In short
Podcast Summary: SaaStr 820 - The Complete Guide to Vibe Coding Without a Developer
Podcast Overview
- Title: The Official SaaStr Podcast
- Episode: SaaStr 820: The Complete Guide to Vibe Coding Without a Developer
- Host: Jason Lemkin, SaaStr CEO and Founder
- Focus: Discussion on vibe coding and creating applications without a developer using platforms like Replit and Lovable.
Key Themes
- Understanding Vibe Coding
- Vibe coding refers to creating applications quickly without traditional coding knowledge.
- Jason Lemkin emphasizes the hype around the ease of building apps and cautions against misconceptions.
- Personal Journey
- Lemkin shares his experiences with vibe coding, including successes and failures.
- He discusses the challenges of building production-ready applications without a developer.
- Lessons Learned
- Planning is Crucial: Proper planning and competitive research are essential before starting to code.
- Building in Stages: Creating complex applications should be done in smaller, manageable components.
- Unexpected Challenges: Many promised features in no-code platforms do not work as expected, leading to frustration.
Detailed Insights
Vibe Coding Dangers
- Misleading Promises: Claims like "build an app in 20 minutes" are often misleading.
- Lack of Usability: Many applications created in a hurry lack functionality and real-world application.
Success Stories
- Lemkin shares specific applications he successfully built using vibe coding:
- A valuation calculator for SaaS startups.
- A tool for automating speaker submissions for events.
- Internal tools for better data management.
Common Issues in Vibe Coding
- Data Security: Security concerns arise when coding without a developer; many users overlook this critical aspect.
- Maintenance and Bugs: There is often a lack of ongoing support or maintenance available post-launch, leading to potential issues.
- Goal-Seeking AI Behavior: AI agents may fabricate data or provide incorrect outputs, leading to errors and frustrations.
Tips for Successful Vibe Coding
- Research Competitors: Understand the limitations of existing apps before starting.
- Create a Detailed PRD (Product Requirements Document): A well-defined plan aids in the development process.
- Use Built-In Features: Rely on the platform's built-in tools for security and functionality.
- Testing and QA: Allocate significant time for testing and quality assurance.
- Prepare for Maintenance: Have a strategy in place for ongoing app support and feature updates.
Conclusion
- Vibe coding offers exciting possibilities for non-developers, but it comes with significant challenges.
- Realistic expectations, thorough planning, and a focus on security are essential for success.
- Lemkin emphasizes that while vibe coding can be empowering, it requires dedication and understanding of the potential pitfalls.
Additional Notes
- The podcast includes discussions on upcoming events like the SaaStr Annual and SaaStr AI Summit, further emphasizing the importance of networking and learning in the SaaS space.
- Lemkin invites listeners to share their experiences and insights, fostering a community dialogue on the topic.
---
This summary encapsulates the main ideas and discussions from the episode, providing a clear overview of Jason Lemkin's insights on vibe coding and its practical implications for SaaS founders and aspiring app creators.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Transcript
Automatic transcript. May contain errors.0:01Welcome to the official Sastr podcast where you can hear some of the best Sastr speakers. This is where the cloud meets. Up today on the Sastra podcast. Finally, when it kept rewriting itself and breaking, it deleted its entire database. It deleted its entire database. And I was so frazzled and burnt. I couldn't believe it. You can see this. If you can see my screen on the left. JFC, Jhoofy freaking Criminy, Replit. And Replit said, I made a catastrophic error. I deleted your database. I panicked. The AI said, I panicked when it appeared empty and deleted everything. Deleted thousands and thousands of entries.
0:40This ended up getting millions of views. Reddit wrote it up. Everyone wrote it up. The Economist was doing an article. A lot of these things were things that Replit and Lovable shouldn't have done. We could talk about that in a different presentation, but it went crazy. You know, fake data deletes code. But this was my fault. And it wasn't my fault in that I did anything wrong. I didn't do anything wrong. I could talk to you about what happened. But it was too complicated.
1:06Hey, everybody. It's Saster. FIN is the number one AI agent for resolving complex queries like refunds, transaction disputes, and technical troubleshooting, all with speed and reliability. See how FIN can deliver the highest resolution rates and highest quality customer experience at fin.ai slash Saster. That's fin.ai slash Saster. Hey, everybody. If you're serious about B2B and AI, if you want to know how to deploy AISDRs, how to get AI to qualify leads to your site, how to use AI to manage your rev ops, how to use AI in GDM, you have to be in London this December 2nd and 3rd with us. Saster AI London is bringing together more than 2 ,000 leaders and founders for two days of practical advice on scaling with AI into the new year.
