Indie Founders, Building First SaaS Products
Early-stage founders are struggling with the practical realities of building their first SaaS products, often leveraging 'vibe coding' and AI tools. They grapple with foundational knowledge versus relying on shortcuts, balancing rapid development with quality, and navigating the initial launch and iteration process. The core pain is the overwhelming complexity and learning curve of bringing a SaaS idea to life.
SOURCES (60)
“My little brother finished college last year and for a year now he's been working non-stop, over 8+ hrs a day on some sort of web application. I think its supposed to be like an image hosting app but I'm not too sure because he…”
“I didn’t mean that as a dig at your approach (and yes I did read your post). It sounds like you’ve put real thought into this already, and I only meant it as an optional second set of eyes. There’s a reason even well-audited open source repos still have security issues pop up from time to time - when securing software, defenders have to be right every single time. No pressure either way, just wanted to offer help if useful.”
“I've been developing a platform for learning ASP.NET Core Web API in a more practical way for some time now. The idea is to combine guided lessons, code examples, and challenges. At the end of each challenge, you can submit your solution and receive feedback from an AI that evaluates it according to certain criteria, highlighting what you did well and the areas for improvement. for now, the lessons use YouTube videos as support. Later, I'd like to create my own content, but first I want”
“It sounds like you have things pretty well covered and seems like you understand your code better than you let on.”
“As a non programmer but a heavily LEGO user I vibe-coded a copy of Rebrickable. All images are offline. The website is blazing fast and has options Rebrickable doesn't have. Best of all, if I need a feature I can just ask. Instead waiting for ages.”
“Yeah that is not very pleasant even though I am kinda against vibe coding. But the reason for me is blind pasting kinda kills the entertainment part for me. So I don’t hate vibe coders. Everyone can build on their own idk why people concern it.”
Hello everybody, I created a tiny new plugin called Heads or Tails :coin: Is it the most powerful plugin in Bubble? No. Will it change the future of no-code forever? Also no.…
“I've seen multiple people obviously vibecode webhooks platforms in the past six or so weeks. The weird thing about it is that they're extremely similar. Five years ago I would've guessed this is a case of convergent evolution. Now it seems like it's some kind of recurrent point of vibecoding output.”
“Lol. You vibe coded another one of thousands of lcoal chat apps and want to charge money for it? Anyone can vibe code it for free in few hours, why would they pay you?”
Hey Justin, thank you! You've my permission to use the UI as a visual reference/benchmark for your testing framework. The whole mission of VibeCurb is to raise the standard of frontend design,…
“Checking the recent additions to the theme repository I see more and more themes entirely made by AI. I think vibe coded themes are themes that are developed quickly, dumped into the repository with extensive documentation that makes it look like a big project until you realize it's AI generated, and after that immediately abandoned by the "creator", because they wouldn't know how to support it, because they didn't develop it in the first place. Meanwhile the actual theme d”
“Absolutely - people are obsessed with vibe coding software products in a few days and launching them, and then doing no marketing. Obviously they won't be successful!”
“Fair question 😄 Not vibe coded, though. I’ve been building software professionally for many years, so this isn’t something I threw together over a weekend with AI. That said, I’m obviously biased because I’m building it. That’s exactly why I’m asking before assuming it’s a real problem worth solving and I’ve deliberately left the link out”
“Awesome concept!The biggest risk with a vibecoded setup is that car-fitment databases are notoriously brutal to map correctly, so your biggest challenge will be handling the Edge cases where submodels or mid-year engine changes don't line up perfectly. Making sure users can easily flag a wrong part recommendation right from the mobile checklist will be a lifesaver for catching those bugs early.”
“Thank you @edkang99 , that’s very useful information for me. That’s a right approach.”
“tbh if it works and you haven't launched, just launch it. You'll learn way more about what actually needs fixing from real users than from paying an engineer to audit code nobody's touched yet.”
“the claude tracker thing freaked me out too. my audit is pretty simple tbh: I check every route that takes a user ID or touches the database, I test IDOR manually (exactly the user A sees user B thing you described), and I grep for any outbound fetch calls I didnt explicitly ask for. thats it. I use ShipDocs to get an overview of the codebase when theres too much to read manually but the actual security testing is still hands on”
“We're building codeindexer.dev , it's a powerful code intelligence layer, we work on it over 7 months already, 2 developers, almost 14 hours each day. We're dogfooders of course - we use our own software a lot, it works. Our clients are people who code a lot, who has max subscriptions and want to make their AI even more smarter to break borders and build something very complicated. It's local-first software and strong PC is required (at least M versions of Mac or not too outdated”
“Oh so you are a dev? I am as well but then may I ask why hire another developer then? If you find issues then any LLM will be able to fix these, so that will reduce the amount of findings for an audit which is always good. Another step would be to establish your threat model ie. "what are you defending against?".”
