The opening scene is a composite, not a customer report. A solo founder had a demo call at four. The status page ran only on one laptop.
A friend asked for a link before the call. That laptop could not serve the shared link. A zero bill still needed a public host.
Public posts this week praise generated pages and profile toys. Those pages still need a host boundary and an end time. A pretty demo without a receipt is still a laptop story.
A free coding model can draft a small page. A free server can hold a short demo. Neither tool should hold a customer record.
Disclosure: This article was prepared as part of MonkeyCode's product outreach. MonkeyCode is treated here as an open-source coding assistant. The operator supplied two availability claims for this draft.
Those claims are free model access and a free server option. This draft does not name any current model. This draft does not state a token grant.
Live quotas change, so the docs must win. A founder should read the current project terms first. A number copied from an old post can sink a launch.
The useful artifact is a local receipt drill. The drill freezes scope before any model edit. The drill also refuses customer data on the demo host.
Think of the free server as a borrowed folding table. It can show a poster for one afternoon. It cannot become the shop till or the ledger.
The founder writes the receipt before opening a chat. The receipt is a plain file in the repo root. The model may edit code, but not that file.
The proposed commands below were not executed for this draft. They show a throwaway drill, not a production deploy. Replace paths before use on a real machine.
mkdir -p "$HOME/demo-receipt/public"
cd "$HOME/demo-receipt"
git init
cat > RECEIPT.md << 'EOF'
scope: public status page only
host_role: demo
no_payments: true
no_customer_data: true
no_secrets: true
model_may_edit_receipt: false
retire_after: SET_A_REAL_TIME_BEFORE_SHARING
EOF
git add RECEIPT.md
The scope line is the whole product for today. A status page can say the demo is up. A status page must not charge a card.
Save the next block as health.py beside the receipt. It binds to localhost until a human chooses a host. It reports a start time and a demo flag.
# Proposed local drill. Not executed in this draft.
from http.server import BaseHTTPRequestHandler, HTTPServer
import json
import os
import time
STARTED = time.strftime("%Y-%m-%dT%H:%M:%SZ", time.gmtime())
class Handler(BaseHTTPRequestHandler):
def do_GET(self):
if self.path != "/health":
self.send_error(404)
return
payload = {
"ok": True,
"started": STARTED,
"demo_only": os.environ.get("DEMO_ONLY", "true"),
"holds_customer_data": False,
}
body = json.dumps(payload).encode("utf-8")
self.send_response(200)
self.send_header("Content-Type", "application/json")
self.send_header("Content-Length", str(len(body)))
self.end_headers()
self.wfile.write(body)
if __name__ == "__main__":
HTTPServer(("127.0.0.1", 8080), Handler).serve_forever()
Save the next block as guard.sh and mark it executable. It fails when risky filenames appear in the tree. Run it after git add, not before the first add.
# Proposed guard. Not executed in this draft.
set -euo pipefail
test -f RECEIPT.md
grep -q 'no_customer_data: true' RECEIPT.md
grep -q 'model_may_edit_receipt: false' RECEIPT.md
grep -q 'retire_after:' RECEIPT.md
if git ls-files | grep -E '(^|/)(\.env|secrets?|payments?|invoices?)'; then
echo "demo tree is not clean" >&2
exit 1
fi
python3 -m py_compile health.py
DEMO_ONLY=true python3 health.py &
pid=$!
trap 'kill "$pid"' EXIT
sleep 0.3
curl -fsS http://127.0.0.1:8080/health | grep '"holds_customer_data": false'
The local port check assumes port 8080 is free. If curl fails, the process never bound the port. Check the terminal for a traceback before blaming any host.
A free server cannot fix a script that dies locally. The founder opens a free model session after the guard exists. The pasted task is narrow and boring on purpose.
The model may add one public line, and nothing more. The task text lives beside the code as a contract. It names the files that are fair game.
Task: add public/index.html with one sentence and a health link.
Allowed files: public/index.html
Forbidden files: RECEIPT.md, health.py, guard.sh
Do not add forms, cookies, payments, or external trackers.
