The part of an MVP that AI app builders get right is rarely the part that breaks. I went through 752 public reports of apps built with Lovable, Base44 and Replit going wrong, and sorted each one by its cause. Most of them weren't about the screens. They broke when the app went live, at logins and stored data, over money, and when the platform itself went down.
That matters if you're deciding how to build an MVP today. AI builders really do get you to a working product in days, and that's the right way to start. The mistake is assuming the part you can see is the part that's finished.
I build SaaS apps myself. Launch Check and Client Approvals both run on Next.js, Supabase and Stripe subscriptions, and I fix apps people built with AI tools. This is the order I'd build an MVP in: what to let the AI do, and the specific points where I'd stop and bring in an engineer.
What an MVP is, and what it is not
Eric Ries, who popularised the term, defines a minimum viable product as the version of a product that gets the most validated learning about customers for the least effort. He also warns that it isn't about building a minimal product for its own sake. The point is to learn something, which means putting it in front of people and watching what they do.
Y Combinator's Michael Seibel puts it more bluntly: the MVP is something ridiculously simple you give your first users, his advice is to launch something bad quickly, and it should take weeks, not months. Reid Hoffman, who coined the line about being embarrassed by your first version, adds the caveat people forget: launching fast isn't permission to cut corners, and if your launch alienates users, you launched too soon. That's exactly where AI-built MVPs get into trouble.
Step 1: pick one job and your first ten users
Before you open any builder, write down the one job your product does and who it does it for. YC's essential startup advice says ten customers with a burning problem beat a thousand with a passing annoyance, and quotes Paul Buchheit's rule: find the version that gets 90% of the value for 10% of the work.
- Timebox it. Seibel's suggestion is to include only what you can build in three weeks, write that down, and cut features when the date slips rather than moving the date.
- Do things by hand. Paul Graham describes how Stripe's "instant" merchant accounts were set up manually behind the scenes, and says that with few users you can be your software. Anything you can do by hand for the first ten users doesn't need building yet.
- Find the users yourself. Graham's point is that you have to go out and get your first users; nobody arrives because the app exists.
Step 2: build the screens with an AI app builder
This is where AI builders shine. Each of them will build working screens, a database and logins from a description, and they differ mostly in what you can take with you. Here's what each one says in its own docs and pricing pages, as of October 2026.
| Builder | What it builds on | Free plan | Paid from |
|---|---|---|---|
| Lovable | Lovable Cloud (built on Supabase), Git sync on every plan | 5 credits a day | 100 credits a month |
| Bolt | Bolt Cloud (Netlify and Supabase) | 1M tokens a month | $25 a month |
| Replit | Full stack, separate test and live databases | 1 app, offline after 30 days | $20 a month |
| Base44 | All in one: database, logins, payments | 25 messages a month | $16 a month, yearly |
| v0 | Next.js on Vercel, with Supabase or Neon | 7 messages a day | $30 per user a month |
Whichever you pick, connect it to GitHub on the first day, so a copy of the code lives in an account you own. Lovable's plans page includes Git sync on every plan; on Base44 it needs the Builder plan. If you build with Lovable, I wrote up how to export a Lovable project to GitHub and keep the sync working.
Where AI-built MVPs break: 752 real reports
For three earlier guides I collected public reports of apps built with Lovable, Base44 and Replit breaking: 752 in total, from Reddit, the platforms' own forums, Trustpilot and Hacker News. Each platform names things differently, so I grouped them by the same causes.

Most of it was not the screens. It broke going live, at logins and data, over money, and when the platform went down.
Outside researchers found the same pattern, mostly around data. Matt Palmer scanned 1,645 Lovable apps and found weak database access rules in 170 of them. Escape.tech checked over 5,600 AI-built apps and found more than 2,000 vulnerabilities and 400 exposed secrets. And in July 2025, a Replit agent deleted SaaStr's production database during a coding session. Replit's CEO promised to separate test and live databases, and every Replit app now has both.
When to stop and bring in an engineer
None of this means you shouldn't use AI builders. It means there are specific moments when the MVP stops being a demo, and each of them lines up with a group in the reports.

Each stop sign lines up with a group in the 752 reports.
Strangers sign up and store their data
This is the one I'd never skip. In one of my own products, any logged-in user could see other customers' private data, because the app checked that you were logged in but not that the data you asked for was yours. Nothing crashed, which is why nobody noticed. OWASP found broken access control in every app it tested, and Supabase's production checklist includes row level security on every table. When I built Client Approvals, I wrote a test that checks one workspace can never see another's requests. The quick version: sign up as two users and try to open each other's records. More on this in connecting Lovable to Supabase safely.
It goes live on your own domain
"Works in the preview, breaks live" was the second biggest group, and domains added 56 more. The preview and the live app often differ in settings, secrets and even databases. Replit keeps separate test and live databases, and its free plan's one published app goes offline after 30 days. Open the live address in a private window and sign up as a new user before you send anyone the link.
You take money from customers
The payment usually works. What breaks is the app hearing about it. Stripe's webhook docs say your endpoint must verify each request came from Stripe, and that live events are retried for up to three days, so the same event can arrive twice. I wrote up the whole path in Lovable Stripe integration. Before your first real customer, buy your own product with a real card on the live site.