“I posted about this earlier, but my example really undersold what vibeArchitecture can do. Here's my second attempt. The OWASP Top 10 has barely changed in a decade. Broken access control has been at or near the top the whole time. These are not beginner mistakes; they are default mistakes: the things code does when nobody explicitly prevents them. AI-generated code ships them constantly, not because models are bad at security but because "make it work" is the objective, and almost”
Hey guys, What would be the right route to find a reliable developer who can audit my project? I'm working on a SaaS platform where people will be paying and upload private…
“I totally get you, but I also think this problem is going away. Creating a good slash command before deploying will solve most of this. Although it burns tokens it's cheaper than breaking something or hiring someone. For better or worse, vibe coding will get easier. We're only on year 1 of it”
“It's real. I build Canlah.AI with Claude Code — hit ~2M RMB revenue over 7 months. Claude Code speeds up the first 80% but you'll fight context limits and agent loops on the last 20% of polish. Worth it if you ship fast and don't let the tool become the project.”
“Love this idea! QA is so important because while it is fast to ship an app, you need to make it secure and stable for your users. Excited to see where this goes for you!”
“I am non technical cofounder with product management background. I have shipped complex features like x402 payments support. It is not an easy process. I went all the way from vibe coding small projects to eventually doing my own Claude Code plugin to help me ship code properly.”
“I think the issue isn't vibe coding itself - it's treating products as disposable. Vibe coding can get you to an MVP incredibly fast. Keeping users, though, still requires product thinking, maintenance, and actually listening to feedback. A buggy app isn't necessarily bad because it was vibe coded. It's bad because nobody took ownership of improving it after launch.”
“If we remove the Hype what would you choose. We have this list which is supposedly the current top in user opinion. Cursor GitHub Copilot Claude Code Windsurf OpenAI Codex / ChatGPT Aider Amazon Q Developer Tabnine JetBrains AI Assistant Cline I don't use any of these and I haven't used them. If you had to choose a service, tools, product, etc. to code in now and without taking into account the hype, which would you choose and why. Would you choose something from the list? Would you deci”
“I'm launching an AI API for vibecoders, with models like Opus and GPT-5.6 , and I'm looking for beta testers to help shape it before launch. I'd love to hear what you think. I'm looking for people who will actually use the API and give honest, detailed feedback about their experience what works well, what doesn't, and what could be improved. If you're interested in trying it out for free and I'll get you set up. 10/Slots Open https://preview.redd.it/0lha2lk0jidh1.png?”
“yeah the architecture and design decisions are the hard part, the typing is just typing”
“Bro I have seen this exact color theme and the same square grid background so many times the layout is good maybe change up the colors and add some animations”
“Founder here. While developing MCPBackend, we noticed a major difference between generating a convincing application demo and building a maintainable SaaS product. AI coding tools are increasingly capable of generating interfaces, routes and even initial application logic. But a production application still needs: a reliable data model authentication and authorization backend validation permissions secure secrets integrations migrations operational visibility infrastructure that remains maintain”
The Story: Hello everyone, This is my first post on this sub. I am a 2nd year university student in India. So one or two days ago I had an idea for…
“Hi everyone. I am new to coding although I have been running and managing a tech company for the past 3 years, my team has been a great support to me thru my vibe coding journey and I’ve made some serious mistakes along the way. It was my team that pushed me to vibe code prototypes and demos of what I needed built. A great way to learn, I think. I work at a legal secretary at a real estate company in London and I was using a free online software by the name of propertyhawk.co.uk which will soon”
“The "abstraction" for agentic coding is "vibe-coding," meaning people without any kind of software development background can now get software developed and deployed. Right now, maintainability may go down over time as the project grows and new features get added, but this allows non-developers to write utilities for to automate tedious parts of their job, and it allows non-developers to work on passion projects. I've talked to multiple non-developers who've gotten MV”
“I’ve been coding for six years, and I often use AI as a learning tool. But how on earth do people build complete games just by 'vibe coding'? In my experience, tracking down the root cause of a bug is already a nightmare. On top of that, the AI tools I use don't actually understand code; the second you try something slightly unconventional, they get completely stuck. So how do these vibe-coded games even make it to the finish line? Are their creators secretly elite coders in disguis”
“Usually this means they give you a problem and expect actual working code that reflects the design - like build a rate limiter or an LRU cache, then extend it to handle scale/concurrency. So less about drawing boxes and more about implementing the components with real tradeoffs. We get a lot of these formats on prepfully and the coaches can run mocks for exactly this hybrid style if you want to see what the questions look like.”