If a change needs a secret, stop and say blocked.
It says to stop if the receipt would change. After the diff lands, the founder runs the guard again. A green guard is not a security audit.
A green guard only means the promise still matches the tree. The founder reads every added line before the commit. A model summary is not a substitute for that read.
The health payload carries four fields for a reason. The ok field means the process answered the route. The other fields mark boot time, demo status, and data limits.
A holds_customer_data value of false is a promise, not a scan. The field does not inspect a database the page forgot. Only the file guard and the human review support that claim.
Secrets fail the drill even when the page looks empty. An env file can hide beside a pretty status card. The name check is crude, and that crudeness is useful.
Crude checks catch the obvious leak before the call. They do not catch a key buried in a comment. That is why the human still reads the diff.
The free server option comes last, not first. The founder publishes the public folder and the health route. The founder does not publish a database or a billing key.
Exact upload steps depend on the current server offer. This draft will not invent a hostname or a lifetime. The project docs are the only honest source for those fields.
A second receipt line belongs after a confirmed upload. That line records the host name a human actually used. That line also records when the demo should die.
# Proposed note after a human confirms the live docs.
printf 'demo_host: REPLACE_AFTER_READING_DOCS\n' >> RECEIPT.md
git add RECEIPT.md public/index.html health.py guard.sh
git commit -m "Record the demo receipt before sharing a link"
Sharing the link is the ship moment for this slice. The call can use that link for one hour. The call must not promote the host into next month.
Failure shows up in ordinary product habits first. The model adds a signup form because pages usually have one. The guard should catch the risky name and stop the share.
Another failure is success that lasts too long. The demo host stays up after the call ends. An old demo link becomes an unpaid production door.
The founder sets a calendar end when the receipt is written. When that time hits, the page comes down. A missing end time means the drill is unfinished.
Free model output remains untrusted text after a tidy diff. It can look clean and still break the health route. The curl check is the small proof that matters today.
Free server capacity stays unknown until the live page is read. A free box can sleep, throttle, or vanish. The public page should say that limit in plain words.
<!-- Proposed public/index.html. Not a claim about any live host. -->
<!DOCTYPE html>
<html lang="en">
<head><meta charset="utf-8"><title>Demo status</title></head>
<body>
<p>This page is a short demo, not a customer system.</p>
<p><a href="/health">Health</a></p>
</body>
</html>
The page sentence is part of the product boundary. Visitors should see the limit without opening a repo. A hidden limit turns a free host into a surprise outage.
Who should skip this path is not a mystery. A shop that takes cards should not park checkout here. A team under compliance review needs a controlled environment.
A founder who cannot read the current terms should skip it. Availability claims without a live page are not a plan. Hope is a poor capacity number for a public link.
This path fits a solo founder with one public slice. The slice has no accounts and no personal data. The slice can die tonight without harming a payer.
The folding table analogy returns at cleanup time. Fold the table when the poster comes down. Leave the till, the ledger, and the keys at home.
A later production host can reuse the health route idea. It should not reuse the free demo box by default. Promotion needs a fresh threat pass and a fresh bill plan.
The drill stays useful even if the free offer changes. The receipt file does not depend on a brand. The guard does not need a token counter to reject a secret.
If the live docs show no free server this week, stop. Local health output is still a win for the afternoon. A shared link can wait for a host the founder can describe.
If the live docs show a tight free model cap, shrink the task. One HTML file is enough for a call. A generated framework is how a free afternoon disappears.
No benchmark is claimed anywhere in this draft. No model is ranked against any other model. The only comparison is scoped work against unbounded chat.
The founder keeps the chat log next to the commit. The log shows what was asked, not what was wished. That record helps the next morning more than a glowing summary.
A good close stays dull on purpose today. The shared link works for the invited call. The receipt matches the tree, and the host has an end.
Before the next demo, open the current MonkeyCode docs. Confirm the free model path and the free server terms. Then run this drill on a throwaway repo.
Top comments (0)