<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: DevToolsPicks</title>
    <description>The latest articles on DEV Community by DevToolsPicks (@devtoolpicks).</description>
    <link>https://dev.to/devtoolpicks</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3841747%2F4a66f12a-54b3-486f-adfc-2887bacde2fa.png</url>
      <title>DEV Community: DevToolsPicks</title>
      <link>https://dev.to/devtoolpicks</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/devtoolpicks"/>
    <language>en</language>
    <item>
      <title>Best ngrok Alternatives for Indie Hackers in 2026</title>
      <dc:creator>DevToolsPicks</dc:creator>
      <pubDate>Fri, 25 Sep 2026 06:00:09 +0000</pubDate>
      <link>https://dev.to/devtoolpicks/best-ngrok-alternatives-for-indie-hackers-in-2026-a0b</link>
      <guid>https://dev.to/devtoolpicks/best-ngrok-alternatives-for-indie-hackers-in-2026-a0b</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Originally published at &lt;a href="https://devtoolpicks.com/blog/best-ngrok-alternatives-indie-hackers-2026" rel="noopener noreferrer"&gt;devtoolpicks.com&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;




&lt;p&gt;&lt;a href="https://ngrok.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;ngrok&lt;/a&gt; is still the name everyone types. It's also $20 a month before you're allowed to use your own domain, the free tier puts an interstitial page in front of every visitor, and it caps you at 3 endpoints, 1 GB and 20,000 requests. For a webhook test that's fine. For a client demo with a warning page on it, or a home server you want reachable all month, it isn't.&lt;/p&gt;

&lt;p&gt;Cloudflare's Quick Tunnels &lt;a href="https://news.ycombinator.com/item?id=49754785" rel="noopener noreferrer"&gt;hit the Hacker News front page again this week&lt;/a&gt;, and the thread doubled as a live comparison of everything below. Prices and limits here were checked on September 19, 2026.&lt;/p&gt;

&lt;h2&gt;
  
  
  Quick Verdict
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Tool&lt;/th&gt;
&lt;th&gt;Best for&lt;/th&gt;
&lt;th&gt;Price&lt;/th&gt;
&lt;th&gt;Rating&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://developers.cloudflare.com/cloudflare-one/connections/connect-networks/?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Cloudflare Tunnel&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Anything on your own domain, permanent&lt;/td&gt;
&lt;td&gt;Free on Zero Trust Free&lt;/td&gt;
&lt;td&gt;4.5/5&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://tailscale.com/kb/1223/funnel?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Tailscale Funnel&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;One service on a home box&lt;/td&gt;
&lt;td&gt;Free on Personal, up to 6 users&lt;/td&gt;
&lt;td&gt;4/5&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://pinggy.io?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Pinggy&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Cheapest persistent URL, TCP and UDP&lt;/td&gt;
&lt;td&gt;Free, Pro $2.50/month billed annually&lt;/td&gt;
&lt;td&gt;4/5&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://localxpose.io?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;LocalXpose&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;UDP and many tunnels, flat price&lt;/td&gt;
&lt;td&gt;Free, Pro $8/month&lt;/td&gt;
&lt;td&gt;3.5/5&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://zrok.io?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;zrok&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Open source, self-host with no limits&lt;/td&gt;
&lt;td&gt;Free hosted tier, Apache 2.0&lt;/td&gt;
&lt;td&gt;4/5&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  What Are You Actually Tunnelling?
&lt;/h2&gt;

&lt;p&gt;Three jobs hide behind "I need an ngrok alternative". A one-off webhook test wants zero setup and doesn't care if the URL dies in an hour. A client demo wants a clean URL with no warning page. A home server wants a permanent address on a domain you own, with no timeout. Pick the job first.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://devtoolpicks.com/blog/best-ngrok-alternatives-indie-hackers-2026" rel="noopener noreferrer"&gt;View the interactive component on devtoolpicks.com&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Cloudflare Tunnel
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://developers.cloudflare.com/cloudflare-one/connections/connect-networks/?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Cloudflare Tunnel&lt;/a&gt; comes in two flavours. Quick Tunnels run with one &lt;code&gt;cloudflared&lt;/code&gt; command, need no account, and hand you a random &lt;code&gt;trycloudflare.com&lt;/code&gt; URL. A named tunnel needs your domain on Cloudflare DNS and a Zero Trust account, which is $0 forever for teams under 50 users, and then it's a permanent hostname with Cloudflare's edge in front of it and no timeout.&lt;/p&gt;

&lt;p&gt;Quick Tunnels have limits Cloudflare states plainly. Testing and development only, 200 in-flight requests before you get a 429, and no Server-Sent Events. The ngrok founder said in the HN thread that ngrok dropped anonymous tunnels because they were its biggest abuse source. Cloudflare's anonymous URLs carry the same risk.&lt;/p&gt;

&lt;p&gt;Who shouldn't use it: anyone whose domain isn't on Cloudflare and doesn't want it there. And anyone who needs raw TCP or UDP without installing a client on the other end.&lt;/p&gt;

&lt;p&gt;Pick this if you own a domain and want the permanent, free answer.&lt;/p&gt;

&lt;h2&gt;
  
  
  Tailscale Funnel
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://tailscale.com/kb/1223/funnel?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Tailscale Funnel&lt;/a&gt; takes a service on a machine in your tailnet and puts it on the public internet at &lt;code&gt;your-tailnet.ts.net&lt;/code&gt;, with HTTPS certificates created for you. It's on every plan, including the free Personal plan for up to 6 users, and the next tier is $8 per user a month.&lt;/p&gt;

&lt;p&gt;The constraints are specific. Funnel only listens on ports 443, 8443 and 10000, the hostname has to be on your &lt;code&gt;ts.net&lt;/code&gt; domain, and Tailscale applies a bandwidth cap it doesn't publish. So it's a way to expose one or two things, not a hosting layer.&lt;/p&gt;

&lt;p&gt;Who shouldn't use it: anyone who needs a custom domain or expects real traffic. The &lt;a href="https://devtoolpicks.com/blog/best-tailscale-alternatives-indie-hackers-2026" rel="noopener noreferrer"&gt;Tailscale alternatives post&lt;/a&gt; covers what to run instead if the mesh itself isn't a fit.&lt;/p&gt;

&lt;p&gt;Pick this if you already use Tailscale and want to share one service from a home box without touching DNS.&lt;/p&gt;

&lt;h2&gt;
  
  
  Pinggy
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://pinggy.io?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Pinggy&lt;/a&gt; is the zero-install option. It runs over SSH, so &lt;code&gt;ssh -p 443 -R0:localhost:3000 free.pinggy.io&lt;/code&gt; gets you a public URL with no binary to download. The free tier has HTTP, TCP, UDP and TLS tunnels, request inspection and unlimited data transfer, with a 60 minute timeout and a random subdomain. Pro is $2.50 a month billed annually for one persistent tunnel, one custom domain and one persistent TCP or UDP port.&lt;/p&gt;

&lt;p&gt;Who shouldn't use it: anyone who needs several persistent tunnels. Pro is priced per seat with one persistent tunnel each, and unlimited tunnels sit on the enterprise plan.&lt;/p&gt;

&lt;p&gt;Pick this if you test webhooks often and want the cheapest URL that never changes.&lt;/p&gt;

&lt;h2&gt;
  
  
  LocalXpose
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://localxpose.io?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;LocalXpose&lt;/a&gt; is the one to look at when Pinggy's single-tunnel Pro plan runs out. The free Starter tier gives you 2 HTTP tunnels with time limits and an interstitial page. Pro is $8 a month, or $96 a year, for 10 tunnels covering HTTP, TCP, TLS and UDP, custom domains, wildcard tunnels with automatic certificates, and unlimited bandwidth.&lt;/p&gt;

&lt;p&gt;Who shouldn't use it: anyone who only needs one tunnel, because Pinggy does that for less, and anyone with a domain already on Cloudflare, where the named tunnel is free.&lt;/p&gt;

&lt;p&gt;Pick this if you run several services and want them all on your domains for one flat price.&lt;/p&gt;

&lt;h2&gt;
  
  
  zrok
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://zrok.io?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;zrok&lt;/a&gt; is the open source pick, built on OpenZiti and licensed Apache 2.0. The hosted free tier is $0 with 5 GB a day of bandwidth, 25 environments and 50 share backends, with an interstitial on unverified accounts that disappears once you add a payment method. Self-hosting has no limits at all. It also does private shares, where only another zrok user can reach the service.&lt;/p&gt;

&lt;p&gt;Who shouldn't use it: anyone who wants a polished dashboard and a one-line install. There's more to learn than with Pinggy, and the paid hosted tiers are a sales conversation rather than a price on a page.&lt;/p&gt;

&lt;p&gt;Pick this if you'd rather own the tunnel server than rent one.&lt;/p&gt;

&lt;h2&gt;
  
  
  How Should You Choose?
&lt;/h2&gt;

&lt;p&gt;For a one-off webhook or a quick "look at this" link, run a Cloudflare Quick Tunnel or Pinggy and don't create an account for anything. For daily webhook testing, Pinggy Pro. For a permanent public address on your own domain, put the domain on Cloudflare and use a named tunnel. If you already run &lt;a href="https://devtoolpicks.com/blog/laravel-forge-vs-ploi-vs-coolify" rel="noopener noreferrer"&gt;Coolify or another self-hosted panel&lt;/a&gt;, that tunnel is how you skip opening ports. For one service on a home machine you already have on Tailscale, Funnel. For a stack you want to own end to end, zrok on your own server, or bore and frp if you want something smaller.&lt;/p&gt;

&lt;h2&gt;
  
  
  Final Recommendation
&lt;/h2&gt;

&lt;p&gt;Cloudflare Tunnel for anyone with a domain, because free with no timeout on your own hostname is the thing ngrok charges $20 a month for. Pinggy when you want that without moving DNS, for $2.50 a month.&lt;/p&gt;

&lt;p&gt;Found a better option? Let me know on Twitter &lt;a class="mentioned-user" href="https://dev.to/devtoolpicks"&gt;@devtoolpicks&lt;/a&gt;.&lt;/p&gt;

</description>
      <category>developertools</category>
      <category>devops</category>
      <category>indiehacker</category>
      <category>opensource</category>
    </item>
    <item>
      <title>When to Use Per-Token Inference vs Renting a GPU by the Hour</title>
      <dc:creator>DevToolsPicks</dc:creator>
      <pubDate>Wed, 23 Sep 2026 06:00:10 +0000</pubDate>
      <link>https://dev.to/devtoolpicks/when-to-use-per-token-inference-vs-renting-a-gpu-by-the-hour-5b4l</link>
      <guid>https://dev.to/devtoolpicks/when-to-use-per-token-inference-vs-renting-a-gpu-by-the-hour-5b4l</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Originally published at &lt;a href="https://devtoolpicks.com/blog/when-to-use-per-token-inference-vs-renting-a-gpu-by-the-hour-indie-hackers-2026" rel="noopener noreferrer"&gt;devtoolpicks.com&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;




&lt;p&gt;A dedicated H100 sounds like the grown-up choice. Your own card, your own model, no shared queue. And at $1.99 an hour on &lt;a href="https://www.runpod.io?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;RunPod&lt;/a&gt;, it doesn't even sound expensive.&lt;/p&gt;

&lt;p&gt;It is, for almost everyone reading this. The card bills 24 hours a day and your users don't send requests 24 hours a day. The per-token API only charges when a token comes out. That asymmetry decides the question, and the &lt;a href="https://devtoolpicks.com/blog/best-hugging-face-inference-alternatives-indie-hackers-2026" rel="noopener noreferrer"&gt;Hugging Face alternatives post&lt;/a&gt; gave it one paragraph. It deserves the math.&lt;/p&gt;

&lt;h2&gt;
  
  
  How Much Does Each Option Cost?
&lt;/h2&gt;

&lt;p&gt;Every number below was checked against the vendor's pricing page on September 19, 2026.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Vendor&lt;/th&gt;
&lt;th&gt;Billing model&lt;/th&gt;
&lt;th&gt;Price&lt;/th&gt;
&lt;th&gt;Idle cost&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://deepinfra.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;DeepInfra&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Per-token, Llama 3.3 70B&lt;/td&gt;
&lt;td&gt;$0.10 in / $0.32 out per million&lt;/td&gt;
&lt;td&gt;$0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://deepinfra.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;DeepInfra&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Per-token, Llama 3.1 8B&lt;/td&gt;
&lt;td&gt;$0.02 in / $0.04 out per million&lt;/td&gt;
&lt;td&gt;$0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://www.together.ai?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Together AI&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Per-token, Llama 3.3 70B&lt;/td&gt;
&lt;td&gt;$1.04 in / $1.04 out per million&lt;/td&gt;
&lt;td&gt;$0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://modal.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Modal&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Per-second H100&lt;/td&gt;
&lt;td&gt;$0.001097/s, $3.95/hr active&lt;/td&gt;
&lt;td&gt;$0 when scaled to zero&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://deepinfra.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;DeepInfra&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Hourly H100, dedicated&lt;/td&gt;
&lt;td&gt;$2.20/hr&lt;/td&gt;
&lt;td&gt;$52.80/day&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://www.runpod.io?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;RunPod&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Hourly H100 PCIe, raw pod&lt;/td&gt;
&lt;td&gt;$1.99 community, $2.89 secure&lt;/td&gt;
&lt;td&gt;$47.76/day&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://www.together.ai?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Together AI&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Hourly HGX H100, dedicated&lt;/td&gt;
&lt;td&gt;$3.99/hr promo to Sep 30, was $5.49&lt;/td&gt;
&lt;td&gt;$95.76/day&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Two things jump out. The same 70B model costs ten times more per output token on Together than on DeepInfra, so "per-token" is not one price. And the cheapest dedicated H100 still costs about $53 a day whether you serve one request or a million.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where Is the Break-Even?
&lt;/h2&gt;

&lt;p&gt;Take DeepInfra, since it sells both models and the comparison is clean. A dedicated H100 at $2.20 an hour is $52.80 a day. Llama 3.3 70B output tokens cost $0.32 per million. Divide one by the other and the card pays for itself at 165 million output tokens a day.&lt;/p&gt;

&lt;p&gt;That's 1,900 tokens a second. Every second. For 24 hours.&lt;/p&gt;

&lt;p&gt;Whether one H100 can even produce that depends on your model, quantization and batching, and every vendor's throughput chart flatters its own hardware. Measure your own model with vLLM before you believe any of them. But the arithmetic alone gives the shape of the answer. A side project doing 50,000 requests a day at 500 output tokens each is 25 million tokens, about $8 on per-token. The card would cost $53 for the same day.&lt;/p&gt;

&lt;p&gt;Run the same math on an 8B model at $0.04 per million and the break-even is 1.3 billion tokens a day. Small models never win on hourly. The serverless price is too low to beat.&lt;/p&gt;

&lt;h2&gt;
  
  
  When Does Hourly Win Anyway?
&lt;/h2&gt;

&lt;p&gt;Cost is one axis. Four situations put you on a rented card before the break-even, and they have nothing to do with tokens.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Your model isn't on anyone's catalog.&lt;/strong&gt; A LoRA fine-tune of a 70B, a custom vision head, an architecture that came out last week. Serverless vendors host what sells. If your model isn't on the list, there's no per-token price to compare against.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Your customers ask where the data lives.&lt;/strong&gt; A shared multi-tenant API is a hard sell to a European healthcare buyer. A dedicated card in a named region, under a contract you can show them, is a different conversation.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;You need latency you control.&lt;/strong&gt; Per-token APIs put you behind a shared queue. Most of the time that's fine. If your product is a voice agent or a live coding assistant, p99 matters more than the bill.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;You want a fixed number on the invoice.&lt;/strong&gt; Some founders would rather pay $1,584 a month, flat, than explain a usage spike to an accountant. That's a legitimate reason, as long as you know you're paying for predictability, not compute.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://devtoolpicks.com/blog/when-to-use-per-token-inference-vs-renting-a-gpu-by-the-hour-indie-hackers-2026" rel="noopener noreferrer"&gt;View the interactive component on devtoolpicks.com&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  What About the Middle Ground?
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://modal.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Modal&lt;/a&gt; sits between the two. You bring your own code and weights, like a rented GPU. But it bills per second at $0.001097 for an H100, scales to zero between requests, and boots a container in about a second. The &lt;a href="https://devtoolpicks.com/blog/modal-vs-replicate-vs-baseten-indie-hackers-2026" rel="noopener noreferrer"&gt;Modal vs Replicate vs Baseten comparison&lt;/a&gt; worked through a real example: 1,600 seconds of actual GPU work a day came to roughly $53 a month, and the same work with a 20 minute scaledown window came to about $1,000. One config value, twenty times the bill.&lt;/p&gt;

