Vibe coding is everywhere. So are the credit meters.
Ever read the spending threads on r/lovable? This one has people burning through hundreds of credits while still trying to get their apps working. Other people are happy with what they shipped. But the question stuck with me: if I already have a coding agent, why do I need another platform's AI credits?
Lovable bundles building and cloud services into its platform. I wanted to keep using my own agent and have somewhere to deploy the result.
So I built drobek, an open-source hosting platform for small web apps. Bring Claude Code, Cursor, or Codex, connect over MCP, and publish what you build. drobek doesn't sell you AI tokens. Your model usage stays with your agent's provider. Hosting still costs money, whether you use a hosted service or run your own server.
The source is on GitHub, under AGPL-3.0. There is a hosted version at drobek.app, and you can self-host it.
At work, almost everyone vibecodes now. People build landing pages, internal tools, and reports for colleagues. The next question is usually where to put them, who gets access, and what to do with the API keys. That's the part I wanted drobek to handle.
The agent connects to drobek over MCP, creates an app, and sends the source files. drobek compiles them and returns errors the agent can fix. A successful build gets a preview URL. You try it, ask for changes, and publish when you're ready. Each successful build is a numbered version, so you can also publish an older one.
The app's JavaScript runs in the browser. drobek compiles and serves it; it doesn't execute agent-written application code on the server. Backend features come from platform modules: login, data storage, forms, file uploads, owner notifications, and API proxying.
That gives me a clearer security boundary for these small apps. Each app has its own origin. Owners enter API secrets in the dashboard, and the relevant module uses them on the server. The agent doesn't need the secret values. Data access rules belong in the backend module, where hiding a button in the frontend can't bypass them. You still need to configure those rules and review what you publish.
Here's a small example from the public gallery: a Pokédex with search, stats, and a live log of requests through drobek's proxy module. PokéAPI is public, so this demo doesn't need a secret API key.
This is the size of app I have in mind: something useful enough to share, without maintaining a custom backend for every little tool. drobek targets browser apps; it isn't a place to run arbitrary server code or background workers. Also, preview and production share an app's backend data. Rolling back the code doesn't roll back the database.
I'll follow up with the technical details, copying and sharing apps, self-hosting, and turning an artifact into something people can keep using. For now, browse the gallery or have a look at the repo.
Where do the little apps your colleagues vibe code end up today?
Top comments (0)