsurf, AWS's Kiro and Google's Antigravity work inside a real codebase. They read your files, run commands and tests, and make multi-file changes you review. This is where serious products get built with AI. My hands-on comparison is in Claude Code vs Cursor vs Codex.
A common and sensible path: prototype in an app builder, sync the code to GitHub, then continue in an AI coding agent with an engineer reviewing the changes.
What vibe coding is good at
- Prototypes and MVPs you can put in front of users to test an idea in days.
- Internal tools and dashboards where the users are your own team.
- UI work: layouts, components, responsive styling and copy changes.
- Well-known patterns: CRUD screens, forms, auth flows from a library, API clients.
- Boring code: tests, migrations, type definitions, scripts and documentation.
Where vibe-coded apps break
These are the problems I find most often when someone sends me a vibe-coded app before launch:
Security
The biggest risk by far. Database tables without row-level security, so any logged-in user can read everyone's data. API keys and service-role secrets in front-end code. Admin checks done only in the browser. No rate limiting on login or AI endpoints that cost money. My vibe coding security checklist lists the 12 checks I run.
Hallucinated or risky dependencies
AI tools sometimes suggest npm packages that don't exist, and attackers register those names with malware. I wrote about this in slopsquatting.
Architecture that doesn't grow
Each prompt solves the problem in front of it, so after a few hundred prompts you get duplicated logic, three ways of fetching data, and files nobody wants to touch. The AI starts breaking things it fixed last week.
Deployment and operations
"It works in the preview" isn't hosting. Custom domains, HTTPS, environment variables, database backups, logs, uptime alerts and a way to roll back a bad release usually don't exist yet.
From vibe coding to production: the steps
This is the order I follow when taking over a vibe-coded app:
- Own the code. Connect the project to a GitHub repository you control. Lovable and Bolt both support GitHub sync. From now on
mainis the source of truth. - Read it. An engineer reads the whole codebase once: data model, auth, API routes, environment variables, dependencies. This is where the big risks show up.
- Fix security first: server-side auth checks, row-level security on every table, secrets moved to server environment variables, rate limits, input validation. Rotate any key that was ever in the front end.
- Add guardrails for the AI. An
AGENTS.mdorCLAUDE.mdfile with the project's rules, commands and "never do this" list makes every future AI change better. See AGENTS.md and CLAUDE.md. - Add tests and CI for the flows that make money or touch data: sign-up, login, payment, the main feature. CI runs them on every push, so the next prompt can't quietly break checkout.
- Deploy properly. A VPS with Nginx, HTTPS and PM2, or a managed platform, deployed from GitHub with automatic rollback. My step-by-step for Lovable apps is Lovable app to production on your own server.
- Operate it: nightly database backups that leave the server, uptime and error alerts, and a log you can search.
Best practices for vibe coding well
- Write the plan first. A one-page spec with users, data and screens gives the AI a target and keeps the architecture consistent.
- Small prompts, small diffs. One feature or fix at a time, committed when it works, so you can go back.
- Read every diff that touches auth, payments or data. Let the AI write it; don't let it decide what's secure.
- Pin the stack. Tell the tool which framework, database and libraries to use, so it doesn't add a second of each.
- Treat the AI as a fast junior developer: great output, needs review, never the final word on architecture or security.
Is vibe coding replacing developers?
Not in my experience. It's changing what developers spend time on. Less typing of routine code, more reviewing, designing systems, securing them and running them in production. The people with the most to gain are those who combine AI speed with the engineering judgment to know when the AI is wrong. The apps with the most risk are the ones where nobody on the team can read the code.
Frequently asked questions
What does vibe coding mean?
Vibe coding means building software by describing what you want in plain language to an AI tool, running the result, and iterating with more prompts, rather than writing the code by hand. Andrej Karpathy coined the term in February 2025.
What is the best vibe coding tool?
For non-developers building a first version, Lovable, Bolt or Replit. For developers working in a real codebase, Claude Code, Cursor or Codex. Many teams prototype in the first group and continue in the second once the code lives in GitHub.
Can a vibe-coded app go to production?
Yes, after an engineering pass. The code needs a security review, tests for critical flows, proper hosting with HTTPS and rollback, and backups and monitoring. Skipping those is how vibe-coded apps leak data.
Is vibe coding safe?
The process is fine; shipping unreviewed output isn't. The common issues are missing database access rules, exposed API keys, client-side-only permission checks and hallucinated dependencies. A pre-launch security review catches most of them.
How much does it cost to make a vibe-coded app production-ready?
It depends on the app's size and how many issues the review finds. A small app often needs a few days of security fixes, deployment and CI setup. Ask for a review first so the estimate is based on the actual code.
Built something with AI and need it production-ready?
I review vibe-coded apps, fix the security and architecture issues, and deploy them with CI, backups and monitoring, so you keep the speed and lose the risk. See my web development services or send me your project for a review.
Written by
MD Rakibul Islam Rakib
Full-stack developer, DevOps engineer and Linux system administrator with 5+ years of production experience. I deploy, harden and fix servers and web apps for clients worldwide, and everything in this article runs on real servers I manage, including this site.
- vibe coding
- AI coding tools
- vibe coding to production
- Lovable
- Cursor
- Claude Code
- AI app builder