&lt;p&gt;So Modal covers the custom-model case without the 24 hour meter. It doesn't cover data residency or fixed billing, and at $3.95 an hour of active time against DeepInfra's $2.20 dedicated, it loses once you're steady. Right answer for bursty custom models, wrong one for anything running flat out.&lt;/p&gt;

&lt;h2&gt;
  
  
  Which Should You Pick?
&lt;/h2&gt;

&lt;p&gt;Per-token by default. If your model is on the DeepInfra or Together catalog and your traffic is spiky, you'll spend a fraction of the hourly rate and never think about capacity. Route through a gateway if you want the option to switch vendors later, which the &lt;a href="https://devtoolpicks.com/blog/best-openrouter-alternatives-indie-hackers-2026" rel="noopener noreferrer"&gt;OpenRouter alternatives post&lt;/a&gt; covers.&lt;/p&gt;

&lt;p&gt;Modal when the model is yours and the traffic is bursty. Hourly, on DeepInfra or RunPod, when the traffic is steady enough that the card is busy most of the day, or when residency, latency or a contract forces your hand. Do the division with your own token counts before you commit, because the vendors won't do it for you.&lt;/p&gt;

&lt;p&gt;Found a better option? Let me know on Twitter &lt;a class="mentioned-user" href="https://dev.to/devtoolpicks"&gt;@devtoolpicks&lt;/a&gt;.&lt;/p&gt;

</description>
      <category>aitools</category>
      <category>developertools</category>
      <category>indiehacker</category>
      <category>opensource</category>
    </item>
    <item>
      <title>Best Tailwind Plus Alternatives for Indie Hackers in 2026</title>
      <dc:creator>DevToolsPicks</dc:creator>
      <pubDate>Mon, 21 Sep 2026 06:00:08 +0000</pubDate>
      <link>https://dev.to/devtoolpicks/best-tailwind-plus-alternatives-for-indie-hackers-in-2026-c40</link>
      <guid>https://dev.to/devtoolpicks/best-tailwind-plus-alternatives-for-indie-hackers-in-2026-c40</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Originally published at &lt;a href="https://devtoolpicks.com/blog/best-tailwind-plus-alternatives-indie-hackers-2026" rel="noopener noreferrer"&gt;devtoolpicks.com&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;




&lt;p&gt;Tailwind Labs joined Shopify on September 9, 2026. The same day, &lt;a href="https://tailwindcss.com/plus?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Tailwind Plus&lt;/a&gt; and ui.sh stopped taking new customers. The pricing page is gone and the URL redirects to a login screen. If you already own a license, nothing changes. If you were about to spend $299 on it, you now need somewhere else to spend it.&lt;/p&gt;

&lt;p&gt;The framework is fine. Adam Wathan's announcement says Tailwind CSS stays MIT licensed with the same team behind it. So this isn't a post about leaving Tailwind. It's about replacing the three things Plus sold: 500+ copy-paste UI blocks, a set of React and Next.js templates, and the Catalyst UI kit.&lt;/p&gt;

&lt;h2&gt;
  
  
  Quick Verdict
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Tool&lt;/th&gt;
&lt;th&gt;Best for&lt;/th&gt;
&lt;th&gt;Price&lt;/th&gt;
&lt;th&gt;Rating&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://ui.shadcn.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;shadcn/ui&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;React projects, owned component code&lt;/td&gt;
&lt;td&gt;Free, MIT&lt;/td&gt;
&lt;td&gt;4.5/5&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://daisyui.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;daisyUI&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Any framework, semantic class names&lt;/td&gt;
&lt;td&gt;Free, MIT&lt;/td&gt;
&lt;td&gt;4.5/5&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://flowbite.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Flowbite&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The closest match to Plus, HTML plus Figma&lt;/td&gt;
&lt;td&gt;Free core, Developer 289 euros one-time&lt;/td&gt;
&lt;td&gt;4/5&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://preline.co?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Preline UI&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Most blocks for the least money&lt;/td&gt;
&lt;td&gt;Free core, Pro 216 euros one-time&lt;/td&gt;
&lt;td&gt;4/5&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://www.untitledui.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Untitled UI React&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Design-led teams already on the Figma kit&lt;/td&gt;
&lt;td&gt;Free core, Pro Solo $349 one-time&lt;/td&gt;
&lt;td&gt;3.5/5&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Every price above was checked against the vendor's pricing page on September 19, 2026. Flowbite and Preline quote in euros before tax.&lt;/p&gt;

&lt;h2&gt;
  
  
  Which Part of Tailwind Plus Were You Buying?
&lt;/h2&gt;

&lt;p&gt;Plus bundled three products, and the replacement depends on which one you wanted. If it was the HTML blocks for a Laravel, Rails or Astro project, Flowbite, Preline and daisyUI all ship plain markup. If it was Catalyst, you need React components you can edit, which is what shadcn/ui is. If it was the Next.js templates, Preline's 21 templates are the nearest thing here.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://devtoolpicks.com/blog/best-tailwind-plus-alternatives-indie-hackers-2026" rel="noopener noreferrer"&gt;View the interactive component on devtoolpicks.com&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  shadcn/ui
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://ui.shadcn.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;shadcn/ui&lt;/a&gt; isn't a component library in the npm sense. You run &lt;code&gt;npx shadcn add button&lt;/code&gt; and the source lands in your repo. You own it from that point. The docs say it plainly: "This is not a component library. It is how you build your component library."&lt;/p&gt;

&lt;p&gt;That's the Catalyst replacement. Free, MIT licensed, with blocks for dashboards, sidebars, login and signup, and a v0 button on every block if you'd rather edit it in a chat.&lt;/p&gt;

&lt;p&gt;Who shouldn't use it: anyone not on React. There are community ports, shadcn-vue and shadcn-svelte, but shadcn doesn't maintain them. And you're now responsible for updating component code yourself, because there's no package to bump.&lt;/p&gt;

&lt;p&gt;Pick this if you're on Next.js or any React framework and you'd rather own the code than license it.&lt;/p&gt;

&lt;h2&gt;
  
  
  daisyUI
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://daisyui.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;daisyUI&lt;/a&gt; is a Tailwind plugin that adds 68 semantic components (&lt;code&gt;btn&lt;/code&gt;, &lt;code&gt;card&lt;/code&gt;, &lt;code&gt;modal&lt;/code&gt;) and 34 themes. It's on version 5, free, MIT licensed, and it's pure CSS, so it runs in Blade, ERB, Svelte, or a static HTML file with equal indifference.&lt;/p&gt;

&lt;p&gt;It solves a different problem from Plus. Plus gave you finished blocks with long utility strings. daisyUI gives you short class names and a theme switcher, so your markup stays readable years later.&lt;/p&gt;

&lt;p&gt;Who shouldn't use it: teams that want pixel-exact marketing sections ready to paste. daisyUI gives you the components, not the page layouts. The paid store sells templates, charts and a Figma library separately.&lt;/p&gt;

&lt;p&gt;Pick this if you're outside React and you want the Tailwind ergonomics without the utility soup.&lt;/p&gt;

&lt;h2&gt;
  
  
  Flowbite
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://flowbite.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Flowbite&lt;/a&gt; is the closest thing to Plus in shape. The community edition is MIT licensed with 56 component types and framework guides for React, Vue, Svelte, Angular, Laravel, Rails, Django and more. The Developer edition costs 289 euros one-time, with lifetime access, and adds marketing, application and publisher blocks. A team license is 949 euros. A Designer edition at 159 euros covers the Figma design system only.&lt;/p&gt;

&lt;p&gt;Who shouldn't use it: React-first teams. Flowbite ships HTML first and the React wrapper is a separate project. If your whole stack is React, shadcn/ui gives you more for nothing.&lt;/p&gt;

&lt;p&gt;Pick this if your stack is server-rendered and you want blocks plus Figma from one vendor.&lt;/p&gt;

&lt;h2&gt;
  
  
  Preline UI
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://preline.co?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Preline UI&lt;/a&gt; undercuts everyone on the paid tier. The free version already includes 640+ components, 189 blocks, 5 templates and a Figma design system. Pro is 216 euros one-time for a single developer and opens all 780+ blocks, 21 templates with 207 pages, and lifetime updates. Team is 399 euros for up to 15 developers.&lt;/p&gt;

&lt;p&gt;That 21-template library is the only serious answer on this list to the Next.js templates Plus sold.&lt;/p&gt;

&lt;p&gt;Who shouldn't use it: anyone who needs React components rather than markup. Preline is HTML and a small JS plugin layer. It works fine inside React, but you're pasting markup, not importing components.&lt;/p&gt;

&lt;p&gt;Pick this if templates were the reason you wanted Plus and you'd rather pay once.&lt;/p&gt;

&lt;h2&gt;
  
  
  Untitled UI React
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://www.untitledui.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Untitled UI React&lt;/a&gt; comes from the team behind the Untitled UI Figma kit. The React free tier is open source and installs by CLI. Pro Solo is $349 one-time for 5,000+ components and 250+ page examples with Figma sync. Studio for up to 8 users is $999.&lt;/p&gt;

&lt;p&gt;Who shouldn't use it: anyone who isn't already designing in the Untitled UI Figma kit. The value is the Figma-to-React sync. Without that workflow you're paying more than Flowbite for a React library that shadcn/ui covers for free.&lt;/p&gt;

&lt;p&gt;Pick this if your designer already works in Untitled UI and you want the code to match the file.&lt;/p&gt;

&lt;h2&gt;
  
  
  How Should You Choose?
&lt;/h2&gt;

&lt;p&gt;Start from your framework, not from the feature list.&lt;/p&gt;

&lt;p&gt;On React or Next.js, take shadcn/ui and stop there unless a designer hands you Untitled UI files. On a server-rendered stack like Laravel, Rails or Django, take daisyUI for components, and Flowbite or Preline when you want finished page blocks. If templates were the point, Preline Pro at 216 euros. If you want one vendor for code and Figma at Plus-like pricing, Flowbite Developer at 289 euros.&lt;/p&gt;

&lt;p&gt;And if you're picking a builder rather than a kit, the &lt;a href="https://devtoolpicks.com/blog/lovable-vs-bolt-vs-replit-vs-v0-2026" rel="noopener noreferrer"&gt;Lovable vs Bolt vs Replit vs v0 comparison&lt;/a&gt; covers that route, while the &lt;a href="https://devtoolpicks.com/blog/best-framer-alternatives-indie-hackers-2026" rel="noopener noreferrer"&gt;Framer alternatives&lt;/a&gt; and &lt;a href="https://devtoolpicks.com/blog/best-figma-alternatives-indie-hackers-2026" rel="noopener noreferrer"&gt;Figma alternatives&lt;/a&gt; posts cover the design side.&lt;/p&gt;

&lt;h2&gt;
  
  
  Final Recommendation
&lt;/h2&gt;

&lt;p&gt;For most indie hackers reading this, shadcn/ui is the answer. It's free, it's the closest thing to Catalyst, and owning the code means no vendor can close its doors on you again.&lt;/p&gt;

&lt;p&gt;If you're not on React, daisyUI first, Preline Pro if you need finished pages. Flowbite Developer is the pick when you want the Plus experience, Figma included, from a company still selling licenses.&lt;/p&gt;

&lt;p&gt;Found a better option? Let me know on Twitter &lt;a class="mentioned-user" href="https://dev.to/devtoolpicks"&gt;@devtoolpicks&lt;/a&gt;.&lt;/p&gt;

</description>
      <category>developertools</category>
      <category>frontend</category>
      <category>indiehacker</category>
      <category>opensource</category>
    </item>
    <item>
      <title>Modal vs Replicate vs Baseten for Indie Hackers in 2026</title>
      <dc:creator>DevToolsPicks</dc:creator>
      <pubDate>Fri, 18 Sep 2026 06:00:07 +0000</pubDate>
      <link>https://dev.to/devtoolpicks/modal-vs-replicate-vs-baseten-for-indie-hackers-in-2026-3knc</link>
      <guid>https://dev.to/devtoolpicks/modal-vs-replicate-vs-baseten-for-indie-hackers-in-2026-3knc</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Originally published at &lt;a href="https://devtoolpicks.com/blog/modal-vs-replicate-vs-baseten-indie-hackers-2026" rel="noopener noreferrer"&gt;devtoolpicks.com&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;




&lt;p&gt;Every comparison of these three opens with a table of hourly GPU rates. Modal's H100 is cheapest, Replicate's costs more, Baseten's costs most. Pick the cheap one, done.&lt;/p&gt;

&lt;p&gt;Then you run an actual workload through all three and the ranking flips. Not by a little. By more than an order of magnitude, in the opposite direction from what the hourly rates predict.&lt;/p&gt;

&lt;p&gt;The reason is that almost nobody scraping by on a side project keeps a GPU busy. You have bursts of traffic and long gaps, and what you pay for during the gaps is the entire ballgame. So this post prices one concrete workload, 200 image generations a day at roughly 8 seconds of GPU time each, and shows what each platform actually bills.&lt;/p&gt;

&lt;p&gt;Every price below came from the vendor's own pricing page or docs on September 12, 2026.&lt;/p&gt;

&lt;h2&gt;
  
  
  Quick Verdict
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Platform&lt;/th&gt;
&lt;th&gt;Best for&lt;/th&gt;
&lt;th&gt;Billing unit&lt;/th&gt;
&lt;th&gt;Entry cost&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;a href="https://replicate.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Replicate&lt;/a&gt; catalog models&lt;/td&gt;
&lt;td&gt;Bursty work on a standard model&lt;/td&gt;
&lt;td&gt;Per output&lt;/td&gt;
&lt;td&gt;$3 per thousand images and up&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://modal.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Modal&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Custom code, tight idle control&lt;/td&gt;
&lt;td&gt;Per second, no minimum&lt;/td&gt;
&lt;td&gt;$0 plus compute, $30/mo free credit&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://www.baseten.co?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Baseten&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Steady, predictable traffic&lt;/td&gt;
&lt;td&gt;Per replica minute, rounds up&lt;/td&gt;
&lt;td&gt;$0 pay as you go&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;a href="https://replicate.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Replicate&lt;/a&gt; private deployments&lt;/td&gt;
&lt;td&gt;Custom models, constant load&lt;/td&gt;
&lt;td&gt;Per second, includes idle&lt;/td&gt;
&lt;td&gt;Per hardware rate&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  What Do These Three Actually Charge Per Hour?
&lt;/h2&gt;

&lt;p&gt;The headline rates, verified today. Modal publishes per second and Baseten per minute, so the hourly columns below are arithmetic on their published figures rather than numbers they print themselves.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;GPU&lt;/th&gt;
&lt;th&gt;&lt;a href="https://modal.com/pricing" rel="noopener noreferrer"&gt;Modal&lt;/a&gt;&lt;/th&gt;
&lt;th&gt;&lt;a href="https://replicate.com/pricing" rel="noopener noreferrer"&gt;Replicate&lt;/a&gt;&lt;/th&gt;
&lt;th&gt;&lt;a href="https://www.baseten.co/pricing/" rel="noopener noreferrer"&gt;Baseten&lt;/a&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;H100 80GB&lt;/td&gt;
&lt;td&gt;$3.95/hr equivalent&lt;/td&gt;
&lt;td&gt;$5.49/hr&lt;/td&gt;
&lt;td&gt;$6.50/hr equivalent&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;A100 80GB&lt;/td&gt;
&lt;td&gt;$2.50/hr equivalent&lt;/td&gt;
&lt;td&gt;$5.04/hr&lt;/td&gt;
&lt;td&gt;$4.00/hr equivalent&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;L40S&lt;/td&gt;
&lt;td&gt;$1.95/hr equivalent&lt;/td&gt;
&lt;td&gt;$3.51/hr&lt;/td&gt;
&lt;td&gt;not listed&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;A10G&lt;/td&gt;
&lt;td&gt;$1.10/hr equivalent (A10)&lt;/td&gt;
&lt;td&gt;not listed&lt;/td&gt;
&lt;td&gt;$1.21/hr equivalent&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;T4&lt;/td&gt;
&lt;td&gt;$0.59/hr equivalent&lt;/td&gt;
&lt;td&gt;$0.81/hr&lt;/td&gt;
&lt;td&gt;$0.63/hr equivalent&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Modal's H100 SXM5 is $0.001097 per second. Replicate prints "$5.49/hr" next to $0.001525 per second. Baseten quotes an H100 80GB at $0.10833 per minute and never prints a headline hourly rate, so the $6.50 is a conversion you do yourself.&lt;/p&gt;