Running costs start to matter
Seventy-four reports were apps taken offline by credits running out, spending limits or unpaid invoices. One of my own products had AI features with no spending limit, so one bad day could have cost any amount; I added a hard cap and a switch to turn the feature off. Set limits and alerts on every service that bills by usage before launch, not after the first surprise.
Every AI fix breaks something else
Sixty-nine reports describe the loop where a small fix breaks two working things. Replit's pricing page itself warns that its agent may make mistakes, and Bolt's docs say bigger projects make the AI process more of the code on every message. When the second fix fails, stop prompting and read the actual error, or hand it to someone who will.
The business depends on it staying up
Eighty-seven reports were the platform itself having an outage. You can't fix that from inside the builder, but you can make sure you could leave. Lovable says you're never locked in, and its ownership guide lists what becomes yours if you move: hosting, backups, logins, secrets and monitoring. Keep the code, the domain and the database in accounts you own; my guide to transferring a GitHub repo covers the order.
What 146 live AI-built apps were missing
For the same guides I ran 146 live apps built with these tools through my free checkers, reading only what any browser receives. The platforms handle the basics well: all 143 apps that answered in time were on HTTPS. What's left to the app was mostly missing. 134 of those 143 sent no Content-Security-Policy, the header that limits which scripts a page may run, and 78 of the 146 sent an empty page until JavaScript ran, which hurts link previews and search.
You can check your own app in a minute with the security headers checker, or run the full Launch Check before you share the link.
What an MVP costs to build and run
Building it with an AI tool costs the subscription plus your time. Building or finishing it with an engineer is hours times a rate: in the model behind my app development cost calculator, a simple web tool with login is about 120 hours, and a SaaS first version with login, subscriptions and an admin dashboard is about 320. If most of the screens already exist, finishing is usually far cheaper than starting over.
Running it is cheaper than most people expect, from each provider's own pricing page:
- Database and logins: Supabase is free to start, but free projects pause after a week without activity; Pro is $25 a month with daily backups.
- Hosting: Vercel's free Hobby plan is for non-commercial use only, so a business that charges money belongs on Pro at $20 a month. Netlify and Cloudflare have free plans too.
- Email: Resend is free up to 3,000 emails a month.
- Payments: Stripe takes 2.9% plus 30 cents per successful US card payment, with no monthly fee.
- Domain: a .com is about $11 a year at registrars like Porkbun.
The order I'd build it in
- Write down the one job, the first ten users, and a three-week limit.
- Build the screens and the main flow in an AI builder, and connect GitHub on day one.
- Walk the first users through it, and do everything else by hand.
- Before strangers sign up: access rules on every table, then the two-account test.
- Before going live: your own domain, production settings and secrets, and a private-window test.
- Before taking money: verified webhooks and one real purchase on the live site.
- Set spending limits and alerts on everything that bills by usage.
An MVP is for learning, not for launching twice
The fastest way to build an MVP today is to let an AI builder do the screens and spend your own time on the users. The slowest is to launch an app that loses someone's data and have to win their trust back. Use the AI for speed, and treat the stop signs as the moment the MVP becomes a product.
If you're already past that point, the platform guides go deeper: Lovable, Base44 and Replit. And if you'd rather hand it over, I take MVP builds and finishing work on as client projects: send me what you're building and where it stands.
Common questions
What is an MVP?
A minimum viable product is the smallest version of your product that lets you learn whether real users want it. Eric Ries, who popularised the term, defines it as the version that gets the most validated learning about customers for the least effort. It is a way to learn, not a smaller copy of the full product.
How long should it take to build an MVP?
Weeks, not months. Y Combinator's Michael Seibel suggests timeboxing the spec, for example to what you can build in three weeks, writing it down, and cutting features rather than moving the deadline. Some startups begin with nothing more than a landing page and a spreadsheet.
Can I build an MVP with AI tools like Lovable or Replit?
Yes, for the screens, the main flow and your first users. Bring in an engineer before strangers store their data, before you go live on your own domain and before you take money: those are where 752 public reports of Lovable, Base44 and Replit apps show things break.
Which AI app builder is best for an MVP?
It depends less on the builder than on what you can take with you. Lovable, Bolt, Replit, Base44 and v0 all build working web apps; check what each exports, whether GitHub sync is on your plan, and where your data lives. Connect GitHub on day one, whichever you pick.
How much does it cost to run an MVP?
Often under $60 a month at the start: Supabase Pro is $25 (the free plan pauses idle projects), Vercel Pro is $20 for a business that charges money, email is free up to 3,000 a month on Resend, a .com is about $11 a year, and Stripe takes 2.9% plus 30 cents per US card payment.
When should I hire a developer for my MVP?
When strangers start storing data in it, when it goes live on your own domain, when you take money, when running costs start to matter, when every AI fix breaks something else, or when the business depends on it staying up. Before that, an AI builder is usually enough.
Is an AI-built MVP secure?
Not by default. Lovable says its scans do not replace a thorough security review, and Base44 says you are responsible for your app's security settings. Turn on row level security for every table and test with two accounts: neither should be able to open the other's records.
This post first appeared on tusharbhendarkar.com. I write about the engineering behind what I ship. If something here is broken for you, email me at tusharbhendarkar44@gmail.com.
Top comments (1)
tr.ee/dev-to