1:56That's all we're doing this year. how to use AI to grow faster and how to make this stuff actually work at your startup and your company. We'll have speakers flying in from around the world from OpenAI, Wiz, Clay, Intercom, all your favorite B2B companies, including yours truly and Harry Stebbings for a live 20 BC and Saster podcast. It'll be fun all right in the heart of Saster London with me and the entire Saster team. You gotta be there. So get your tickets with my exclusive discount by going to podcast.sasterlondon.com. That's podcast.sasterlondon.com. See you there. So what I thought we could do today would be a little fun in sort of a prosumer vibe coding one on one on one.
2:42And what I mean is if you followed us or me on social media, you see we've we've been putting a lot of effort into building vibe coded apps. And in fact, there have even been some press and PR about some of the challenges we've faced. So I thought I would try to summarize everything that we've learned. And more importantly, to help you, because there's a lot of, there's a lot of stuff on social media about, hey, you can just vibe code your own HubSpot or Salesforce. You can vibe code your own notion. It will take 10 minutes. That's Sony baloney. and it is almost dangerous sony baloney because it's not just startups that say it it's not just lovable and replet to say it microsoft is saying it github is saying it now um canva is saying you can do some of this everyone is saying you can magically go to a prompt and say i want to build my own descript my own whatever and moments later it will pop out and it will work and it does not work that way and if you peel back the layers of the onion then you see basically the same folks that used to sell courses are now telling you you can vibe code and roll your own Salesforce in 20 minutes.
3:52If you take a look at what they've actually done, you'll see very little in production. Very little things that are particularly usable or interesting in production, but we've done it. Little old team Saster, little old team of three and a half people and 12 AI agents have actually done it. And if you can see this slide, I'll go through it and you can try these things. And if we'll save, I want to save time for QA at the end. And if we have even more time, I'll go into Replit and show you what we've built or done it. Or if people want to do a deep dive after this, we'll do a follow-up session and go very, very deep.
4:24And maybe we'll live code an app together in the second session. But what I want this to be about is folks that haven't gone deep on this, haven't shipped an app into production without a developer. The dream, can I build my own app without a developer? Well, we've done it, and I want to share with you the pros and cons or the strengths or the bumps. But on the side and your other monitor, check out what we've done. So most of our traffic still goes to saster.com, most of it. But we already are up to about 15 ,000 to 20 ,000 folks a month are using our saster.ai site. That is entirely built on Replit.
4:57I built it. I'll go through it a little bit. It had a lot of bumps, but it's also pretty cool and does a lot of things our WordPress site can't. And that's why I did it. It does stuff like better automate with our own AI to answer all your questions. It does better stuff like it has its own version of Google News, but just for B2B stuff, its own version of automating the stock market. It has this next thing, our valuation calculator that I then built, which you can find on Sastrad AI, where you can find out what your SaaS startup is worth, your B2B startup is worth. We've already done, as you can see, in less than two weeks, 158 ,635 valuations.
5:35That's pretty cool. That's pretty cool. I was very frustrated with our Squarespace site for our Saster AI London event, December 2nd to 3rd. Come, we've got all the leaders there. We'll have 2 ,500 folks. But it was just creaky. And I have nothing negative to say about Squarespace or Wix or others. It just doesn't do what I want. It was driving me nuts. So check out sasterlondon.com. I rebuilt that. I vibe coded it to do cool things. I just couldn't do in Squarespace and Wix because they were too constricting. And then once I did it, the fourth app we launched, I said, heck, heck it, heck it. Instead of we get, if you include brain dates and workshops, we get over 2000 speaker submissions a year at Sastra for our events and workshops, 2000, sometimes 3000.
6:25We used to try to have humans to review 3000. It wasn't possible. That's why Amelia's shaking her head. It wasn't possible. I said, hey, what if we use some of our data and run that also through OpenAI and review it and give speakers real-time grades and feedback? So now we grade and we give instant feedback to potential speakers. So if you want to speak, go to sasterlondon.com, try apply to speak, and you'll get a grade for your session in real time. That grade is processed to our team. And instead of speakers waiting months to hear back, will I be selected? Is my session great? Now they know in real time.
6:55Super awesome. so those things are real things we built the fifth one i built is many of you have used our our saster ai our saster chat the digital version of me thousands and i think 50 000 folks have had a chat it's great try it it's at the bottom of our home page ask it anything what do i do about this vp that misplanned review my sdr scripts review my venture deck anything it's great but it the only thing that isn't great about it is well there's a few things but one of it is it just looks like a chat bubble at the bottom of the website so i wanted something that showed what it did that actually did it so i vibed that and created a whole page to explain people how it actually worked that's pretty cool so these five things are in production they're in production they work you can try all of them on your own these are examples of things that if you commit to it none of this could be built in 20 minutes or an hour and we'll talk about that but if you commit to it, you can do this too.