&lt;p&gt;On Modal, CPU and memory bill separately from the GPU, at $0.0000131 per core-second and $0.00000222 per GiB-second. The others fold that into the hardware rate.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why Does the Billing Unit Matter More Than the Rate?
&lt;/h2&gt;

&lt;p&gt;Because the unit decides what happens in the gaps, and for an indie project the gaps are most of the day.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href="https://modal.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Modal&lt;/a&gt; bills per second with no minimum.&lt;/strong&gt; Their &lt;a href="https://modal.com/docs/guide/billing" rel="noopener noreferrer"&gt;billing docs&lt;/a&gt; say it plainly: "Reservations are not required, and there are no minimum usage-time increments." The pricing page goes further, claiming "You never pay for idle resources."&lt;/p&gt;

&lt;p&gt;That claim doesn't survive their own cold start documentation, which says "you will be billed for any resources used while the container is idle (e.g., GPU reservation or residual memory occupancy)." Both statements are Modal's. The docs are the accurate one. What you control is &lt;code&gt;scaledown_window&lt;/code&gt;, the idle timeout before a container dies, configurable from 2 seconds to 20 minutes.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href="https://www.baseten.co?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Baseten&lt;/a&gt; bills per replica minute and rounds partial minutes up.&lt;/strong&gt; From their &lt;a href="https://docs.baseten.co/organization/billing" rel="noopener noreferrer"&gt;billing docs&lt;/a&gt;: "Baseten meters usage by the minute while a workload is running on a node." Worth being precise here, because secondary sources get it wrong. The meter runs per &lt;em&gt;running replica&lt;/em&gt;, not per request. A replica serving 100 requests over 15 minutes bills about 15 minutes, not 100 rounded-up minutes.&lt;/p&gt;

&lt;p&gt;The number that actually costs you money is &lt;code&gt;scale_down_delay&lt;/code&gt;, and its default is 900 seconds. Fifteen minutes where the replica is still running after your last request. The docs say you "pay for usage up to the moment the replica terminates, and partial minutes round up", and that metering runs "while a workload is running on a node", so that window bills. Cold starts and model loading bill too: "During startup, billing is per minute even though the replica isn't yet serving responses."&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href="https://replicate.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Replicate&lt;/a&gt; has two completely different cost shapes on one platform.&lt;/strong&gt; For public catalog models, "you only pay for the time it's active processing your requests. Setup and idle time for the model is free." For private models and deployments, you "pay for all the time instances of the model are online," setup and idle included. Same company, opposite economics. Get this backwards and your bill moves by 10x.&lt;/p&gt;

&lt;p&gt;Catalog models are also priced per output, not per second:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Model&lt;/th&gt;
&lt;th&gt;Price per output&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Flux Schnell&lt;/td&gt;
&lt;td&gt;$3.00 per thousand images&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Flux Dev&lt;/td&gt;
&lt;td&gt;$0.025 per image&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Flux 1.1 Pro&lt;/td&gt;
&lt;td&gt;$0.04 per image&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Recraft V3&lt;/td&gt;
&lt;td&gt;$0.04 per image&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Ideogram v3 quality&lt;/td&gt;
&lt;td&gt;$0.09 per image&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;An 8-second generation and a 3-second generation cost the same. Duration stops being a variable.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Does 200 Images a Day Actually Cost?
&lt;/h2&gt;

&lt;p&gt;200 generations at 8 seconds is 1,600 seconds of GPU time a day, about 13.3 hours a month. Here's what each platform bills for that same work, assuming traffic arrives in roughly 24 bursts through the day.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Setup&lt;/th&gt;
&lt;th&gt;Billed/month&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Replicate Flux Schnell (catalog)&lt;/td&gt;
&lt;td&gt;~$18&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Replicate Flux Dev (catalog)&lt;/td&gt;
&lt;td&gt;~$150&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Modal H100, 60s scaledown window&lt;/td&gt;
&lt;td&gt;~$100&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Modal H100, pure active time only&lt;/td&gt;
&lt;td&gt;~$53&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Modal H100, 20min scaledown window&lt;/td&gt;
&lt;td&gt;~$1,000&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Baseten H100, default 15min delay&lt;/td&gt;
&lt;td&gt;~$1,326&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Look at the Modal rows. Same GPU, same 1,600 seconds of real work, and the bill moves from $53 to $1,000 on one config value. The hourly rate never changes. Your &lt;code&gt;scaledown_window&lt;/code&gt; does.&lt;/p&gt;

&lt;p&gt;Baseten's H100 has the highest headline rate of the three, but that's not why it lands at the top of this table. It's the 900-second default idle delay multiplied by every burst, with each burst's partial minute rounded up. Lower &lt;code&gt;scale_down_delay&lt;/code&gt; and that number drops hard. Leave the default on bursty traffic and you pay for roughly six hours of idle H100 a day.&lt;/p&gt;

&lt;p&gt;And Replicate, whose H100 costs 39% more per hour than Modal's, comes out cheapest by a mile on a catalog model, because the question of how long a GPU sat warm never arises.&lt;/p&gt;

&lt;p&gt;So the ranking by hourly rate is Modal, Replicate, Baseten. The ranking by what you'd actually pay is Replicate, Modal, Baseten, and the gap between first and last is more than 70x.&lt;/p&gt;

&lt;h2&gt;
  
  
  When Is Each One the Right Call?
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Pick &lt;a href="https://replicate.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Replicate&lt;/a&gt; catalog models&lt;/strong&gt; when a standard model does the job. Flux, SDXL, Whisper, the usual suspects. Bursty traffic is free of idle cost, failed runs aren't charged ("If a run fails, we don't charge you", except on private deployments), and you can ship in an afternoon. This is where most indie projects should start.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Pick &lt;a href="https://modal.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Modal&lt;/a&gt;&lt;/strong&gt; when you need your own code around the model, custom preprocessing, a pipeline, or a model nobody hosts. Per-second billing with no minimum is the most honest unit of the three, and the $30 monthly free credit covers a lot of experimentation. Set &lt;code&gt;scaledown_window&lt;/code&gt; deliberately, because the default will quietly decide your bill.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Pick &lt;a href="https://www.baseten.co?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Baseten&lt;/a&gt;&lt;/strong&gt; when traffic is steady enough to keep a replica properly busy. Per-minute metering stops being a penalty once your replica isn't idling, their cold start engineering is real, and dev deployments aren't billed at all, which makes iteration cheap. For a solo project with spiky traffic and default settings, it's the most expensive way to run this workload.&lt;/p&gt;

&lt;h3&gt;
  
  
  When should you not use any of them?
&lt;/h3&gt;

&lt;p&gt;If you're under a few hundred requests a day on a standard model, a hosted API is simpler and cheaper than all three. We worked through that break-even in &lt;a href="https://devtoolpicks.com/blog/when-to-use-litellm-self-hosted-vs-managed-ai-gateway-indie-hackers-2026" rel="noopener noreferrer"&gt;when to use LiteLLM self-hosted vs a managed AI gateway&lt;/a&gt;, and the same logic applies to image work.&lt;/p&gt;

&lt;p&gt;If you're running models locally already, &lt;a href="https://devtoolpicks.com/blog/best-local-ai-coding-tools-indie-hackers-2026" rel="noopener noreferrer"&gt;the local AI coding tools roundup&lt;/a&gt; covers where a machine you already own beats renting one.&lt;/p&gt;

&lt;h2&gt;
  
  
  A Note on Benchmarks You'll Find Searching This
&lt;/h2&gt;

&lt;p&gt;There's a site ranking high for serverless GPU cold starts that reports Modal at 1.8 seconds, RunPod 4.2, Replicate 6.5, with a stated methodology of 500 cold invocations per provider. Tempting to cite. I'm not going to, because its Modal A100 40GB price (~$2.85/hr) and Replicate A100 80GB price (~$4.14/hr) both contradict the vendors' own pages, which say $2.10 and $5.04. A benchmark that gets published list prices 18% wrong isn't a benchmark I'd trust on latency.&lt;/p&gt;

&lt;p&gt;The vendors' own cold start claims, for what they're worth: Modal's docs say "Containers boot in about one second." Baseten's blog claims "cold start times of 9 seconds, from zero to ready for inference" for Stable Diffusion XL on an A100. Replicate publishes no number, saying only that setup "can take a few seconds." Two vendor claims and one absence, which is the honest state of the public record.&lt;/p&gt;

&lt;h2&gt;
  
  
  My Recommendation
&lt;/h2&gt;

&lt;p&gt;Start on &lt;a href="https://replicate.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Replicate&lt;/a&gt; catalog models. At 200 images a day the per-output model is cheapest, the idle question disappears, and you'll know within a week whether the feature matters to anyone.&lt;/p&gt;

&lt;p&gt;Move to &lt;a href="https://modal.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Modal&lt;/a&gt; when you outgrow the catalog, either because you need custom code or because your volume is high enough that per-second billing beats per-image. Set the scaledown window yourself on day one.&lt;/p&gt;

&lt;p&gt;Consider &lt;a href="https://www.baseten.co?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Baseten&lt;/a&gt; when your traffic flattens out into something steady. Its economics reward a busy replica and punish an idle one, which is the opposite of what a side project's traffic looks like early on.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://devtoolpicks.com/blog/modal-vs-replicate-vs-baseten-indie-hackers-2026" rel="noopener noreferrer"&gt;View the interactive diagram on devtoolpicks.com&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;We covered the hosted end of this market in &lt;a href="https://devtoolpicks.com/blog/best-hugging-face-inference-alternatives-indie-hackers-2026" rel="noopener noreferrer"&gt;the Hugging Face inference alternatives post&lt;/a&gt;, and the routing layer above it in &lt;a href="https://devtoolpicks.com/blog/best-openrouter-alternatives-indie-hackers-2026" rel="noopener noreferrer"&gt;the OpenRouter alternatives roundup&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The number to check before you commit to any of these isn't the hourly rate on the pricing page. It's the idle timeout in your deployment config, because that's the one you're actually going to pay.&lt;/p&gt;

&lt;p&gt;Found a better option? Let me know on Twitter &lt;a class="mentioned-user" href="https://dev.to/devtoolpicks"&gt;@devtoolpicks&lt;/a&gt;.&lt;/p&gt;

</description>
      <category>aitools</category>
      <category>indiehacker</category>
      <category>developertools</category>
      <category>aiinfrastructure</category>
    </item>
    <item>
      <title>Best AI Coding Agent Security Tools for Indie Hackers in 2026</title>
      <dc:creator>DevToolsPicks</dc:creator>
      <pubDate>Wed, 16 Sep 2026 06:00:09 +0000</pubDate>
      <link>https://dev.to/devtoolpicks/best-ai-coding-agent-security-tools-for-indie-hackers-in-2026-29j9</link>
      <guid>https://dev.to/devtoolpicks/best-ai-coding-agent-security-tools-for-indie-hackers-in-2026-29j9</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Originally published at &lt;a href="https://devtoolpicks.com/blog/best-ai-coding-agent-security-tools-indie-hackers-2026" rel="noopener noreferrer"&gt;devtoolpicks.com&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;




&lt;p&gt;On Friday April 24, 2026, a Cursor agent running Claude Opus 4.6 was given a routine staging task. It hit a credential mismatch, and instead of stopping to ask, it went looking for a way forward. It found a Railway API token in the codebase, created months earlier for the narrow job of adding and removing custom domains, which turned out to carry blanket permissions across every environment. Then it deleted the production database volume in one API call.&lt;/p&gt;

&lt;p&gt;Nine seconds. And because Railway stored volume backups inside the volume they protect, the backups went too. The most recent off-site copy was three months old.&lt;/p&gt;

&lt;p&gt;We covered &lt;a href="https://devtoolpicks.com/blog/cursor-ai-agent-deleted-production-database-pocketos-2026" rel="noopener noreferrer"&gt;that incident in detail when it happened&lt;/a&gt;. What I want to work through here is the practical question it leaves behind. What actually stops that?&lt;/p&gt;

&lt;p&gt;The market has answers now, and they don't compete with each other the way a comparison table would suggest. They sit at three different points in time: before you install something, before a command runs, and after the agent is done. So this post is organized by layer, not by vendor. The best options for a solo developer are free, and the paid tier of this category is built for people with a CISO.&lt;/p&gt;

&lt;h2&gt;
  
  
  Quick Verdict
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Tool&lt;/th&gt;
&lt;th&gt;Layer&lt;/th&gt;
&lt;th&gt;Price&lt;/th&gt;
&lt;th&gt;Best for&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://code.claude.com/docs/en/permissions" rel="noopener noreferrer"&gt;Claude Code permissions and sandbox&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Runtime&lt;/td&gt;
&lt;td&gt;Free, built in&lt;/td&gt;
&lt;td&gt;Everyone, start here&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://github.com/NVIDIA/SkillSpector" rel="noopener noreferrer"&gt;NVIDIA SkillSpector&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Pre install&lt;/td&gt;
&lt;td&gt;Free, Apache 2.0&lt;/td&gt;
&lt;td&gt;Scanning skills and MCP servers before use&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://github.com/dwarvesf/claude-guardrails" rel="noopener noreferrer"&gt;dwarvesf/claude-guardrails&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Runtime&lt;/td&gt;
&lt;td&gt;Free, MIT&lt;/td&gt;
&lt;td&gt;A ready made hardened config&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://github.com/snyk/agent-scan" rel="noopener noreferrer"&gt;Snyk Agent Scan&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Pre install&lt;/td&gt;
&lt;td&gt;Free tier, account needed&lt;/td&gt;
&lt;td&gt;Auditing what you already installed&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://harden.run?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Harden AIF&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Runtime&lt;/td&gt;
&lt;td&gt;Free CLI&lt;/td&gt;
&lt;td&gt;Local model scoring with secret redaction&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://watcher.apolloresearch.ai?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Apollo Research Watcher&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Runtime and review&lt;/td&gt;
&lt;td&gt;Contact sales&lt;/td&gt;
&lt;td&gt;Teams needing central policy and audit&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  What Are the Three Layers?
&lt;/h2&gt;

&lt;p&gt;Time is what separates these tools.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Pre install&lt;/strong&gt; is before an agent skill, plugin or MCP server ever runs. You're reading someone else's code and deciding whether to trust it. Static scanners live here.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Runtime&lt;/strong&gt; is the moment between the agent deciding to run something and the thing actually running. This is where a &lt;code&gt;rm -rf&lt;/code&gt; gets stopped, or doesn't.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Post hoc&lt;/strong&gt; is afterwards, reviewing what the agent actually did across a whole session. Useful for teams and audits, mostly overkill for one person.&lt;/p&gt;

&lt;p&gt;The PocketOS failure was a runtime failure. No scanner would have caught it, because the malicious code was not the problem. The agent did exactly what it was told, with credentials it should never have been able to reach.&lt;/p&gt;

&lt;h2&gt;
  
  
  Layer 1: What Should You Scan Before Installing a Skill?
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href="https://github.com/NVIDIA/SkillSpector" rel="noopener noreferrer"&gt;NVIDIA SkillSpector&lt;/a&gt;&lt;/strong&gt; is the clear pick, and it's free. Apache 2.0, 17,000 stars, and the repo was pushed to the day I wrote this.&lt;/p&gt;

&lt;p&gt;It runs a two stage scan on a skill before you install it. The first stage is static: 71 vulnerability patterns across 17 categories, regex matching, Python AST analysis that flags &lt;code&gt;exec&lt;/code&gt;, &lt;code&gt;eval&lt;/code&gt;, &lt;code&gt;subprocess&lt;/code&gt; and imports resolved at runtime, YARA signature matching, taint tracking, and live CVE lookups against OSV.dev. The second stage uses an LLM to judge intent and filter false positives, and it runs by default, so pass &lt;code&gt;--no-llm&lt;/code&gt; if you want static only.&lt;/p&gt;

&lt;p&gt;It never executes what it scans, which is the guarantee that matters here. The docs are explicit that all analysis is static plus optional LLM evaluation of file contents. It accepts a directory, a single file, a git URL or a zip, and covers Claude Code skills, Codex and Gemini CLI skills, MCP servers, &lt;code&gt;SKILL.md&lt;/code&gt; files and Python or JS dependencies. MCP scanning needs the extra, installed as &lt;code&gt;skillspector[mcp]&lt;/code&gt;.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;uv tool &lt;span class="nb"&gt;install &lt;/span&gt;git+https://github.com/NVIDIA/skillspector.git
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Run it with &lt;code&gt;--no-llm&lt;/code&gt; and it's fully offline and free. The semantic pass needs your own provider and API key.&lt;/p&gt;