“I don’t know what kind of software you are writing but in business applications, I’ve found most of the time is not writing code in the first place. The main issue is semantics not syntax. Specifically I looked at a great many projects and said, well if we knew exactly what to do, how long would it realistically take to write and debug and harden and test this much code. The answer was consistently around 30% of the total project time spent by the engineers. Meaning what are the details of the p”
“At this point, my entire company is totally dependent on vibe coding... when sr leadership was asked why our perf reviews only take into consideration code quantity and not customer success... we were tokd that as software engineers our output is code, not amything else. Of course we need to max out AI useage to. Getting the message, the comoany does not care about product/ code quality... the people who have been token maxxing have been getting ranked high. Unfortunately they have fired several”
“I was responding to a 100% vibe coder who doesn't know how to manually write or change code at all. They need an agentic workflow because they're responsible for making a small inhouse app without any experience or developers at the company to help. You likely have opinion about that situation; however, you're far outside the target audience and the situation doesn't involve you. I'm confused as to why you're acting like I suggested you do anything or why you replied at a”
“I want to develop certain game mechanics and make practice projects If I just do it myself, I’ll always be limited to the scope of my own knowledge. Sometimes that can become a closed loop that has an overall negative trajectory in terms of actually improving So is there a person / organization I can pay to look at my code, check it for best software engineering practices, recommend me algorithms I can use for certain features, etc etc Basically like how a professor in university can check your”
“I vibe-coded a tiny SaaS for about a month with basically zero software background. It works well enough that real users are poking at it, which is exactly when the fun left the room. a dev friend asked one question that ruined my evening. Can user A change an ID in a request and see user B's records. I had no answer. Claude generated a lot of the app and I nodded along becuase the UI looked right. Tenant isolation is not a UI feeling. It is route checks, database policy, ownership, and all”
Hey guys, What would be the right route to find a reliable developer who can audit my project? I'm working on a SaaS platform where people will be paying and upload private…
“They don't need to be dynamic. A QR code just opens up a url, and you can track whenever that url is opened.”
“I always procrastinate on marketing and talking to customers, not just because they are scary (they really are), but I was worried my app had something wrong from all the vibe coding I did. Genuinely noticed I would spend hours trying to just test different flows out with different edge cases and entrypoints. I tried Claude Code to do it but it was way too slow and it went through it like a, well, bot. Not really tracking its memories, what flows it followed, and how it went through it. It's”
“If you are a software engineer you should be able to afford at the very least the $20 subscription and play with CC on your own time in hobby projects. Yeah it sucks that you have to invest your time outside work for your career, but it’s nothing new, we have always needed to grind LeetCode or learn newer tech stacks on our own time.”
“The framing is stronger in the direction you're taking: make the proof artifact the product, not the remote device access. One useful test is whether a mobile lead can tell in ten seconds what gets run, what evidence lands in the PR, and what decision they can make from it. If any of that still feels abstract, show one real pass/fail report above the fold. That keeps the story about release confidence.”
“The line for me is whether you can delete a random row from the database and the app degrades gracefully instead of just dying. Most vibe-coded demos I've seen fall over the second real data gets messy or edge cases show up, which is exactly when the actual engineering bill (auth hardening, error handling, testing) comes due. Not saying every demo ends up this fragile, but it's the pattern I keep running.”
So I have a ChatGPT Go account. Over the past couple of weeks I've been working on an app using chatGPT. It would make code for me and tell me where to…
“Sometimes you accidently make the RLS open because RLS is not apt for complex use cases like having object permission because I am the admin of shared team.”
“I used to just ask ai to build things, but when i reviewed the code, I found things myself, I've been the CTO so It was easy for me to find the basic issues.”
Did you find these manually or did you use a tool/AI to audit it?
“Hey r/microsaas , I've been building SaaS apps with AI tools for a while now, and last month I went back through one of my older projects specifically looking for security issues. Found way more than I expected. Sharing them here because I see the same mistakes in almost every "I built this in a weekend" post. API keys in client-side code. If your AI assistant put a key directly in a React component or a .env file that's not gitignored, it's exposed the moment you deploy. A”
“My SaaS is 90% vibecoded, so this isn't me dunking on AI tools, I live in them. But here's the pattern I kept missing: the AI builds the feature and never builds the guard around the feature. It ships you a working app with the confidence of a senior engineer, and never once mentions that the data's wide open. I found this out the hard way on my own product. A data-scoping leak, change one ID in a request and you'd be looking at someone else's records. Classic IDOR plus a dat”
“90% of the demo stuff on this sub gives off the hallmark "AI built it for me" so why is all of it incredibly shallow? submitted by /u/Small_Summer5817 [link] [comments]”
“My general rule is that everything should be designed in the simplest manner need to to achieve the functionality and security required and not one bit more. I'd lean for option 2 unless there's a clear need to do 1.”