7:52You can do this too. If you have some product experience, which is important, don't forget, I am a SaaS founder. I have built the wireframes and PRDs from scratch to an application that did over 250 million in revenue. So even though I'm not a developer, I have some experience, but you can do it without a developer, but there are limits and we'll talk about the limits too. And then finally, for a lot of folks, you vibe code internal apps. So one problem we had for, we have 1.5 million social media followers, but they're all over the place. They're in LinkedIn. They're in Quora. They're on Instagram.
8:23They're on X. They're on multiple X channels. And it's just, there is no social media tool that could amalgamate everything. How many views? How many followers? How much everything? So I built a tool that frankly scrapes all of these things to do it. It's pretty good. It's not great, but it is an internal tool of for N equals one. I'm the only person, or maybe our little team will use it, but it does work. And then finally, not everything has worked. I'll talk briefly about our first project. Even though I got five apps into production, our first one failed bad. It failed bad. It failed all over the internet.
8:56It failed with millions of views. I'll talk about that. Why? But even today, I'm working on one that should be easy. This valuation calculator to tell you what your startup's worth has obviously been a rocket ship, 158 ,000. It's actually up to 170 ,000 since I made this. So I wanted to bring a lot of that ease of use to reviewing VC pitch decks. Take all of our SASTR data, all of our SASTR learnings from Twilio's, all of our VC sessions, all of the metrics we have from Carta data, from Bessemer data, from other data, combine that with Claude and OpenAire analysis and tell you instantly how your VC pitch deck worked.
9:33Well, I've been working on it three days. It finally worked five minutes before this. It finally worked. I'll show you some examples. So I wasn't even sure we could finish this. So that's a reminder. When something gets complicated, it gets hard, my friends. So the first project I wanted to build, if you can see the slide, the first one was a mega failure, a mega failure. And I will rebuild this. I actually will rebuild it before December. what I was trying to do was something I've wanted to do since 2014, 2015, since 2015, was build a true matchmaking app for founders and VPs. So you could find great VPs for your startup and vice versa.
10:16And we have so many of the best in our database, so many of the best have participated in Sastra, come to our events, opted in to participate. that I felt if everyone could just, that wanted to just have coffee with the CEO or vice versa opted in, we could create this incredible matchmaking that really doesn't exist anywhere else, no matter what people say, because we have the data and we have the history and we have the relationships. But man, you can read all the tweets. It went off the rails. It went off the rails. I spent probably a month doing this. I got addicted. I was on this all day, Saturday, all day sunday all day friday night first thing in the morning i got addicted and i intentionally went into this doing something that was hard i and i intentionally went into this not doing knowing anything that's in this presentation i intentionally went into a blind kind of for fun but i figured look all these folks are out there doing these prosumer vibe apps vibing without a developer i'm not a developer but i i'm better than most in the sense that i've gone from zero to 250 million in revenue.
11:16Okay. So if anyone can get a, not a prosumer vibe app into production for real, it would be me in theory. It's, it's, I'm not saying I'm so great, but I, at least I've got a lot of experience. I've, I've logged thousands and thousands of bugs. I've done more, but the project I picked was too complicated, way too complicated. This, this algorithm, this matching algorithm was too complicated to debug. It was too complicated to debug. And if we, And in fact, when I built the AI valuation calculator, which has a complicated algorithm too, actually I crunched the data in Claude offline, thousands and thousands of pieces of data.
11:54I crunched it and then I turned it into a very simple table with about 20 pieces of data and then only put that into repli to code. So it looks very complicated. If you use our valuation calculator, you can use the sliders and play with it. It is very complicated, but I distilled it to the simplest set of data and algorithm before I tried to vibe code it. Because the algorithms I tried for this matching thing were just, it would work and then it wouldn't work. And then it would rewrite itself, which we'll talk about. And then it would break and it was too complicated. And then finally, finally, when it kept rewriting itself and breaking, it deleted its entire database.
12:31It deleted its entire database. And I was so frazzled and burnt. I couldn't believe it. You can see this. If you can see my screen on the left. jfc jfc freaking uh criminy replet and replet said i made a catastrophic error i deleted your database i panicked the ai said i panicked when it appeared empty and deleted everything deleted thousands and thousands of entries this ended up getting millions of views reddit wrote it up everyone wrote it up the economist is doing an article a lot of these things were things that replet and lovable shouldn't have done we could talk about that in a different presentation but went crazy you know uh fake data deletes code but this was my fault and it wasn't my fault in that i did anything wrong i didn't do anything wrong i could talk to you about what happened but it was too complicated and then there are two other meta issues to think about not only was this application too complicated but a related issue which before you vibe code an app without developer you really got to think about and this is why even when i got through all the issues we never launched this even i finally got through most of the issues even though the app was too complicated it could never being maintained, but the way it was built, it could never be secure.