&lt;p&gt;Its documented blind spots: it misses non-English content, can't read text inside images, can't process encrypted or binary code, and when OSV.dev is unreachable it falls back to a small bundled vulnerability list.&lt;/p&gt;

&lt;h3&gt;
  
  
  Who should not use SkillSpector?
&lt;/h3&gt;

&lt;p&gt;Nobody, really, at this price. But it only answers one question. It tells you whether a skill looks malicious, not whether your agent will do something reckless with legitimate tools, which is the more common failure.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href="https://github.com/snyk/agent-scan" rel="noopener noreferrer"&gt;Snyk Agent Scan&lt;/a&gt;&lt;/strong&gt; covers different ground: it discovers agent components already on your machine and scans for prompt injections, tool poisoning, toxic flows and malware hidden in natural language. Apache 2.0, 3,000 stars, actively maintained.&lt;/p&gt;

&lt;p&gt;Its own README says, in bold: scanning MCP configurations will execute the commands defined in them. It starts stdio MCP servers by running their configured commands to read tool descriptions. Snyk's own advice is to run scans inside a container or VM when evaluating untrusted configs. There's a consent prompt per server by default.&lt;/p&gt;

&lt;p&gt;So a pre install scanner that runs the untrusted thing is a different risk model from SkillSpector's. Use it for auditing what you've already got, not for vetting something you don't trust. It also needs a Snyk account and a token, and while the free plan is $0, it's metered by test counts. Whether agent scans draw on those quotas isn't documented.&lt;/p&gt;

&lt;h2&gt;
  
  
  Layer 2: What Stops a Command Before It Runs?
&lt;/h2&gt;

&lt;p&gt;Start with what you already have, because it's substantial and it's what every third party tool hooks into anyway.&lt;/p&gt;

&lt;h3&gt;
  
  
  Claude Code's built in permissions
&lt;/h3&gt;

&lt;p&gt;Under &lt;code&gt;permissions&lt;/code&gt; in your settings file you get &lt;code&gt;allow&lt;/code&gt;, &lt;code&gt;ask&lt;/code&gt; and &lt;code&gt;deny&lt;/code&gt; arrays, plus &lt;code&gt;defaultMode&lt;/code&gt; and &lt;code&gt;additionalDirectories&lt;/code&gt;. Rules look like &lt;code&gt;Bash(rm *)&lt;/code&gt;, &lt;code&gt;Read(./.env)&lt;/code&gt; and &lt;code&gt;WebFetch(domain:example.com)&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;Two behaviors make this more useful than it first looks. Deny beats allow, and a deny rule cannot carry exceptions: a broad &lt;code&gt;Bash(aws *)&lt;/code&gt; blocks every matching call even when a narrower allow rule also matches. And deny rules match inside subshells, command substitutions, pipes and &lt;code&gt;for&lt;/code&gt; loops, and past environment variable assignments, so &lt;code&gt;FOO=bar rm -rf tmp/&lt;/code&gt; still trips &lt;code&gt;Bash(rm *)&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;A bare tool name in deny, like &lt;code&gt;"Bash"&lt;/code&gt;, removes the tool from Claude's context entirely so the model never sees it. A scoped rule leaves the tool available and blocks only matching calls.&lt;/p&gt;

&lt;p&gt;Here's the honest part, and it comes straight from Anthropic's own docs. A deny rule does not match the same program called by absolute path or inside &lt;code&gt;sh -c&lt;/code&gt;. &lt;code&gt;Bash(curl *)&lt;/code&gt; misses &lt;code&gt;/usr/bin/curl&lt;/code&gt; and &lt;code&gt;sh -c 'curl ...'&lt;/code&gt;. &lt;code&gt;Bash(rm *)&lt;/code&gt; misses &lt;code&gt;/bin/rm -rf build/&lt;/code&gt;. Read and Edit deny rules don't cover a Python or Node script that opens files itself, or &lt;code&gt;grep -r pattern .&lt;/code&gt; run from the right directory. Environment runners aren't stripped either, so &lt;code&gt;Bash(devbox run *)&lt;/code&gt; would happily permit &lt;code&gt;devbox run rm -rf .&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;Which is why the docs' own recommendation is to stop matching command text and enforce at the OS level instead.&lt;/p&gt;

&lt;h3&gt;
  
  
  The sandbox, which is free and most people have not turned on
&lt;/h3&gt;

&lt;p&gt;Run &lt;code&gt;/sandbox&lt;/code&gt; and Claude Code gives you OS level filesystem and network isolation covering Bash commands and their child processes. It's built in, using Seatbelt on macOS with nothing to install, and two packages on Linux or WSL2. Native Windows isn't supported.&lt;/p&gt;

&lt;p&gt;It can block writes outside your working directory, including &lt;code&gt;~/.bashrc&lt;/code&gt; and &lt;code&gt;/bin/&lt;/code&gt;. No domains are allowed by default, and you allowlist them under &lt;code&gt;sandbox.network.allowedDomains&lt;/code&gt;. Credential masking swaps a sentinel for the real secret only on allowed hosts.&lt;/p&gt;

&lt;p&gt;Three defaults to know, because they're the difference between protection and the appearance of it. Claude can retry a blocked command with the sandbox disabled unless you set &lt;code&gt;allowUnsandboxedCommands: false&lt;/code&gt;. If the sandbox can't start, Claude Code warns and runs commands unsandboxed unless you set &lt;code&gt;failIfUnavailable: true&lt;/code&gt;. And the docs say plainly that sandboxing reduces risk but is not a complete isolation boundary.&lt;/p&gt;

&lt;p&gt;A &lt;code&gt;PreToolUse&lt;/code&gt; hook is the third free mechanism. Exit with code 2 and the tool call is blocked unconditionally, before permission rules are even evaluated. Every third party runtime tool in this category uses this same hook.&lt;/p&gt;

&lt;p&gt;If you'd rather not assemble that yourself, &lt;strong&gt;&lt;a href="https://github.com/dwarvesf/claude-guardrails" rel="noopener noreferrer"&gt;dwarvesf/claude-guardrails&lt;/a&gt;&lt;/strong&gt; is a hardened config bundle, MIT licensed, pushed within the last week. Lite gives you 21 credential deny rules and 4 hooks for trusted projects. Full gives 40 rules, 6 hooks and a prompt injection scanner for untrusted codebases. It's the free config above, pre packaged.&lt;/p&gt;

&lt;p&gt;I'd skip &lt;strong&gt;rulebricks/claude-code-guardrails&lt;/strong&gt;. It's a &lt;code&gt;PreToolUse&lt;/code&gt; hook that routes policy to the hosted Rulebricks platform, 79 stars, and its last commit was about seven months ago. The authors say they've since built a commercial product. The rule engine being hosted also means it isn't purely local.&lt;/p&gt;

&lt;h3&gt;
  
  
  Harden's AIF, the interesting paid adjacent option
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href="https://harden.run?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Harden&lt;/a&gt;&lt;/strong&gt; ships Agentic Integrity Foundation, which evaluates covered tool calls before execution and records the verdict locally. Six decisions: allow, block, ask, redact, log only, model error.&lt;/p&gt;

&lt;p&gt;Redact is the feature worth the install. Instead of just blocking a &lt;code&gt;curl&lt;/code&gt; carrying a Stripe key, it rewrites the secret to &lt;code&gt;[AIF_REDACTED]&lt;/code&gt; so the retry can proceed safely. Its rule families cover DLP patterns for Stripe, Slack, Telegram and Azure secrets, plus policy checks like &lt;code&gt;curl_pipe_to_shell&lt;/code&gt;, flagged because downloaded code would run immediately.&lt;/p&gt;

&lt;p&gt;It scores calls with a local model post trained from Zyphra's ZAYA1-8B, quantized to Q4_K_M. Budget for it: the download is 5.17 GiB and first install wants 10 GB free disk, 15 GB for updates. The CLI is macOS or Linux only, and the full local model has Apple Silicon requirements.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl &lt;span class="nt"&gt;-fsSL&lt;/span&gt; https://aif.harden.run/install.sh | sh
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Its &lt;a href="https://docs.harden.run/integrations/agents" rel="noopener noreferrer"&gt;integrations page&lt;/a&gt; lists Claude Code, Codex, Cursor, Antigravity CLI, Hermes, Kiro and OpenClaw, using native hooks where they exist and a bridge process elsewhere, and the repo README adds Gemini CLI. Check the current list for your agent rather than trusting either. Kiro subagent shell and file operations are a documented exclusion.&lt;/p&gt;

&lt;p&gt;Harden says AIF is free forever for individual developers, with no account or card, and shared controls for teams on top. No enterprise numbers are published.&lt;/p&gt;

&lt;p&gt;Read the license before you lean on it, though. Its &lt;a href="https://github.com/hardenrun/aif" rel="noopener noreferrer"&gt;public repo&lt;/a&gt; has 728 stars but ships no source code, just an installer, docs and an issue tracker, and &lt;a href="https://raw.githubusercontent.com/hardenrun/aif/main/LICENSE.txt" rel="noopener noreferrer"&gt;LICENSE.txt&lt;/a&gt; is an "AIF Beta License Agreement" from VizopsAI, Inc. covering the binary. It forbids decompiling the proprietary parts, and says the software "may contain defects, may change or be withdrawn at any time, and is not guaranteed to be complete, supported, or fit for production use", with a documented version-recall mechanism. Bundled open source components keep their own licenses.&lt;/p&gt;

&lt;p&gt;None of that makes it a bad tool. It does mean you're installing a closed beta binary as a security control, which is a different proposition from SkillSpector's Apache 2.0 source you can read.&lt;/p&gt;

&lt;p&gt;Worth crediting: its docs state coverage per agent rather than implying blanket protection, and the Kiro exclusion above is documented instead of buried. That's more honest than most of this market.&lt;/p&gt;

&lt;h2&gt;
  
  
  Layer 3: Is Post Hoc Review Worth It Yet?
&lt;/h2&gt;

&lt;p&gt;For a solo developer, no.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href="https://watcher.apolloresearch.ai?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Apollo Research Watcher&lt;/a&gt;&lt;/strong&gt; is the serious entrant. It scores every tool call through a three stage pipeline: zero latency regex rules, then a fast triage model for ambiguous cases, then a fuller evaluator, which can run a different model from the agent so the monitor doesn't share the agent's biases. Most safe actions resolve in under two seconds. It does both blocking and trailing review, with a team dashboard and central policy. Apollo's own framing is an MDM for coding agents.&lt;/p&gt;

&lt;p&gt;Three reasons it isn't an indie hacker purchase. There's no public pricing at all, just a sales call. The public repo is a binary distribution repo, not source, and no license is published. And while self hosting is offered alongside an Apollo-hosted option, you arrange it through the same sales call.&lt;/p&gt;

&lt;p&gt;Its landing page reports 100% recall on critical severity failures, under 1% false positives, and 3 to 5% added cost. Its own technical blog gives no recall figures and cites 1 to 5% overhead. Inconsistent across its own pages, and vendor reported either way. You'll also see a 93% recall figure circulating from an aggregator site. I wouldn't repeat it.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;AIR Security&lt;/strong&gt; raised $50M on September 1, 2026, led by Sequoia then Greenoaks, founded by two Unit 8200 alumni. TechCrunch reports it filters roughly 27% of tools found online and has more than 20 customers, about a quarter large enterprises. It publishes no pricing and no self-serve signup, and TechCrunch describes it selling to companies rather than individuals. Treat it as the enterprise end of this market.&lt;/p&gt;

&lt;h2&gt;
  
  
  My Recommendation
&lt;/h2&gt;

&lt;p&gt;Spend an hour on the free layer and you'll have covered more risk than any purchase would.&lt;/p&gt;

&lt;p&gt;Write deny rules for your secrets first: &lt;code&gt;Read(./.env)&lt;/code&gt;, &lt;code&gt;Read(**/.env)&lt;/code&gt;, &lt;code&gt;Read(./secrets/**)&lt;/code&gt;. Add &lt;code&gt;Bash&lt;/code&gt; denies for the destructive commands you'd never want run unattended. Then turn on &lt;code&gt;/sandbox&lt;/code&gt;, and set &lt;code&gt;allowUnsandboxedCommands: false&lt;/code&gt; and &lt;code&gt;failIfUnavailable: true&lt;/code&gt; so the protection doesn't quietly disable itself. If you want a head start, clone &lt;a href="https://github.com/dwarvesf/claude-guardrails" rel="noopener noreferrer"&gt;dwarvesf/claude-guardrails&lt;/a&gt; and read its rules rather than pasting them blind.&lt;/p&gt;

&lt;p&gt;Install &lt;a href="https://github.com/NVIDIA/SkillSpector" rel="noopener noreferrer"&gt;SkillSpector&lt;/a&gt; and actually run it before adding a skill or MCP server you didn't write. It takes one command and it never executes what it inspects.&lt;/p&gt;

&lt;p&gt;Add &lt;a href="https://harden.run?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Harden's AIF&lt;/a&gt; if secret redaction appeals and you have 10 GB to spare. It's the only tool here doing something the free layer can't.&lt;/p&gt;

&lt;p&gt;Skip Layer 3 until you have teammates and an audit requirement.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://devtoolpicks.com/blog/best-ai-coding-agent-security-tools-indie-hackers-2026" rel="noopener noreferrer"&gt;View the interactive diagram on devtoolpicks.com&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The lesson from PocketOS wasn't that the agent was malicious. It was that a token made for managing domain names could delete a database, and was sitting somewhere the agent could read it. Most of what these tools sell you is a way to make that impossible, and the cheapest version of that is a deny rule you can write this afternoon.&lt;/p&gt;

&lt;p&gt;For more on what agents can reach and how the pieces fit, see &lt;a href="https://devtoolpicks.com/blog/claude-skills-vs-mcp-connectors-vs-plugins-2026" rel="noopener noreferrer"&gt;Claude Skills vs MCP connectors vs plugins&lt;/a&gt; and &lt;a href="https://devtoolpicks.com/blog/ai-agents-runaway-claude-code-bills-overnight-2026" rel="noopener noreferrer"&gt;how to stop a runaway Claude Code session&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Found a better option? Let me know on Twitter &lt;a class="mentioned-user" href="https://dev.to/devtoolpicks"&gt;@devtoolpicks&lt;/a&gt;.&lt;/p&gt;

</description>
      <category>aicodingtools</category>
      <category>developertools</category>
      <category>claudecode</category>
      <category>indiehacker</category>
    </item>
    <item>
      <title>When to Use LiteLLM Self-Hosted vs a Managed AI Gateway</title>
      <dc:creator>DevToolsPicks</dc:creator>
      <pubDate>Fri, 11 Sep 2026 06:00:11 +0000</pubDate>
      <link>https://dev.to/devtoolpicks/when-to-use-litellm-self-hosted-vs-a-managed-ai-gateway-3gke</link>
      <guid>https://dev.to/devtoolpicks/when-to-use-litellm-self-hosted-vs-a-managed-ai-gateway-3gke</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Originally published at &lt;a href="https://devtoolpicks.com/blog/when-to-use-litellm-self-hosted-vs-managed-ai-gateway-indie-hackers-2026" rel="noopener noreferrer"&gt;devtoolpicks.com&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;




&lt;p&gt;On September 3, 2026, ChatGPT, Claude and Grok all had outages inside the same few hours. Claude was down for three hours and six minutes. Everything was back by 12:38pm Pacific, and the Hacker News thread asking why three providers broke at once ran to 688 comments.&lt;/p&gt;

&lt;p&gt;If your app called one provider directly, your app was down too. If it went through a gateway with a fallback configured, it wasn't.&lt;/p&gt;

&lt;p&gt;So the gateway question isn't really "should I have one". It's who runs it. And the answer people reach for, self-host it because the software is free, is wrong more often than it's right.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Does a Gateway Actually Do?
&lt;/h2&gt;

&lt;p&gt;One API in front of many providers, plus the things you'd otherwise build twice. Automatic fallback when a provider errors or times out. Spend caps per key so one runaway loop can't empty your account. Request logging you can search when a customer says the output was wrong. Caching for repeated prompts.&lt;/p&gt;

&lt;p&gt;LiteLLM's open source proxy gives you all of that for free. 100 plus providers behind one OpenAI-shaped API, virtual keys, users and teams, spend tracking, budgets, rate limits, fallbacks, request and response logging, Prometheus metrics. It's a good piece of software and the licence costs nothing.&lt;/p&gt;

&lt;p&gt;Worth saying plainly: a fallback only saves you if the backup provider serves a model you'd accept. Falling back from Claude to a model that can't follow your prompt format turns an outage into a stream of bad output, which is sometimes worse than an error your app can retry. Pick the second choice deliberately and test it before you need it.&lt;/p&gt;

&lt;p&gt;That's the part everyone gets right. The next part is where the money actually is.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://devtoolpicks.com/blog/when-to-use-litellm-self-hosted-vs-managed-ai-gateway-indie-hackers-2026" rel="noopener noreferrer"&gt;View the interactive component on devtoolpicks.com&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  What Does Self-Hosting Really Cost?
&lt;/h2&gt;

&lt;p&gt;Not much, in hardware. A Hetzner CX22 is €3.79 a month before VAT for 2 vCPUs, 4 GB of RAM, 40 GB of disk and 20 TB of traffic. That runs a LiteLLM proxy for a solo SaaS without breathing hard. On Railway you'd be at $5 a month on Hobby including $5 of usage credit, more once Postgres and Redis are running.&lt;/p&gt;

&lt;p&gt;You need both of those, by the way. Postgres holds keys and spend records. Redis handles rate limiting and caching. At small scale they sit on the same box happily enough.&lt;/p&gt;

&lt;p&gt;Then comes the actual cost. A gateway sits in the request path, which means its uptime is your uptime. Every AI feature you ship goes through it. When it falls over at 3am, your product is down and you are the on-call rotation. You've taken a thing that was somebody else's problem and made it yours, to save roughly the price of a coffee.&lt;/p&gt;

&lt;p&gt;If you already run infrastructure and enjoy it, that trade is fine. Our &lt;a href="https://devtoolpicks.com/blog/when-to-use-vercel-vs-railway-vs-hetzner-solo-saas-2026" rel="noopener noreferrer"&gt;Vercel, Railway and Hetzner comparison&lt;/a&gt; covers the same instinct applied to hosting generally. But price it honestly, because the server was never the expensive part.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Does Managed Really Cost?
&lt;/h2&gt;

&lt;p&gt;Less than the self-hosting crowd assumes, which is what makes this decision lopsided.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Gateway&lt;/th&gt;
&lt;th&gt;Free tier&lt;/th&gt;
&lt;th&gt;Paid entry&lt;/th&gt;
&lt;th&gt;Notes&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://developers.cloudflare.com/ai-gateway/?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Cloudflare AI Gateway&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Core features free, all plans&lt;/td&gt;
&lt;td&gt;Free&lt;/td&gt;
&lt;td&gt;100k logs on Workers Free, 10M per gateway on Workers Paid&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://portkey.ai?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Portkey&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;10k logs/month, 3-day retention&lt;/td&gt;
&lt;td&gt;$49/month&lt;/td&gt;
&lt;td&gt;100k logs, then $9 per extra 100k&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://www.helicone.ai?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Helicone&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;10k requests/month, 1 seat&lt;/td&gt;
&lt;td&gt;$79/month&lt;/td&gt;
&lt;td&gt;7-day retention free, 1 month on Pro&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://openrouter.ai?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;OpenRouter&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;No markup on inference&lt;/td&gt;
&lt;td&gt;Free&lt;/td&gt;
&lt;td&gt;5.5% on Stripe credit purchases, 5% BYOK above $25k/month&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;a href="https://www.litellm.ai?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;LiteLLM&lt;/a&gt; self-hosted&lt;/td&gt;
&lt;td&gt;Everything, forever&lt;/td&gt;
&lt;td&gt;~€4/month server&lt;/td&gt;
&lt;td&gt;Plus Postgres, Redis and your own pager&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Cloudflare AI Gateway's core features are free on every plan, including dashboard analytics, caching and rate limiting. Logpush costs $0.05 per million requests above the 10 million base, and unified billing adds a 5% fee on credit purchases. For a solo builder that's effectively zero.&lt;/p&gt;

&lt;p&gt;Read that table again with the self-hosting argument in mind. The pitch for running your own is cost, and the cheapest managed option costs nothing while somebody else carries the pager.&lt;/p&gt;

&lt;h2&gt;
  
  
  So When Does Self-Hosting Actually Win?
&lt;/h2&gt;

&lt;p&gt;Three situations, and they're all about constraints rather than price.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Data residency and air-gap.&lt;/strong&gt; If prompts can't leave your infrastructure, no hosted gateway works, and this is the reason that survives every argument. LiteLLM Enterprise supports air-gapped deployment for exactly this.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Routing logic nobody sells.&lt;/strong&gt; Model choice by customer tier, a bespoke cost ceiling per tenant, a fallback order that depends on your own data. Hosted products express the common cases well and the unusual ones not at all.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Log volume.&lt;/strong&gt; Per-log pricing is fine until it isn't. Portkey Production includes 100,000 logs for $49 and charges $9 for each additional 100,000. Run 3 million logs a month and you're at $49 plus 29 blocks of overage, which is $310. Against a €4 server that finally reads like a real argument, and it's the point where most teams should switch.&lt;/p&gt;

&lt;p&gt;Getting there takes a while, though. Three million logs a month is roughly 100,000 requests a day, every day. Most solo products never see that, and the ones that do have revenue to match.&lt;/p&gt;

&lt;p&gt;Notice what's missing. "I want to save $49 a month" is not on the list, because at that scale you're spending far more on tokens than on the gateway, and the gateway is the cheapest line on the invoice.&lt;/p&gt;

&lt;h2&gt;
  
  
  What About Portkey's Acquisition?
&lt;/h2&gt;

&lt;p&gt;Palo Alto Networks completed its purchase of Portkey on May 29, 2026, and Portkey is now the AI Gateway inside Prisma AIRS, aimed at securing AI agents. The press release says nothing about the standalone product, the open source gateway, or what happens to existing pricing.&lt;/p&gt;

&lt;p&gt;Silence isn't a reason to migrate this week. It is a reason to keep your setup portable. Any of these gateways speaks the OpenAI API shape, so switching should be a config change rather than a rewrite, and it stays that way only if you don't build against one vendor's proprietary features. The &lt;a href="https://devtoolpicks.com/blog/litellm-vs-portkey-vs-cloudflare-ai-gateway-indie-hackers-2026" rel="noopener noreferrer"&gt;LiteLLM, Portkey and Cloudflare comparison&lt;/a&gt; goes deeper on the feature differences.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Pick
&lt;/h2&gt;

&lt;p&gt;Start managed. Start with Cloudflare AI Gateway, because free and operated by someone else beats €4 and operated by you, and it takes one line of code to put in front of your existing calls.&lt;/p&gt;

&lt;p&gt;Move to Portkey or Helicone when you want better logging and search than the free tier gives you, somewhere around the point where you're debugging customer complaints weekly rather than monthly.&lt;/p&gt;

&lt;p&gt;Self-host LiteLLM when a constraint forces it. Compliance, air-gap, or routing you can't buy. Not to save money, because you won't.&lt;/p&gt;

&lt;p&gt;And whichever you run, set the spend caps on day one. A gateway without budgets is just a faster way to discover &lt;a href="https://devtoolpicks.com/blog/ai-agents-runaway-claude-code-bills-overnight-2026" rel="noopener noreferrer"&gt;what a runaway agent loop costs overnight&lt;/a&gt;, and configure the fallbacks too, because September 3 will happen again. The &lt;a href="https://devtoolpicks.com/blog/best-openrouter-alternatives-indie-hackers-2026" rel="noopener noreferrer"&gt;OpenRouter alternatives roundup&lt;/a&gt; covers who to fall back to.&lt;/p&gt;

</description>
      <category>aitools</category>
      <category>developertools</category>
      <category>indiehacker</category>
      <category>opensource</category>
    </item>
    <item>
      <title>Best Cron and Scheduled Job Monitoring Tools for Indie Hackers in 2026</title>
      <dc:creator>DevToolsPicks</dc:creator>
      <pubDate>Wed, 09 Sep 2026 06:00:11 +0000</pubDate>
      <link>https://dev.to/devtoolpicks/best-cron-and-scheduled-job-monitoring-tools-for-indie-hackers-in-2026-3042</link>
      <guid>https://dev.to/devtoolpicks/best-cron-and-scheduled-job-monitoring-tools-for-indie-hackers-in-2026-3042</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Originally published at &lt;a href="https://devtoolpicks.com/blog/best-cron-job-monitoring-tools-indie-hackers-2026" rel="noopener noreferrer"&gt;devtoolpicks.com&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;




&lt;p&gt;Your nightly database backup stopped running on August 12. You found out on September 4, when you needed it.&lt;/p&gt;

&lt;p&gt;Nothing alerted you, because nothing errored. The job didn't throw an exception or exit non-zero. It just stopped being invoked, so there was no exception to catch, no log line to grep, and nothing for Sentry to report. Your error tracker was working perfectly the whole time. It was watching the wrong thing.&lt;/p&gt;

&lt;p&gt;That's the gap cron monitoring fills, and it's the one piece of the stack most solo builders skip.&lt;/p&gt;

&lt;h2&gt;
  
  
  How Does a Dead Man's Switch Actually Work?
&lt;/h2&gt;

&lt;p&gt;The model is inverted compared to every other monitor you run. Instead of something calling your app to check it's alive, your job calls out every time it finishes. The monitor holds a timer. If the ping doesn't arrive before the deadline plus a grace period, you get an alert.&lt;/p&gt;

&lt;p&gt;That's it. One HTTP request appended to the end of your job, usually a curl at the end of the crontab line.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://devtoolpicks.com/blog/best-cron-job-monitoring-tools-indie-hackers-2026" rel="noopener noreferrer"&gt;View the interactive component on devtoolpicks.com&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;One rule matters more than any feature comparison. Never run the monitor on the same machine as the jobs. A server that dies takes both with it, and you learn nothing.&lt;/p&gt;

&lt;h2&gt;
  
  
  Quick Verdict
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Tool&lt;/th&gt;
&lt;th&gt;Best for&lt;/th&gt;
&lt;th&gt;Free tier&lt;/th&gt;
&lt;th&gt;Rating&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://healthchecks.io?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Healthchecks.io&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;The default pick&lt;/td&gt;
&lt;td&gt;20 jobs&lt;/td&gt;
&lt;td&gt;4.5/5&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://betterstack.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Better Stack&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Uptime and heartbeats together&lt;/td&gt;
&lt;td&gt;10 heartbeats + 10 monitors&lt;/td&gt;
&lt;td&gt;4.5/5&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://cronitor.io?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Cronitor&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Catching slow jobs, not just dead ones&lt;/td&gt;
&lt;td&gt;5 monitors&lt;/td&gt;
&lt;td&gt;4/5&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://deadmanssnitch.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Dead Man's Snitch&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;One critical job, nothing more&lt;/td&gt;
&lt;td&gt;1 snitch&lt;/td&gt;
&lt;td&gt;3.5/5&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://ohdear.app?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Oh Dear&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Laravel shops who want everything in one&lt;/td&gt;
&lt;td&gt;None, $17/mo&lt;/td&gt;
&lt;td&gt;4/5&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://hyperping.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Hyperping&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Cron plus status page on one bill&lt;/td&gt;
&lt;td&gt;20 monitors&lt;/td&gt;
&lt;td&gt;3.5/5&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  Healthchecks.io
&lt;/h2&gt;

&lt;p&gt;The one I'd start with. The free Hobbyist plan monitors 20 jobs with 100 log entries each, which is more than most solo projects will ever schedule. Supporter is $5 a month for the same limits if you want to fund it. Business is $20 a month for 100 jobs, 1,000 log entries, 50 SMS credits and 20 phone call credits.&lt;/p&gt;

&lt;p&gt;The real argument is the escape hatch. Healthchecks is BSD 3-clause open source and the hosted service runs the same code you can deploy yourself. Pricing risk is close to zero when you can walk with the software.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Who should skip it:&lt;/strong&gt; anyone who wants one vendor for uptime, errors and heartbeats. This does one job.&lt;/p&gt;

&lt;h2&gt;
  
  
  Better Stack
&lt;/h2&gt;

&lt;p&gt;The most generous free tier here by some distance. Ten monitors and ten heartbeats, checks as often as every 30 seconds, and unlimited SMS and phone call alerts without paying anything. Phone alerts on a free plan is unusual enough to be the deciding factor for a lot of people.&lt;/p&gt;

&lt;p&gt;Scaling costs $25 a month per 50 extra monitors and $20 a month per 10 extra heartbeats, dropping to $21 and $17 on annual billing. Heartbeats get expensive faster than monitors do, so watch that ratio if you schedule a lot of small jobs.&lt;/p&gt;

&lt;p&gt;It also shows up in our &lt;a href="https://devtoolpicks.com/blog/best-uptime-monitoring-tools-indie-hackers-2026" rel="noopener noreferrer"&gt;uptime monitoring roundup&lt;/a&gt;, which is the other half of this problem.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Who should skip it:&lt;/strong&gt; anyone monitoring 40 jobs. The heartbeat pricing works against you at that point.&lt;/p&gt;

&lt;h2&gt;
  
  
  Cronitor
&lt;/h2&gt;

&lt;p&gt;Cronitor is the one that knows your job ran slowly. It's schedule aware, so it tracks duration and can alert when a job that normally takes 40 seconds suddenly takes nine minutes. That's the failure that precedes the outage, and none of the pure heartbeat services see it.&lt;/p&gt;

&lt;p&gt;Free Hacker gives you 5 monitors, one seat, and email and Slack only. Business is usage based at $2 per monitor plus $5 per user, so 20 monitors across 3 people works out at $55 a month, with 6 months of retention and all 11 alert integrations including SMS and on-call routing.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Who should skip it:&lt;/strong&gt; anyone with a handful of jobs. At small scale you're paying for analytics you won't read.&lt;/p&gt;

&lt;h2&gt;
  
  
  Dead Man's Snitch
&lt;/h2&gt;

&lt;p&gt;The oldest and simplest option, and it still does the job. Free covers exactly one snitch, which is enough if you have precisely one thing that must not die quietly. Little Birdy is $5 a month for 3, Private Eye is $19 for 100, Surveillance Van is $49 for 300 with smart alerts and error notices.&lt;/p&gt;

&lt;p&gt;Every paid tier carries unlimited team members, which is a nicer stance than most.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Who should skip it:&lt;/strong&gt; anyone comparing on features. The jump from 3 monitors to 100 with nothing in between is awkward if you land at 8.&lt;/p&gt;

&lt;h2&gt;
  
  
  Oh Dear
&lt;/h2&gt;

&lt;p&gt;Scheduled task monitoring is included in every Oh Dear plan alongside uptime, SSL, broken links, DNS, performance, domain expiry and status pages. Nothing is gated to a higher tier. The only thing that changes as you pay more is how many sites you watch.&lt;/p&gt;

&lt;p&gt;Solo is $17 a month for 2 sites, Solo Plus is $32 for 5, Freelance is $55 for 10, all with unlimited team members. It's built by people from the Laravel world and it shows in how the scheduled task integration fits a Laravel app.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Who should skip it:&lt;/strong&gt; anyone with one site and one cron job. You're buying nine products to use one.&lt;/p&gt;

&lt;h2&gt;
  
  
  Hyperping
&lt;/h2&gt;

&lt;p&gt;Hyperping folds heartbeat checks in beside uptime monitoring rather than selling them separately. The free plan covers 20 monitors at 5 minute checks with one status page. Essentials at $29 a month brings 50 monitors, 30 second checks and a status page on your own domain. Pro at $89 gets 100 monitors and three status pages. Annual billing gives you two months free.&lt;/p&gt;

&lt;p&gt;The pricing page counts monitors, not cron jobs, so budget by total checks rather than by scheduled tasks. It's the tidiest option if you want monitoring and a public &lt;a href="https://devtoolpicks.com/blog/best-status-page-tools-indie-hackers-2026" rel="noopener noreferrer"&gt;status page&lt;/a&gt; on one invoice.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Who should skip it:&lt;/strong&gt; cron-first users. Paying $29 a month to get past a free tier built around uptime is poor value when Healthchecks watches 20 jobs for nothing.&lt;/p&gt;

&lt;h2&gt;
  
  
  What About Laravel's Scheduler?
&lt;/h2&gt;