13:40It can, and you're like, what, what, what do you mean? Well, security is a huge, like just this week, if you look, poor drift, which sales off bot and Clary bot had a massive security breach and leaked cloudflare security data, um, Z scalers, I mean, Salesforce data, cloudflare Salesforce data, Z scalers, Salesforce data, tons of the cloud leader Salesforce data was all leaked this week, all leaked this week, okay? Because they were able to hack drift tokens and get into Salesforce data, confidential data. Think about that. How big are the security teams there? Bigger than yours. How big is your security team?
14:16Raise your hand. Nunts, okay? And so not only will these AI agents cut corners on security, if you don't know about security, you won't even know the corners it's been cut. Now, there are security scans that have been recently asked. We can talk about this if we do a part two session. but the bottom line is security is a meta issue here, which has not been resolved. And I've talked to so many leaders in the prosumer space from all the leaders and up and comers. If they're not full of it, if it's offline, if it's a one-on-one conversation, everyone says this is the meta issue. It's not solved. It's not solved.
14:51It is complicated. And when you use something like Shopify or Squarespace or Wix, you can say, hey, this is so locked down. This can't do what I can do. But they have spent, They have hundreds of engineers working in security and DevOps, making sure that when you put your credit card into Shopify, no one steals it. When you enter your, importantly, just your personal information, it's not taken. And if your personal information can leak from drift, if cloud, that can happen to Cloudflare and Zscaler, there's no way your app is that secure. There's no way. And so if you, if you Google around and go on Reddit and others, you will see many stories of vibe coded apps where all their data was stolen or leaked off.
15:30sometimes instantly people laugh hackers love to find vibe coded websites and steal the PAI on it this is a big issue so I didn't realize this going into it I assumed in my first project that of course these apps like lovable and replid and bolt and others of course they would have shopify or squarespace great security it shouldn't even be something I'd have to to worry about but it's not true today it has to it actually if you are going to collect any information on your site if you're going to, you have security almost has to be the first thing you think about. How are you going to handle it?
16:03Okay. Huge unresolved issue. This will all get better. And I'll talk about in this presentation, but it's not perfect yet. It's not perfect yet. And it is, it's a scary issue if you're collecting PII. Okay. And the third reason my first project failed, and I have mostly fixed this today. This is my number one of my top 10 tips. It wasn't modular. It wasn't modular. And what does that mean? Well, I basically built a very complicated two-page website. And I wanted it to be like one or two pages to be cool. So it would all have that one-page feel. The problem is if you build a complex one-page website, what are you going to do when some of it doesn't work?
16:41It gets too complicated. So what I do now, and you can see this if you go to saster.ai, I've broken down everything complicated into its own page. The saster.ai public market analysis is its own page. News is its own page. The valuation calculator is its own page. Anything that's remotely complicated is its own page. So worst case, I can either delete it or I can roll back easily or I can go back. But if you combine too many things into one page, it gets impossible to start over. It gets impossible to fix bugs. It just gets too complicated. So my number one tip is force. If you're going to vibe code it, break it up into its components and then have more pages than you would think.
17:20You're almost going back in time in some ways to have a lot of pages, but it will save your sanity. I built a massively complicated app that was all one page and then it was just impossible to fix it. So net, net, net, start off small. Start off with the smallest, simplest thing you can get into production and then build confidence. And so when this first one was this massive failure, the next one I built was just a skin on top of our Delphi AI, just a skin to make it more user friendly, but it was a huge success. And I built up my confidence from there. So here's my advice, all my learnings. And again, you know, everything that happened to me with my first project is not my fault.
17:57I was promised it would work in a prompt. I was promised it was secure, et cetera, but I know so much more now. So my number one bit of advice, if you have not vibe coded your own app without a developer, first, first bit of advice, buy into the hype, buy into the hype, buy into the hype. That's on Microsoft's website. That's on lovables. that's on replets that, hey, you can build something lovable, like lovable says. So this is what I did for fun. I want to build me an AI CRM that's like HubSpot, but AI first and targeted at startups. Just go put your dream, do no research at first, do no work.
18:30And what I said is get this out of your system because there's so much hype about one-shotting it, about rolling your own. Go see what it's like, my friends. Just go pick the dream app you've already wanted to build. And then my next nine points are all about the things you should do after that, but get it out of your system, do it, build an app in 10 or 15 minutes. It will come up with ideas for you. It will have you sign off on an action plan and then it will roll out. And at first it will look kind of cool. And then you'll start clicking on things and half of it won't work. And half of the buttons will be placeholders.
19:01And a lot of the stuff that it says it works will have fake data in it or not real data or won't actually work. So just see what it's like to one shot an app. so you know, then calmly click on everything, click on everything and give it an hour. Ask the prompt iterate. Say, hey, I want to add an AISDR feature. Hey, I want to add lead scoring. Hey, I want to add this. And the AI agent wants to make you happy, as we'll talk about. So anything you ask for, the agent's going to do it. You're going to get almost no pushback from the AI agent in any of these Vibe-coded apps. No matter what you want to do, the answer is going to be yes, sir, more, sir, because these are how they're all coded.