&lt;p&gt;If you're on Laravel you already have the wiring. The scheduler ships with &lt;code&gt;pingOnSuccess&lt;/code&gt; and &lt;code&gt;pingOnFailure&lt;/code&gt;, plus &lt;code&gt;pingBefore&lt;/code&gt; and &lt;code&gt;thenPing&lt;/code&gt; for the start and end of a task, and conditional variants of all four. Point them at a Healthchecks or Cronitor URL and you're done in one line per task.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight php"&gt;&lt;code&gt;&lt;span class="nc"&gt;Schedule&lt;/span&gt;&lt;span class="o"&gt;::&lt;/span&gt;&lt;span class="nf"&gt;command&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;'backup:run'&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="o"&gt;-&amp;gt;&lt;/span&gt;&lt;span class="nf"&gt;dailyAt&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;'02:00'&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="o"&gt;-&amp;gt;&lt;/span&gt;&lt;span class="nf"&gt;pingOnSuccess&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$url&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="o"&gt;-&amp;gt;&lt;/span&gt;&lt;span class="nf"&gt;pingOnFailure&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$failureUrl&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;No package needed. This is the cheapest observability win available to a Laravel app, and it pairs well with the queue side covered in our &lt;a href="https://devtoolpicks.com/blog/best-background-job-tools-indie-hackers-2026" rel="noopener noreferrer"&gt;background job tools roundup&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  How Should You Choose?
&lt;/h2&gt;

&lt;p&gt;Count your jobs first, because that number decides almost everything.&lt;/p&gt;

&lt;p&gt;Under 20 jobs and no budget: Healthchecks.io free. It's not a trial, it's a real tier, and the self-host option means you never get squeezed later.&lt;/p&gt;

&lt;p&gt;Already paying for uptime monitoring: Better Stack, and consolidate. Ten free heartbeats bolted onto monitoring you already run is less work than a second vendor and a second login.&lt;/p&gt;

&lt;p&gt;Jobs where timing matters, like a billing run or a nightly export with an SLA behind it: Cronitor. Duration tracking is worth real money when a job finishing late costs you something.&lt;/p&gt;

&lt;p&gt;And whatever you pick, alerts belong somewhere you'll actually see them. An email alert at 3am is a log entry with extra steps. Route the ones that matter to SMS or a phone call, the same way you'd route &lt;a href="https://devtoolpicks.com/blog/sentry-vs-honeybadger-vs-glitchtip-indie-hackers-2026" rel="noopener noreferrer"&gt;error tracking&lt;/a&gt; alerts.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Pick
&lt;/h2&gt;

&lt;p&gt;Healthchecks.io for most people. Twenty free jobs covers a solo SaaS with room to spare, the interface stays out of the way, and BSD licensing means the pricing page can never hold you hostage.&lt;/p&gt;

&lt;p&gt;Better Stack wins if you're already inside it for uptime. Cronitor wins when late is as bad as never.&lt;/p&gt;

&lt;p&gt;The tool matters less than doing it at all. Every scheduled job you run right now is either monitored or it's a silent failure waiting for the worst possible day to reveal itself, and adding the ping takes about 30 seconds per job.&lt;/p&gt;

</description>
      <category>developertools</category>
      <category>indiehacker</category>
      <category>observability</category>
      <category>saastools</category>
    </item>
    <item>
      <title>Best Hugging Face Inference Alternatives for Indie Hackers in 2026</title>
      <dc:creator>DevToolsPicks</dc:creator>
      <pubDate>Mon, 07 Sep 2026 06:00:10 +0000</pubDate>
      <link>https://dev.to/devtoolpicks/best-hugging-face-inference-alternatives-for-indie-hackers-in-2026-1o4i</link>
      <guid>https://dev.to/devtoolpicks/best-hugging-face-inference-alternatives-for-indie-hackers-in-2026-1o4i</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Originally published at &lt;a href="https://devtoolpicks.com/blog/best-hugging-face-inference-alternatives-indie-hackers-2026" rel="noopener noreferrer"&gt;devtoolpicks.com&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;




&lt;p&gt;Nvidia agreed to buy Hugging Face on September 3, 2026, for $12.93 billion. Jensen Huang said the platform stays open and that Nvidia compute won't be required to build or deploy on it. Clem Delangue said Nvidia committed to keeping it open, independent and compute agnostic. Take them at their word, because the acquisition isn't really the reason to go looking.&lt;/p&gt;

&lt;p&gt;The reason is the bill. Dedicated Inference Endpoints have always been the expensive part of Hugging Face, and a $12.93 billion deal is a good excuse to actually read your invoice. An H100 endpoint on the Hugging Face GCP tier costs $10.00 an hour. RunPod rents the same card for $1.99. That gap existed in August. Nobody was looking.&lt;/p&gt;

&lt;h2&gt;
  
  
  Which Hugging Face Product Are You Actually Replacing?
&lt;/h2&gt;

&lt;p&gt;Three different products share one name, and most "alternatives" lists mash them together.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Inference Providers&lt;/strong&gt; is a router. Your request goes through Hugging Face to Together, Fireworks, Replicate or another partner, and Hugging Face bills you the provider's own rate with no markup added. That's their documented policy, not a marketing line. Free accounts get $0.10 of credit a month, PRO at $9 gets $2, Team and Enterprise seats get $2 each. If this is what you use, price is not your problem and you can stop reading.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Inference Endpoints&lt;/strong&gt; is the dedicated product. Your model, your GPU, billed per minute at Hugging Face's rates. This is where the money goes.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Spaces&lt;/strong&gt; is for demos. Free on CPU basic and ZeroGPU, $0.40 an hour for a small T4 if you upgrade.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://devtoolpicks.com/blog/best-hugging-face-inference-alternatives-indie-hackers-2026" rel="noopener noreferrer"&gt;View the interactive component on devtoolpicks.com&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Everything below is about replacing the middle one.&lt;/p&gt;

&lt;h2&gt;
  
  
  Quick Verdict
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Platform&lt;/th&gt;
&lt;th&gt;Best for&lt;/th&gt;
&lt;th&gt;H100 per hour&lt;/th&gt;
&lt;th&gt;Rating&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://www.runpod.io?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;RunPod&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Cheapest raw GPU time&lt;/td&gt;
&lt;td&gt;$1.99 community, $2.89 secure&lt;/td&gt;
&lt;td&gt;4.5/5&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://modal.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Modal&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Bursty traffic, fast cold starts&lt;/td&gt;
&lt;td&gt;$3.95&lt;/td&gt;
&lt;td&gt;4.5/5&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://replicate.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Replicate&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Shipping something this weekend&lt;/td&gt;
&lt;td&gt;$5.49&lt;/td&gt;
&lt;td&gt;4/5&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://deepinfra.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;DeepInfra&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Cheapest managed inference&lt;/td&gt;
&lt;td&gt;$2.20&lt;/td&gt;
&lt;td&gt;4/5&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://www.together.ai?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Together AI&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Per-token open models&lt;/td&gt;
&lt;td&gt;$3.99 dedicated&lt;/td&gt;
&lt;td&gt;4/5&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://www.baseten.co?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Baseten&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Production teams who want support&lt;/td&gt;
&lt;td&gt;$6.50&lt;/td&gt;
&lt;td&gt;3.5/5&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Hugging Face for comparison: $2.50 an hour for an A100 on AWS, $3.60 on GCP, $5.00 for an H200, $10.00 for an H100.&lt;/p&gt;

&lt;h2&gt;
  
  
  RunPod
&lt;/h2&gt;

&lt;p&gt;The cheapest way to stop paying platform rates. An A100 PCIe is $1.19 an hour on Community Cloud and $1.39 on Secure Cloud. H100 PCIe is $1.99 and $2.89. An RTX 4090 at $0.34 an hour will serve a 7B model perfectly well, which is the config most side projects actually need.&lt;/p&gt;

&lt;p&gt;Community Cloud is hardware rented from third parties, so treat it as spot capacity rather than something you'd put a paying customer's checkout flow behind. Serverless exists at $4.79 an hour for an H100 if you want autoscaling without managing pods.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Who should skip it:&lt;/strong&gt; anyone who wants a platform to handle deploys, versioning and observability. RunPod hands you a machine. The rest is yours.&lt;/p&gt;

&lt;h2&gt;
  
  
  Modal
&lt;/h2&gt;

&lt;p&gt;Modal charges per second and boots containers in about one second. That combination is what makes scale to zero work in practice rather than just exist on a pricing page. Memory snapshots let a warmed container skip its initialization on later boots, which matters when your model weights take 40 seconds to load.&lt;/p&gt;

&lt;p&gt;An A100 80GB works out to $2.50 an hour, identical to Hugging Face on AWS. H100 SXM5 lands at $3.95, L40S at $1.95, T4 at $0.59. The Starter plan includes $30 of free credit a month, which covers a lot of a hobby project. Team is $250 a month before compute.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Who should skip it:&lt;/strong&gt; anyone who wants a UI. Modal is a Python SDK and you define infrastructure in code. If that sounds like work rather than relief, look elsewhere.&lt;/p&gt;

&lt;h2&gt;
  
  
  Replicate
&lt;/h2&gt;

&lt;p&gt;Replicate is the fastest path from idea to working endpoint, and it has been for three years. Push a model with Cog, get an API. Public models bill by run time, so a text-to-image call costs $0.025 to $0.09 an image and you pay nothing when idle.&lt;/p&gt;

&lt;p&gt;Hardware is pricier than the rest. T4 at $0.81 an hour, L40S at $3.51, A100 80GB at $5.04, H100 at $5.49. You're paying for the packaging, and for a lot of projects that's a fair trade.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Who should skip it:&lt;/strong&gt; anyone running steady traffic. At consistent load, Replicate's A100 costs twice DeepInfra's and four times RunPod's. Prototype here, then move.&lt;/p&gt;

&lt;h2&gt;
  
  
  DeepInfra
&lt;/h2&gt;

&lt;p&gt;The best managed price on the list. A100 at $0.89 an hour, H100 at $2.20, H200 at $2.69. Per-token rates are aggressive too, with DeepSeek V4 Flash at $0.09 in and $0.18 out per million tokens, and Llama 3.3 70B Turbo at $0.10 and $0.32. A Flex tier drops to 0.8x base for non-production work.&lt;/p&gt;

&lt;p&gt;So why isn't everyone here? Smaller model catalog, thinner tooling, and a support story that assumes you can debug your own deployment.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Who should skip it:&lt;/strong&gt; teams who need a specific fine-tuned architecture or an SLA with a name on it.&lt;/p&gt;

&lt;h2&gt;
  
  
  Together AI
&lt;/h2&gt;

&lt;p&gt;Together is the per-token option when you want open models without running anything. Qwen3.8 Flash at $0.15 and $0.47 per million tokens, DeepSeek V4 Flash at $0.14 and $0.28, Llama 3.3 70B at $1.04 flat. Dedicated HGX H100 endpoints are $3.99 an hour on demand if you outgrow serverless.&lt;/p&gt;

&lt;p&gt;It pairs well with a gateway in front. If you're already routing through one, adding Together as a fallback provider takes an afternoon. Our &lt;a href="https://devtoolpicks.com/blog/litellm-vs-portkey-vs-cloudflare-ai-gateway-indie-hackers-2026" rel="noopener noreferrer"&gt;LiteLLM, Portkey and Cloudflare AI Gateway comparison&lt;/a&gt; covers that layer, and the &lt;a href="https://devtoolpicks.com/blog/best-openrouter-alternatives-indie-hackers-2026" rel="noopener noreferrer"&gt;OpenRouter alternatives roundup&lt;/a&gt; covers the routing question directly.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Who should skip it:&lt;/strong&gt; anyone deploying a custom model. Together's catalog is the product.&lt;/p&gt;

&lt;h2&gt;
  
  
  Baseten
&lt;/h2&gt;

&lt;p&gt;The most polished operator experience here. Per-minute billing, real autoscaling, and deployment tooling that a team can hand between people without a handover doc. T4 at $0.63 an hour, A10G at $1.21, A100 80GB at $4.00, H100 at $6.50.&lt;/p&gt;

&lt;p&gt;That H100 rate is over three times RunPod's. You're buying support and a control plane, and for a funded team shipping a product that's defensible. For one person with an idea, it isn't.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Who should skip it:&lt;/strong&gt; solo builders watching every dollar. This is the enterprise-shaped choice on the list.&lt;/p&gt;

&lt;h2&gt;
  
  
  How Should You Choose?
&lt;/h2&gt;

&lt;p&gt;Answer one question first. Do you have steady traffic?&lt;/p&gt;

&lt;p&gt;If no, use per-token serverless. DeepInfra or Together, pay nothing when idle, revisit in three months. Most side projects never leave this box, and the ones that do can afford the migration.&lt;/p&gt;

&lt;p&gt;If yes, and you can operate a machine, RunPod. The saving against Hugging Face is real money at any meaningful uptime, roughly $5,800 a year on a single H100 running half the day.&lt;/p&gt;

&lt;p&gt;If yes, but you'd rather write Python than manage pods, Modal. It costs more than RunPod and less than everything else, and the one second boot is worth paying for.&lt;/p&gt;

&lt;p&gt;Watch the meter either way. Idle GPUs have bankrupted more side projects than bad code, and &lt;a href="https://devtoolpicks.com/blog/ai-agents-runaway-claude-code-bills-overnight-2026" rel="noopener noreferrer"&gt;runaway agent bills&lt;/a&gt; are the same lesson in a different jacket.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Pick
&lt;/h2&gt;

&lt;p&gt;For most indie hackers reading this: DeepInfra for per-token, RunPod when you need your own GPU. That covers the real range of what a solo builder ships, at prices that don't punish you for succeeding.&lt;/p&gt;

&lt;p&gt;Modal is the one I'd actually reach for personally, because per-second billing and a one second boot remove the thing that makes self-managed inference annoying. It's the middle option that behaves like the expensive one.&lt;/p&gt;

&lt;p&gt;And if you're only using Inference Providers, stay. No markup means no problem, whoever owns the company. If you're running models on your own hardware instead, the &lt;a href="https://devtoolpicks.com/blog/best-local-ai-coding-tools-indie-hackers-2026" rel="noopener noreferrer"&gt;local AI tooling roundup&lt;/a&gt; is the other half of this decision.&lt;/p&gt;

</description>
      <category>aitools</category>
      <category>developertools</category>
      <category>indiehacker</category>
      <category>opensource</category>
    </item>
    <item>
      <title>LiteLLM vs Portkey vs Cloudflare AI Gateway for Indie Hackers in 2026</title>
      <dc:creator>DevToolsPicks</dc:creator>
      <pubDate>Fri, 04 Sep 2026 06:00:11 +0000</pubDate>
      <link>https://dev.to/devtoolpicks/litellm-vs-portkey-vs-cloudflare-ai-gateway-for-indie-hackers-in-2026-58eg</link>
      <guid>https://dev.to/devtoolpicks/litellm-vs-portkey-vs-cloudflare-ai-gateway-for-indie-hackers-in-2026-58eg</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Originally published at &lt;a href="https://devtoolpicks.com/blog/litellm-vs-portkey-vs-cloudflare-ai-gateway-indie-hackers-2026" rel="noopener noreferrer"&gt;devtoolpicks.com&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;




&lt;p&gt;Stripe just agreed to buy OpenRouter for over $7 billion. Palo Alto Networks closed its acquisition of Portkey in May. That's two independent AI gateways bought in one year, and every indie hacker running traffic through a hosted router should be re-reading the terms of service. If your router can be acquired, your routing costs can change. So this comparison looks at the three gateways you'd shortlist when you want more control than OpenRouter offers: LiteLLM on your own server, Portkey as a managed control panel, and Cloudflare AI Gateway at the edge.&lt;/p&gt;

&lt;p&gt;The short answer first. Cloudflare for most people, LiteLLM if you already run a VPS, Portkey if observability is the actual problem you're solving.&lt;/p&gt;

&lt;h2&gt;
  
  
  Quick Verdict
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Tool&lt;/th&gt;
&lt;th&gt;Best for&lt;/th&gt;
&lt;th&gt;Price&lt;/th&gt;
&lt;th&gt;Rating&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://developers.cloudflare.com/ai-gateway/?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Cloudflare AI Gateway&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Most indie hackers, zero ops&lt;/td&gt;
&lt;td&gt;Free core features&lt;/td&gt;
&lt;td&gt;9/10&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://litellm.ai?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;LiteLLM&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Self-hosters, full control&lt;/td&gt;
&lt;td&gt;Free (OSS) + your VPS&lt;/td&gt;
&lt;td&gt;8.5/10&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://portkey.ai?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Portkey&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Observability and debugging&lt;/td&gt;
&lt;td&gt;Free tier, $49/mo production&lt;/td&gt;
&lt;td&gt;8/10&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  Cloudflare AI Gateway
&lt;/h2&gt;

&lt;p&gt;Point your OpenAI-style base URL at Cloudflare, and you get caching, rate limiting, analytics, and automatic fallbacks running at their edge. The core features are free with any Cloudflare account. Not free-trial free. Actually free.&lt;/p&gt;

&lt;p&gt;Limits show up in log retention. The free Workers plan stores 100,000 logs total, and the $5/month Workers Paid plan raises that to 10 million per gateway. Unified billing, where Cloudflare buys the tokens and you pay one bill, adds a 5% fee on credit purchases, with inference itself passing through at provider list price. Skip unified billing and there's no percentage anywhere.&lt;/p&gt;

&lt;p&gt;Who should NOT use it? Anyone who needs their gateway to see inside prompts. Cloudflare counts and caches requests, but it won't version your prompts or trace a multi-step agent conversation.&lt;/p&gt;

&lt;h2&gt;
  
  
  LiteLLM
&lt;/h2&gt;

&lt;p&gt;LiteLLM is the open source answer. A Python proxy that speaks the OpenAI format, routes across providers, retries failures, and tracks spend per key. It's free forever, self-hosted, and after the OpenRouter news that phrase carries new weight. Nobody can acquire the container running in your basement.&lt;/p&gt;

&lt;p&gt;The honest math, though. LiteLLM itself costs nothing, but it needs a server, a database for its config, and someone who notices when it falls over at 2 AM. That someone is you. If a VPS is already in your stack, the marginal cost is close to zero and this is a great deal. If you'd be renting a server just to run a gateway, you've traded a free managed service for an ops chore.&lt;/p&gt;

&lt;p&gt;Who should NOT use it? Builders with no infrastructure habit. A gateway is in the critical path of every AI request you serve. Self-host it only if you'd be comfortable self-hosting your database.&lt;/p&gt;

&lt;h2&gt;
  
  
  Portkey
&lt;/h2&gt;

&lt;p&gt;Portkey sells the layer the other two skip. Every request gets logged, traced, and inspectable, with prompt versioning and guardrails on top of the usual routing and fallbacks. The Developer tier is free and records 10,000 requests a month, which genuinely covers a prototype. Production costs $49/month for 100,000 logs, then $9 per additional 100,000. There's an open source gateway too, if you want the routing without the console.&lt;/p&gt;

&lt;p&gt;One ownership note. Portkey belongs to Palo Alto Networks since May 2026, and its pricing above is current under the new owner. Enterprise parents tend to steer products upmarket over time, so treat the indie-friendly tiers as worth enjoying now rather than guaranteed forever.&lt;/p&gt;

&lt;p&gt;That $49 buys answers, not tokens. When your agent burned through $40 overnight and you need to know which loop did it, this is the tool that shows you. We've written about exactly that failure in &lt;a href="https://devtoolpicks.com/blog/ai-agents-runaway-claude-code-bills-overnight-2026" rel="noopener noreferrer"&gt;runaway agent bills&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Who should NOT use it? Anyone whose monthly AI spend is smaller than $49. Paying more for the dashboard than for the tokens is backwards.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Does the Self-Host Math Actually Say?
&lt;/h2&gt;

&lt;p&gt;Enterprise comparisons of these tools argue about SOC 2 and VPC deployment. At indie scale the question is simpler. What does each path cost per month for, say, a side project doing 200,000 requests?&lt;/p&gt;

&lt;p&gt;Cloudflare: $0, or $5 if you want long log retention. LiteLLM: $0 software plus a $5 to $10 VPS you may already have, plus your evenings when it misbehaves. Portkey: $49 plus $9 in log overage. Three real numbers, three different products. The spread isn't about generosity, it's about what you're buying. Zero-ops routing, sovereignty, or visibility.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://devtoolpicks.com/blog/litellm-vs-portkey-vs-cloudflare-ai-gateway-indie-hackers-2026" rel="noopener noreferrer"&gt;View the interactive diagram on devtoolpicks.com&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  The Bottom Line
&lt;/h2&gt;

&lt;p&gt;Start with Cloudflare AI Gateway. It's free, it's managed, and it solves routing, caching, and failover, which is everything most indie projects need from a gateway. Move to LiteLLM when data locality or acquisition-proofing starts to matter and you already have the ops muscle. Add Portkey when your product leans on agents and you're spending real money you can't explain, because at that point the $49 pays for itself in one debugging session.&lt;/p&gt;

&lt;p&gt;And if you're deciding between leaving a hosted router entirely, our &lt;a href="https://devtoolpicks.com/blog/best-vercel-ai-gateway-alternatives-indie-hackers-2026" rel="noopener noreferrer"&gt;Vercel AI Gateway alternatives&lt;/a&gt; and &lt;a href="https://devtoolpicks.com/blog/best-openrouter-alternatives-indie-hackers-2026" rel="noopener noreferrer"&gt;OpenRouter alternatives&lt;/a&gt; posts cover those exits. Model prices themselves are identical through every gateway here, and our &lt;a href="https://devtoolpicks.com/ai-models" rel="noopener noreferrer"&gt;AI models pages&lt;/a&gt; track them daily.&lt;/p&gt;

&lt;p&gt;Running one of these in production? Tell me what broke on X &lt;a class="mentioned-user" href="https://dev.to/devtoolpicks"&gt;@devtoolpicks&lt;/a&gt;.&lt;/p&gt;

</description>
      <category>aitools</category>
      <category>indiehacker</category>
      <category>saastools</category>
    </item>
    <item>
      <title>When to Use a Status Page vs Just Emailing Customers</title>
      <dc:creator>DevToolsPicks</dc:creator>
      <pubDate>Wed, 02 Sep 2026 06:00:10 +0000</pubDate>
      <link>https://dev.to/devtoolpicks/when-to-use-a-status-page-vs-just-emailing-customers-dio</link>
      <guid>https://dev.to/devtoolpicks/when-to-use-a-status-page-vs-just-emailing-customers-dio</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Originally published at &lt;a href="https://devtoolpicks.com/blog/when-to-use-status-page-vs-emailing-customers" rel="noopener noreferrer"&gt;devtoolpicks.com&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;




&lt;p&gt;Your SaaS went down at 2 AM. The question is not whether to tell your customers. It's where. And for most indie hackers, the honest answer is not the status page you set up in an afternoon because real companies have one. It's email.&lt;/p&gt;

&lt;p&gt;Here's the uncomfortable bit. A status page with no visitors isn't communication. It's a prop. We put together a full roundup of &lt;a href="https://devtoolpicks.com/blog/best-status-page-tools-indie-hackers-2026" rel="noopener noreferrer"&gt;status page tools&lt;/a&gt; this week, and the tools are good. The question this post answers is different. When do you actually need one?&lt;/p&gt;

&lt;h2&gt;
  
  
  What Is a Status Page Actually For?
&lt;/h2&gt;

&lt;p&gt;A status page does one job well. It answers "is it down for everyone or just me?" for people who have no direct line to you. Strangers evaluating your product, users who never open your emails, a procurement team checking your uptime history before signing.&lt;/p&gt;

&lt;p&gt;Notice what all of those have in common. Scale and anonymity. A status page is broadcast infrastructure for an audience you can't reach individually.&lt;/p&gt;

&lt;p&gt;Now flip it around. If you have 40 paying customers, you don't have an anonymous audience. You have a list of names. You know which of them are affected. Broadcasting to strangers is solving a problem you don't have yet.&lt;/p&gt;

&lt;h2&gt;
  
  
  When Is a Status Page Just Theater?
&lt;/h2&gt;

&lt;p&gt;Three signs, and most early-stage projects show all of them.&lt;/p&gt;

&lt;p&gt;Nobody visits it. Check the analytics. If your status page gets four hits a month and two are you, it isn't informing anyone. It's decoration.&lt;/p&gt;

&lt;p&gt;You forget to update it. This is the killer. An unattended status page defaults to green. So during your real outage, the page says all systems operational while customers stare at error screens. That's worse than having no page, because now you look dishonest instead of just small. Solo founders mid-incident are debugging, not updating comms tools. Be realistic about which one you'll drop.&lt;/p&gt;

&lt;p&gt;It exists to look bigger than you are. Buyers aren't fooled, and the maintenance debt is real.&lt;/p&gt;

&lt;h2&gt;
  
  
  When Does Email Win?
&lt;/h2&gt;

&lt;p&gt;Under about 100 paying customers, email wins on every axis that matters.&lt;/p&gt;

&lt;p&gt;It's push, not pull. The status page requires customers to wonder whether something's wrong and go check. Email lands in front of them with the answer before most of them noticed.&lt;/p&gt;

&lt;p&gt;It's personal. "We broke something, here's what happened, here's what we're doing" from a founder builds more trust at small scale than any uptime widget. Some of my most loyal users came out of a well-handled outage email.&lt;/p&gt;

&lt;p&gt;And it's free at this size. &lt;a href="https://partners.kit.com/g7ozwj521yig" rel="noopener noreferrer"&gt;Kit&lt;/a&gt; is free up to 10,000 subscribers with unlimited broadcasts, which covers any indie SaaS customer base several times over. &lt;a href="https://www.beehiiv.com?via=hafiz-zeeshan" rel="noopener noreferrer"&gt;Beehiiv&lt;/a&gt; is free to 2,500 subscribers with unlimited sends. Either one holds your customer segment and sends an incident email in five minutes. You'll likely already run one of them for your newsletter anyway.&lt;/p&gt;

&lt;p&gt;The incident email itself is three sentences. What broke. What still works. When you'll update them. Send the fix confirmation later, that second email is where the trust actually gets built.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Does Each Path Cost?
&lt;/h2&gt;

&lt;p&gt;The money is honestly a rounding error either way. &lt;a href="https://instatus.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Instatus&lt;/a&gt; has a free status page with 15 monitors, capped at 200 subscribers. &lt;a href="https://openstatus.dev?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;OpenStatus&lt;/a&gt; is free for one monitor and one page at 10-minute checks, and its Starter plan runs $30/month. Email is $0 at indie scale on either tool above.&lt;/p&gt;

&lt;p&gt;The real cost is attention. A status page is one more thing that must be correct during the worst 40 minutes of your month. An email is written once, when you need it. Pay the attention cost only when the page produces something back, and that requires visitors.&lt;/p&gt;

&lt;h2&gt;
  
  
  How Do You Decide?
&lt;/h2&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://devtoolpicks.com/blog/when-to-use-status-page-vs-emailing-customers" rel="noopener noreferrer"&gt;View the interactive diagram on devtoolpicks.com&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;One nuance the diagram can't hold. The two are not rivals forever. Once you do run a status page, incident email stays in the loop, because the page informs strangers while email reaches the people paying you. Pairing the page with &lt;a href="https://devtoolpicks.com/blog/best-uptime-monitoring-tools-indie-hackers-2026" rel="noopener noreferrer"&gt;uptime monitoring&lt;/a&gt; so it updates itself removes most of the stale-green risk, and decent &lt;a href="https://devtoolpicks.com/blog/best-log-management-tools-indie-hackers-2026" rel="noopener noreferrer"&gt;log management&lt;/a&gt; is what tells you what to write in that first email.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Bottom Line
&lt;/h2&gt;

&lt;p&gt;Under 100 customers, put the afternoon into your incident email template, not a status page. Past that, or the day a B2B buyer asks, stand the page up, wire it to your uptime monitor so it can't lie, and keep emailing the humans who pay you. The status page is for strangers. The email is for customers. Don't confuse the audiences.&lt;/p&gt;

&lt;p&gt;Handled an outage well by email? Tell me how it went on X &lt;a class="mentioned-user" href="https://dev.to/devtoolpicks"&gt;@devtoolpicks&lt;/a&gt;.&lt;/p&gt;

</description>
      <category>saastools</category>
      <category>indiehacker</category>
      <category>devops</category>
    </item>
    <item>
      <title>Best Vercel AI Gateway Alternatives for Indie Hackers in 2026</title>
      <dc:creator>DevToolsPicks</dc:creator>
      <pubDate>Mon, 31 Aug 2026 06:00:09 +0000</pubDate>
      <link>https://dev.to/devtoolpicks/best-vercel-ai-gateway-alternatives-for-indie-hackers-in-2026-i90</link>
      <guid>https://dev.to/devtoolpicks/best-vercel-ai-gateway-alternatives-for-indie-hackers-in-2026-i90</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Originally published at &lt;a href="https://devtoolpicks.com/blog/best-vercel-ai-gateway-alternatives-indie-hackers-2026" rel="noopener noreferrer"&gt;devtoolpicks.com&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;




&lt;p&gt;Vercel's AI Gateway made a strong pitch to indie hackers. Zero markup on tokens, one API for hundreds of models, budgets built in. But it lives inside Vercel's ecosystem, your request logs live in their dashboard, and this August the whole gateway category got shaken when Stripe agreed to buy OpenRouter for over $7 billion. If you're routing real production traffic through a gateway, this is a good moment to ask where that traffic should actually live.&lt;/p&gt;

&lt;p&gt;Here's the short version. The strongest reason to leave Vercel AI Gateway isn't price. It's control: running the gateway inside your own network, keeping logs on your own disk, or escaping a platform you're otherwise trying to leave.&lt;/p&gt;

&lt;h2&gt;
  
  
  Quick Verdict
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Tool&lt;/th&gt;
&lt;th&gt;Best for&lt;/th&gt;
&lt;th&gt;Price&lt;/th&gt;
&lt;th&gt;Rating&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://litellm.ai?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;LiteLLM&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Self-hosting, full control&lt;/td&gt;
&lt;td&gt;Free (OSS)&lt;/td&gt;
&lt;td&gt;9/10&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://developers.cloudflare.com/ai-gateway/?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Cloudflare AI Gateway&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Managed, zero ops&lt;/td&gt;
&lt;td&gt;Free core features&lt;/td&gt;
&lt;td&gt;8.5/10&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://openrouter.ai?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;OpenRouter&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Widest model catalog&lt;/td&gt;
&lt;td&gt;~5.5% fee on credit top-ups&lt;/td&gt;
&lt;td&gt;8/10&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://portkey.ai?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Portkey&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Observability + guardrails&lt;/td&gt;
&lt;td&gt;Free tier, then $49/mo&lt;/td&gt;
&lt;td&gt;7.5/10&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://helicone.ai?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Helicone&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Logging-first teams&lt;/td&gt;
&lt;td&gt;Free to 10K req/mo, then $79/mo&lt;/td&gt;
&lt;td&gt;7/10&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  LiteLLM
&lt;/h2&gt;

&lt;p&gt;LiteLLM is an open source proxy you run yourself. It speaks the OpenAI API format, routes to more than 100 providers, and gives you retries, fallbacks, load balancing, and per-key spend tracking without a bill. Your logs never leave your server. For a Laravel or Node app already running on a VPS, it's one more Docker container.&lt;/p&gt;

&lt;p&gt;The license costs nothing, but the operations don't. You patch it, you monitor it, you babysit its Postgres. That's a real cost in hours even when the invoice reads zero. An enterprise tier with SSO and audit logs exists at custom pricing, which solo builders can ignore.&lt;/p&gt;

&lt;p&gt;Who should NOT use it? Anyone who doesn't want to run infrastructure. If a weekend of downtime while you're away would hurt, a managed gateway is the safer call.&lt;/p&gt;

&lt;h2&gt;
  
  
  Cloudflare AI Gateway
&lt;/h2&gt;

&lt;p&gt;Cloudflare's gateway runs at their edge and its core features cost nothing. Caching, rate limiting, analytics, and automatic fallbacks are free with any Cloudflare account. Log storage is where limits appear. The free Workers plan keeps 100,000 logs total, and the $5/month paid plan raises that to 10 million per gateway. Unified billing, where Cloudflare buys the tokens for you, carries a 5% fee on credit purchases with no markup on inference itself.&lt;/p&gt;

&lt;p&gt;It's the closest like-for-like swap for Vercel's product. Managed, fast, and cheap.&lt;/p&gt;

&lt;p&gt;Who should NOT use it? Builders who want deep request tracing and prompt management. Cloudflare gives you counters and logs, not an observability suite.&lt;/p&gt;

&lt;h2&gt;
  
  
  OpenRouter
&lt;/h2&gt;