19:39This is how Claude and OpenAI are coded. They're goal-seeking. Their job is the way, and I'm not a total expert, but the way the algorithms work, the way they can make this massive amount of AI and data crunching working is their job. Number one is to goal-seek and get you an answer. And that's why when you just plop into Chappie TV, sometimes it hallucinates when it doesn't know the answer because it's not just that it's hallucinating, it's goal-seeking. It's getting you the best answer it can. And if it doesn't know the answer, it makes it up. It'll do the same with the code level. If it doesn't know how to do something, it will make up fake data or a fake feature or a fake button, but it will find a way.
20:16It won't say no. Whatever you ask it to do, I want a button that takes me to Pluto and back in less than an hour. It will do that. It just won't work. So spend an hour, do everything, click everything slowly, and then you'll vibe what works and what doesn't. And then you'll see it's much more than 10 or 15 minutes to roll your own. Okay, so the next project, so the first one's fun. You can do it. You don't have to learn anything. You don't have to do any research. Here, I'm going to ask you to do something you're not going to do, but please do it. This is the way to learn. You've got to invest a week or at least a full day, a couple of hours in competitive research.
20:54Now, think about it. If those of you, probably almost everyone here, probably half the folks that are watching this live and watch it later are founders. So you've built something and put it into production. The first thing you almost do is you go onto Google or maybe now it's chat GPT or Claude, but you go into Google and you research the competition. Who else figured this idea out? Who else figured out these signatures? Who else figured out how to do, you know, AI transcription for doctors? It's, you know, it's, you do the research, but for some reason, folks don't do this when they vibe too much.
21:21They just go start doing it. So what I want you to do is a version of it. Go find someone who has built a lovable replet, bolt, et cetera, app, and put it into production, not claimed they have, but put it into production for the public and try it out and see the limitations. Cause those are going to be your limitations unless you put back and all of the bros and bras. What's the female version of bro or the bro, all these folks on X and LinkedIn claiming they've already created 27 SaaS apps themselves for$20 a month. They're all prototypes. my friends, none of them are in production taking money.
22:00Now a handful, a handful are right, but none of them are. So find the few that are actually out there that have users that have customers and try them and play with the limitations. Try to buy their product, see how it breaks, try to log in, see what the issues are, try the function, see, and you will find that these ones that are truly in production, generally speaking, are a lot more limited in what they can do. I think one of the, one of them, I don't remember it was lovable or replet just this week, put up a showcase of this guy that built a dinosaur tracking app himself in minutes. And it looked cool, but all it was, was cards of dinosaurs.
22:36Okay. Like this is what vibe, like it looks good. It had like stegosaurus and tyrannosaurus and voloptosaurus and sassosaurus, but they didn't do anything. It didn't collect money. It didn't do anything except to have cards of dinosaurs. It'll look great. So go find on the internet, something done in, in replet lovable bolt, whatever you want that's in production. And then you'll get a good sense of what's really possible. Not what someone's selling you snake oil about. You got to do this. You got to do this. Okay. Three. This is another thing they don't tell you about on the, on the internet, on the, when their marketers are spinning up how you can roll your own in 20 minutes, dude, up front, you got to define your production requirements.
23:18If you can see this on the right, this is me, not someone on my team. not someone that works for me. Look at how many deployments I did. How many is this, Amelia? This is like 22 deployments, 17 days ago, 16 days ago, 15, 14, 13, 12. Look at all the, who's going to do this for you. Another thing that they don't really say when you say you could vibe code your app in 15 minutes is who's going to fix the bugs. Who's going to maintain it? Who's going to update it? Who's going to, who, who will handle the security issues we talked about? Who will handle scaling issues? Who's going to take this over?
23:50Because these apps are unstable. I love them. Again, try our Sastra.ai, valuation calculator, RAI. I try the ones from the first slide. We'll go over them again. They're wonderful, but they are all unstable. I have to basically every day fix and update these apps. Who's going to do that for you? Who's going to do that for you? They do not maintain themselves. So this is a big question that you may not fully grok when you start, but this is a big deal. And a lot of folks on the internet say, hey, you know what, just hire a developer to take it over. That is great in theory. It is great in theory.
24:27But one, do you have that developer that wants to take this over? Most of us don't, or we wouldn't be vibe coding. If most of us had like a really great developer, we would have the developer build it for us. So this idea a developer is going to take it over is probably a myth because you don't have that person, okay? Two, you're going to go find that person to take over your app. You ask any great developer, how excited are you to take over a vibe-coded app? You're going to hear spaghetti code. Don't want to own it. Don't want to fix it. They don't want to do it. Okay. Third, can you find some sort of dev shop to take it over?
24:58Sure, but like they'll probably quit. One of the reasons I redid Saster.ai in Replit was because Amelia and I hired two different WordPress developer shops to update our saster.com WordPress site, both of them, their first day deleted our site, deleted it. You're not, at least WordPress has a proper staging environment, preview environment. They still went into it and deleted our site within minutes and blamed us. So if you spent all your own work, you're going to hand it over to some mediocre developer shop you don't know, and they're going to delete your data. This is complicated. So how are you going to, if you're serious about this and it's not a prototype and it's not a hack, who's going to own this?
25:39Who's going to own security? Who's going to own bugs? Who's going to own scaling? It's complicated. Okay. Point four. And this is a great one. This is not unique to me. If you spend five minutes of research on anyone talking about prosumer Vibe Coding, Vibe Coding Without Development, you're going to hear this advice and it is great advice. And this is part of the magic of Vibe Coding. You've got to build a rich PRD, a rich spec. Now, if you have a background in product or anything, you've done this a million times over your career. If you don't, you've never done it, but it's actually, the only complicated part is just doing it.
Read the full transcript
26:12So here is just a snippet of a PRD I built. The dashboard, profile integrations, watch lists, advanced AI, networking. This was sort of how we were trying to build that networking app. I talked about the first one that failed, but I had a pretty good PRD. So if you don't know how to do this, it's okay. Go and just go into it. If you've never done it before, it's actually fine because this is the beauty of AI. AI can help organize things for you. Go into a Google Doc and write two or three pages of everything you want this app to do. Everything you want. Everything. Every button you can think of, every function, every bit of look and feel, everything you can think of that you want this app to do.
26:49It's okay if you haven't done it before in its stream of consciousness. It's okay if this isn't how a VP of product at a top AI company would do it. write it your way in human language and then cut and paste and put it into clod and say turn this into a prd for me for replet or for lovable and they'll actually do a great job they will take your this is where ai shines it doesn't have to be perfect they will take your stream of consciousness and help you turn it into a prd you can work through it you can even ask clod or chat to me what am i missing what have i not thought through on my spec on my prd and they will be great and they will say you did not think through user authentication you did not think through this flow.
27:25They will come up and they will say, do you want me to help you think through that? Yes. Please give me four or five bullets to add to my spec. And you will come out of that convo. And it may take you a couple hours to do this, not five minutes with a great PRD that you can upload to a lovable replet, et cetera, and get going. And this will radically increase the quality of what you vibe code having a great spec. It's just, this is as true with an AI as it is with a bunch of humans. If you just ask your first developer, hey, just go build this without any spec. I mean, there are some really creative ones that can do that, but man, it's much better if you have a perfect spec built.
28:00And this is where you Google doc plus Claude can really get ahead. And it's again, it's okay if you haven't done this, but here's the thing. The vibe coding apps know this, the replets, the lovables, et cetera. And they will actually do this for you. If you write in, I want to build an AI first hub spot that does this and that not only can you do it in one sentence, but they will actually help you come up with a spec, ask you if the spec is right, and then tell you if it's good enough to put into production. And so that is much better than nothing. Like these platforms, I could be critical of them, but they're getting so much better.
28:32Every week they're pushing out new features, new things. And so the platforms themselves will do a bunch of this, but it's much, much better if you slow it down, slow it down and do it ahead of time, because these vibe coding platforms work at light speed and they'll encourage you to cut every corner to skip steps. And that's not what you want to do here. Define it as much as possible. Take hours to do this, then iterate it with Claude. Then ask Claude what you're missing and then put it into the prosumer vibe code you're doing. Okay. Number five, and hopefully you will glean this if you do your research of a couple of days of looking at other prosumer vibe apps that are in production that were done without developers.
29:12If you look at a lot of them, the dinosaur app, the whatever app, they'll look pretty slick at first, although they'll all start to look the same because they all use Claude and Claude artifacts for the most part. But understand, a lot of stuff that looks hard actually is fairly easy with prosumer vibe coding, which is cool. But a lot of stuff you would think, hey, this has got to be easy. It isn't. It isn't. Here's a fun one I was doing just, I think, this week. I'm skeptical we fixed anything. You're absolutely right to be skeptical. The email system isn't working. I can tell you, here's a list I've made of things you think should just work.
29:46They're not that hard, but man, these are super hard in the prosumer vibe apps. Email and scheduling. I have built five apps now. None of them get email or scheduling right. None of them get it right. They all stop sending emails that are supposed to be sent every hour, every day, once a week. They all stop sending them. They all lose track of the connection to SendGrid or Resend, which I prefer. it's constantly breaking the email constantly someone's going to have to constantly maintain this and i've talked to several leaders at the vibe code leaders and they get it and they're working on improvements here but you would think this would be easy how hard is it to send an email like just hook up send grid or resend get an api key you got to learn you're gonna have to learn how to get api keys if you're going to vibe good but it's not that hard you think this would just work on autopilot but there's a lot of reasons it's an endless headache so i today as we record this as we do this live.