&lt;p&gt;OpenRouter is the biggest catalog in the category, with 400+ models behind one endpoint, and inference passes through at provider list price. Its revenue comes from a roughly 5.5% fee (minimum $0.80) when you top up credits by card. Bring your own provider keys and there's no BYOK fee until $25,000 of monthly usage, which no indie project needs to worry about.&lt;/p&gt;

&lt;p&gt;And now the elephant. Stripe is acquiring OpenRouter for over $7 billion. Nothing about the fees has changed yet, and the team says it's business as usual. But companies don't pay $7 billion to leave a product alone, and packaging tends to shift after deals like this, the way &lt;a href="https://devtoolpicks.com/blog/anthropic-splits-claude-subscriptions-agent-sdk-credit-june-2026" rel="noopener noreferrer"&gt;Anthropic reshuffled its Claude subscriptions&lt;/a&gt; this June. We covered the switching math in our &lt;a href="https://devtoolpicks.com/blog/best-openrouter-alternatives-indie-hackers-2026" rel="noopener noreferrer"&gt;OpenRouter alternatives&lt;/a&gt; post.&lt;/p&gt;

&lt;p&gt;Who should NOT use it? Anyone whose compliance story can't absorb a vendor change mid-acquisition, or who only ever calls one provider.&lt;/p&gt;

&lt;h2&gt;
  
  
  Portkey
&lt;/h2&gt;

&lt;p&gt;Portkey is a gateway wrapped in an operations console. Routing, fallbacks, and load balancing come with logs, traces, prompt versioning, and guardrails. The free Developer tier records 10,000 logs a month, enough for a side project. Production costs $49/month for 100,000 logs, then $9 per extra 100,000. There's also an open source gateway you can self-host with the routing features and a basic dashboard.&lt;/p&gt;

&lt;p&gt;You're paying for visibility, not for tokens. That's the right trade when you're debugging why an agent burned $40 overnight, something we've written about in &lt;a href="https://devtoolpicks.com/blog/ai-agents-runaway-claude-code-bills-overnight-2026" rel="noopener noreferrer"&gt;runaway agent bills&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Who should NOT use it? Cost-minimalists. If you just need routing, LiteLLM or Cloudflare does it for free.&lt;/p&gt;

&lt;h2&gt;
  
  
  Helicone
&lt;/h2&gt;

&lt;p&gt;Helicone approaches from the logging side. It's open source, and the hosted Hobby tier is free for 10,000 requests a month with one seat. Pro runs $79/month plus usage. You get request logs, cost dashboards, and session traces that make multi-step agent debugging genuinely easier.&lt;/p&gt;

&lt;p&gt;One caveat. The gateway feature sits in the paid tiers on the hosted plan, so treat the free tier as observability only.&lt;/p&gt;

&lt;p&gt;Who should NOT use it? Anyone picking primarily for routing. Helicone is a magnifying glass first and a router second.&lt;/p&gt;

&lt;h2&gt;
  
  
  How Do You Choose?
&lt;/h2&gt;

&lt;p&gt;Three questions settle it. Do you want to run infrastructure? If yes, LiteLLM, if no, Cloudflare. Do you need many models or one? A wide catalog points to OpenRouter, a single provider barely needs a gateway. And is your real problem cost visibility? Then Portkey or Helicone, because routing alone won't answer where the money went.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://devtoolpicks.com/blog/best-vercel-ai-gateway-alternatives-indie-hackers-2026" rel="noopener noreferrer"&gt;View the interactive diagram on devtoolpicks.com&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  The Bottom Line
&lt;/h2&gt;

&lt;p&gt;For most indie hackers leaving Vercel AI Gateway, Cloudflare AI Gateway is the move. Same managed convenience, free core, no ecosystem strings. Self-hosters with a VPS already running should pick LiteLLM and own the whole stack. Stay on OpenRouter if catalog breadth is why you came, and just keep one eye on what Stripe does with it. Model prices themselves are the same everywhere, and if you're choosing which model to route to, our &lt;a href="https://devtoolpicks.com/ai-models" rel="noopener noreferrer"&gt;AI model comparison pages&lt;/a&gt; track live pricing daily.&lt;/p&gt;

&lt;p&gt;Found a better option? Tell me on X &lt;a class="mentioned-user" href="https://dev.to/devtoolpicks"&gt;@devtoolpicks&lt;/a&gt;.&lt;/p&gt;

</description>
      <category>aitools</category>
      <category>indiehacker</category>
      <category>saastools</category>
    </item>
    <item>
      <title>Best Status Page Tools for Indie Hackers in 2026</title>
      <dc:creator>DevToolsPicks</dc:creator>
      <pubDate>Fri, 28 Aug 2026 06:00:10 +0000</pubDate>
      <link>https://dev.to/devtoolpicks/best-status-page-tools-for-indie-hackers-in-2026-7lb</link>
      <guid>https://dev.to/devtoolpicks/best-status-page-tools-for-indie-hackers-in-2026-7lb</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Originally published at &lt;a href="https://devtoolpicks.com/blog/best-status-page-tools-indie-hackers-2026" rel="noopener noreferrer"&gt;devtoolpicks.com&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;




&lt;p&gt;Your app will go down at some point. That part isn't optional. What's optional is whether your users find out from a professional status page or from a tweet asking if anyone else is seeing errors.&lt;/p&gt;

&lt;p&gt;A public status page is the cheapest trust signal an indie product can buy. It answers "is it down for everyone or just me?" before that email reaches your inbox, it gives paying customers a place to subscribe to incident updates, and it makes a one-person product look like a company that takes uptime seriously. Big customers increasingly ask for one before they sign.&lt;/p&gt;

&lt;p&gt;The verdict upfront: &lt;a href="https://instatus.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Instatus&lt;/a&gt; is the best pick for most indie hackers, and its free plan is good enough that you can stop reading and go set it up. The other five earn their spots in specific situations, and every price below was verified against the vendors' pricing pages this week.&lt;/p&gt;

&lt;h2&gt;
  
  
  Quick Verdict
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Tool&lt;/th&gt;
&lt;th&gt;Best For&lt;/th&gt;
&lt;th&gt;Price&lt;/th&gt;
&lt;th&gt;Rating&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://instatus.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Instatus&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Most indie hackers&lt;/td&gt;
&lt;td&gt;Free, Pro $20/month&lt;/td&gt;
&lt;td&gt;4.5/5&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://betterstack.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Better Stack&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Monitoring and status page in one&lt;/td&gt;
&lt;td&gt;Free, then usage-based&lt;/td&gt;
&lt;td&gt;4.5/5&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://www.openstatus.dev?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;OpenStatus&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Self-hosters&lt;/td&gt;
&lt;td&gt;Free self-hosted, cloud $30/month&lt;/td&gt;
&lt;td&gt;4/5&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://hyperping.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Hyperping&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Polished all-in-one on a budget&lt;/td&gt;
&lt;td&gt;Free, Essentials $29/month&lt;/td&gt;
&lt;td&gt;4/5&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://www.atlassian.com/software/statuspage?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Atlassian Statuspage&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Enterprise expectations&lt;/td&gt;
&lt;td&gt;Free, paid from $29/month&lt;/td&gt;
&lt;td&gt;3.5/5&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="https://cronitor.io?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Cronitor&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;Cron-heavy backends&lt;/td&gt;
&lt;td&gt;Free, $2/monitor/month&lt;/td&gt;
&lt;td&gt;3.5/5&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  Why Is This a Separate Decision From Uptime Monitoring?
&lt;/h2&gt;

&lt;p&gt;Because the audiences are different. Monitoring watches your endpoints and pages you at 3 a.m., and we ranked those tools in our &lt;a href="https://devtoolpicks.com/blog/best-uptime-monitoring-tools-indie-hackers-2026" rel="noopener noreferrer"&gt;uptime monitoring roundup&lt;/a&gt;. A status page faces the other direction. It's the public record your customers check, subscribe to, and judge you by during an incident.&lt;/p&gt;

&lt;p&gt;Most modern tools bundle both, which is convenient and slightly misleading. A bundled product can be great at checks and mediocre at incident communication. So this roundup judges the page, not the pinger.&lt;/p&gt;

&lt;h2&gt;
  
  
  Instatus
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://instatus.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Instatus&lt;/a&gt; does one thing, public status pages, and prices it like someone who wants indie hackers as customers. The free plan includes 15 monitors, 200 email subscribers, 5 team members, and a clean public page with 2-minute checks. That's not a trial. It's a complete setup for a small product.&lt;/p&gt;

&lt;p&gt;Pro at $20/month (less on annual billing) adds a custom domain, 50 monitors, 30-second checks, and 5,000 subscribers. Compare that subscriber count to what Atlassian charges for the same number below and the positioning is obvious. The pages themselves are fast, look modern out of the box, and don't scream "free tier" the way some competitors' branding does.&lt;/p&gt;

&lt;h3&gt;
  
  
  Who should NOT use Instatus?
&lt;/h3&gt;

&lt;p&gt;Teams that want deep monitoring in the same product. Instatus checks your endpoints, but it's a status page first, and you'll still want real alerting elsewhere. And the jump from Pro to Business is steep (reported around $300/month), so a product that outgrows 5,000 subscribers should budget for that cliff before it arrives.&lt;/p&gt;

&lt;h2&gt;
  
  
  Better Stack
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://betterstack.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Better Stack&lt;/a&gt; comes at it from the monitoring side. The free plan includes 10 monitors and one status page with up to 1,000 subscribers, and the paid ladder is usage-based rather than tiered: extra monitors run $25/month per 50, and an additional public status page is $15/month.&lt;/p&gt;

&lt;p&gt;If you read our &lt;a href="https://devtoolpicks.com/blog/best-log-management-tools-indie-hackers-2026" rel="noopener noreferrer"&gt;log management roundup&lt;/a&gt;, you know Better Stack's play is the consolidated observability stack. Uptime checks, incident management, logs, and the public page all live in one place, which for a solo founder is genuinely fewer tabs and fewer invoices.&lt;/p&gt;

&lt;p&gt;The catch is the add-on pricing at the edges. Custom styling for a page is $15/month, password protection $50/month, and white-labeling a startling $250/month per page. The core is generous. The cosmetics are not.&lt;/p&gt;

&lt;h3&gt;
  
  
  Who should NOT use Better Stack?
&lt;/h3&gt;

&lt;p&gt;Anyone who mainly wants a beautiful branded page. The add-ons that make the page fully yours cost more than Instatus's entire Pro plan. Use Better Stack when monitoring is the anchor and the status page is the bonus, not the other way around.&lt;/p&gt;

&lt;h2&gt;
  
  
  OpenStatus
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://www.openstatus.dev?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;OpenStatus&lt;/a&gt; is the open source option, AGPL-3.0 licensed with a Docker image and deployment guides for Docker Compose and Coolify. Self-hosted, it costs whatever your server costs. The hosted cloud has a free Hobby tier (1 monitor, 1 page, 10-minute checks) and a Starter plan at $30/month with 20 monitors and 1-minute checks.&lt;/p&gt;

&lt;p&gt;For the self-host crowd this is the honest pick, and synthetic monitoring from multiple regions is built in rather than bolted on.&lt;/p&gt;

&lt;h3&gt;
  
  
  Who should NOT use OpenStatus?
&lt;/h3&gt;

&lt;p&gt;Anyone who wants zero ops, since the hosted free tier is thin (one monitor) and the $30 Starter costs more than Instatus Pro. And if you do self-host, put it on different infrastructure than your product. A status page that dies with your app is a very quiet status page.&lt;/p&gt;

&lt;h2&gt;
  
  
  Hyperping
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://hyperping.com?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Hyperping&lt;/a&gt; is the polished middle option. The free plan covers 20 monitors with 5-minute checks and a basic status page. Essentials at $29/month (billed annually) brings 30-second checks, 50 monitors, a status page on your custom domain, and on-call escalations with 2 seats included. Pro at $89/month adds browser checks, phone call alerts, and 3 status pages.&lt;/p&gt;

&lt;p&gt;The product feel is the selling point. Pages look great with minimal fiddling, and the monitoring side is credible enough that it can be your only tool, the same all-in-one argument Better Stack makes but with simpler, flat pricing.&lt;/p&gt;

&lt;h3&gt;
  
  
  Who should NOT use Hyperping?
&lt;/h3&gt;

&lt;p&gt;The strictly-free crowd, since the custom domain sits behind the $29 paywall that Instatus undercuts at $20. And large teams needing SAML SSO or white-labeling pay Business prices at $299/month, where the enterprise tools start to compare.&lt;/p&gt;

&lt;h2&gt;
  
  
  Atlassian Statuspage
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://www.atlassian.com/software/statuspage?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Statuspage&lt;/a&gt; invented this category, and enterprise buyers still treat it as the default. The free tier is real: 100 subscribers, 25 components, two team members, and email, Slack, and Teams notifications. For a side project that just needs a credible page, it works.&lt;/p&gt;

&lt;p&gt;The paid ladder is where indie hackers should look away. Hobby is $29/month for 250 subscribers, Startup $99/month for 1,000, and it climbs to $399 and $1,499. Instatus gives you 5,000 subscribers for $20. You're paying for the Atlassian logo and procurement-friendly compliance, which is worth real money to enterprises and nothing to a solo founder.&lt;/p&gt;

&lt;h3&gt;
  
  
  Who should NOT use Statuspage?
&lt;/h3&gt;

&lt;p&gt;Anyone planning to grow a subscriber list on a budget. The per-subscriber economics are the worst here by an order of magnitude. Pick it when a big customer's security questionnaire effectively picks it for you.&lt;/p&gt;

&lt;h2&gt;
  
  
  Cronitor
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://cronitor.io?ref=devtoolpicks.com" rel="noopener noreferrer"&gt;Cronitor&lt;/a&gt; earns its spot for a specific kind of backend, one full of cron jobs and scheduled tasks. Its heartbeat-style monitoring for jobs is the best of this group, and every plan includes a basic status page. The free Hacker plan covers 5 monitors, and the Business plan prices at $2/month per monitor plus $5 per additional user, with branded pages at $25/month and private pages at $50/month.&lt;/p&gt;

&lt;p&gt;If your product's failure mode is "the nightly sync silently didn't run" rather than "the site is down," this is the tool that catches it, and the status page comes along for free.&lt;/p&gt;

&lt;h3&gt;
  
  
  Who should NOT use Cronitor?
&lt;/h3&gt;

&lt;p&gt;Anyone whose main need is the public page. The basic included page is plain, and paying $25/month to brand it puts you above Instatus Pro. Cronitor is a monitoring tool with a status page, not the reverse.&lt;/p&gt;

&lt;h2&gt;
  
  
  How Do You Choose?
&lt;/h2&gt;

&lt;p&gt;Four questions settle it. Does a big customer or compliance checklist force an enterprise vendor? Do you insist on owning the infrastructure? Do you want monitoring and the page in one product? If every answer is no, the default wins.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://devtoolpicks.com/blog/best-status-page-tools-indie-hackers-2026" rel="noopener noreferrer"&gt;View the interactive component on devtoolpicks.com&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Two of the six didn't make the chart, on purpose. Hyperping sits between Instatus and Better Stack (pick it when page polish and monitoring both matter and $29/month is fine), and Cronitor is the answer to a different question, scheduled jobs. The chart routes the common cases. This is the same keep-it-boring logic we applied to &lt;a href="https://devtoolpicks.com/blog/best-feature-flag-tools-indie-hackers-2026" rel="noopener noreferrer"&gt;feature flags&lt;/a&gt;: the tool that quietly does the one job usually beats the platform.&lt;/p&gt;

&lt;h2&gt;
  
  
  Which One Wins?
&lt;/h2&gt;

&lt;p&gt;Instatus, for most indie hackers. The free plan covers a small product completely, $20/month buys a custom domain and room for 5,000 subscribers, and it does the actual job (communicating during an incident) as well as pages costing twenty times more.&lt;/p&gt;

&lt;p&gt;Better Stack is the strong second when you'd rather run one observability tool than three. OpenStatus takes the self-host crowd. Statuspage takes the enterprise checkbox. And whichever you pick, set it up before the outage. A status page created during an incident is a receipt for panic, and one that was already there is proof you run a real operation.&lt;/p&gt;

&lt;p&gt;Found a better option? Let me know on Twitter @hafizdev.&lt;/p&gt;

</description>
      <category>observability</category>
      <category>indiehacker</category>
      <category>developertools</category>
      <category>saastools</category>
    </item>
  </channel>
</rss>