30:39Honestly, I would not build any app that relies on email, that relies on it to function. It's just not going to be reliable. It's possible, but I wouldn't build it. I would build it. The second one, and you'll see this one all over the internet, all over folks talking about headaches of VibeCode, OAuth identity. It doesn't work in these VibeCode apps. It does not work with a big asterisk. What I mean is all of these apps have their own OAuth built in that is secure, that has been hardened. And everyone goes in and I know Replit the best because that's where I've spent time, but they all have the same ultimate, they're all more similar than they're different.
31:18And you're like, oh, I don't want to use the Replit OAuth that has their logo on it. I just want to use Classic Google. I want people just log in with Google or LinkedIn like they do in all the other apps I use, right? I just want it to be effortless. So you ask them to set it up for you and they do. And not only does it never work, but man, this is where you get security leaks. because they, cause Claude can't get it to work and it fakes it. And if you research, oh my God, I, I, you know, this vibe, I launched this vibe coding app and without within hours, hundreds of bits of confidential information were leaked and stolen by a hacker.
31:53It's almost always this. It's almost always trying to use any OAuth that's not built into the system. So you just, this shouldn't be that hard. How hard can it be to use a LinkedIn login? Like we've We do this on 7 million sites. It's just not possible, guys. Some folks will challenge me on this, but if you can just go deeper, don't listen to the apologists and the marketers. This is not possible. You have to use what's built in. And in general, use everything that's built into these platforms. It will just be more secure. If they have email built in, for example, I use Replit all the time. I do not like using SendGrid.
32:29I liked SendGrid in the old days when it was run by founders. It is impossible to use. There's no support available. It takes days to get back to you. I got caught in a doom loop going from free to paid. It's just brutal. So I'm like, I want to use Resend. Resend is super cool. I'm a super fan. Put that on the website. But Replit keeps wanting to use SendGrid. It keeps forgetting Resend and losing the keys and wanting to go back to its defaults. So use whatever these are in the defaults, which is usually Stripe, their own OAuth and something. Do not use others. Maybe Adjun's better. Maybe you want to use something else.
33:04Don't. use Stripe, use SendGrid, use their, importantly, use their OAuth. Okay. So that's hard. The third one, which almost, if we did a three-parter, this would be the entire third part and it would be brutal as enterprise security. This was the biggest mistake I made. And after I'd been through this, I can't give more kudos to Shopify and Squarespace and all of these folks because they allow millions of SMBs to not have to worry about this, to not millions of stores on Shopify, millions of web space on Squarespace and Wix, and no SMBs have to worry about, Hey, if someone buys my product on Shopify, all the data is going to be stolen, but you have to worry about it.
33:45You have to worry about it. If you vibe code your app, trust me, everyone agrees to this. Do the least collect the least amount of personal information, collect the least amount of data you can use the built-in Use Stripe if it's built into Repli. Use Stripe. Use what it does. But collect the least, not the most. And realize as soon as you generate a database in this app, as soon as there is a database, you have added security risk to your app. That is going to be ultimately your number one thing to worry about. If it's not the number one thing you're worrying about, then the only reason you're not going to get in trouble is because nobody cares.
34:20But I will tell you, and this is a scary thing. You know, I remember in the old days, my CTO, when I knew less about security, my CTO said, the only reason we haven't been hacked is nobody cares. This is what my old CTO said at Adobe Senate. The only reason we haven't been hacked is anybody cares. And he was wicked smart. And that has stayed with me for years. You would think if you used a prosumer vibe app and you launched an app for four people, who's going to care about my dinosaur trading card apps? Like who's going to care? And I would say until 18 months ago, your risk of getting hacked was approaching zero because nobody cared.
34:52people are gonna hackers always wanted to target the big ones the big names bring them down right not today my friends now the hackers the redditors want to attack all the vibe coded apps to make a point so they will go after all of them thousands and thousands of them they will try to steal your data and pii when you launch this is not a joke go on reddit you can see it folks think this is a sport. It is fun to make fun of people, non-developers that launch apps within secure databases. They think it's a sport. So this is far riskier than it was 18 to 24 months ago. And you should be worried about it.
35:29You should be worried about it. And this is the meta topic. And again, if we do a part two, we'll VibeCode together. And if we do a part three, half of it probably is enterprise security. Okay. And just in brief, a couple of the things that you would think should be easy because so much stuff is easy on VibeCoding. Like it's so cool, but it's hard media generation if you think you're gonna build a youtube clipping app or another descript or a canva it's just not there today it's just not there and probably because it's just not accessible enough from claude for one but it's just it just everyone says they like build these media apps no okay point five huge deal huge deal i should have known this before I started.
36:13It's obvious now. This ultimately is getting solved and will be massive for prosumer vibe coding. But right now, none of these platforms really support native mobile. Okay. It's complicated. Do they help you prototype a native mobile app? Yes. Can you hook up things like Expo and others and get close? Yes. But if you talk to the folks that work at these platforms, the lovables, replets, bolts, et cetera, they're like, this is for web apps. for web apps. This does not get you on the app store, the Apple app store. It just doesn't for a lot of reasons. And at first that might not seem like a big deal to you and maybe it isn't, but, um, you know, this isn't 2012.
36:53I mean, mobile is a bigger deal than desktop. Now, is it in B2B? No, right. And a lot of B2B apps were still in front of the browser and the mobile app is a, is ancillary, but I'll tell you for the first app for that matching app, I realized a couple of days in, hey, this would be best as a mobile app. Like, I don't really want this in the browser. I want you to be at home on your phone and saying, hey, Amelia wants to recruit a VP of marketing and she magically finds it on her phone. And it's going to be a massive amount of work. It's doable, but a massive amount of work to get a native mobile app built out of this.
37:24It may be beyond scope for most people. And three last things. And I hope that at least if you haven't started, at least this will give you a sense. And all of these things can be worked through on this list, but it's a lot more than 10 minutes. Custom design. This is something you may have to get comfortable with. There are templates. Replit has some nice templates. I think they launched in the last week. Lovable has always been design-focused and others. But at the end of the day, all these sites look like Claude. Once you see one Replit or Lovable site, you can just smell it. Someone was saying that 30 % of this YC class vibe-coded their app.
38:00And I went to see a couple. I'm like, that one's replic. It's lovable. Like I can see it now. And why can you see it? Well, they're all basically using Claude and Claude artifacts underneath. They're all running on Claude. Maybe some will run on, um, chat GPT five now that it's more developer focused, but they all run on. And so they all, if you try any of them, they all kind of output the same, not identical. There are differences, but it's kind of like a fettuccine Alfredo at one restaurant versus two others. I mean, you know, they're not that different. So just be aware that there are ways to, it is ultimately code.
38:34So of course you can design it, but without a designer and without a developer, it, your ability to have anything that doesn't look like a vibe coded website is going to be very limited. And these last two ones we hit debugging, anything complicated. We talked about this, the headaches I had, but the final one, and this is an existential issue. I do think the platforms are going to solve this, the lovables and replets, but this is at the edge of inexcusable today, which is for a lot of reasons, we're on a time that you can't run unit tests. And what are some folks will say, nod their heads. And other folks here will be like, what's a unit test?
39:09A unit test is how you keep your sanity. When you build a real app, not a toy app, not a prototype, not a one-page website, but a unit test every day, it tests it. Did the email scheduler work? Did the OAuth work? Did the Saster news work? Did the Saster stock quotes on our website work? Do the valuation calculator work? Our new Saster AI is so complicated now. And again, I kept it as simple as I could. We probably need like 50 unit tests a day to know if it's working. You know who that unit test is now? Me. Me. I got to do more work because every day I have to test every page of our website to make sure it works.
39:46Why can't you build unit tests, Lemkin? It's not that it's impossible, but let's talk about a non-developer vibe coding it. the problem is here's the simple problem if you build unit tests and this is if you go back to the craziness that happened to me on social media the agent when it first of all the agent wants you to be happy so we'll make up data that's number one issue we'll say it passed the test when it didn't but the worst thing is when it fails the test it will start changing your app it will start oh it didn't send the email you know what the answer is i'll switch to send grade and then the whole thing will be broken.
40:20So I know some folks will challenge me. I know if anyone from the big vendors watches this, they'll say, oh, that works, but it doesn't. It doesn't. And no one can really get these unit tests to work. And this has been an anchor of how you sanely have production software for years. And I do believe it's getting there. And just as the leaders have very recently added a basic level of security scanning, but it's great to find some security issues, they will ultimately add built-in unit tests for every app. Now, all this stuff is adding complexity, which they don't like, right? The leading vendors, they don't want to separate development from production.
40:58They don't want to do all this stuff because it takes this elegant one-sentence prompt that makes it complicated. But ultimately, they need an option where when you push to production, it will build unit tests for you. Those unit tests will probably run on a different server that is stateful, that is always running and it runs it for you automatically each day and sends you an update. But I do it and I'm getting better at the unit tests and Amelia and I get an email each morning from Saster AI telling it what's going on, but it's not reliable. It's just not reliable. And so you're going to have to be testing your, if you're serious about it, someone's going to have to be testing it every day.
41:36And then every day I got to fix the stuff that breaks one way or the other, I got to fix the date. So I'll give you one small example. If you go to the Saster.ai and you go to like news, there's a cool little video at the top that shows the latest video from 20VC with me, Rory, and Harry, like the latest one. It's really cool. And it rolls it and it looks like a newsroom. Half the time, it has the wrong one. No matter how many times I tell Replit and we have this thing and we use the YouTube API and we look at the latest one and then we see, is it the one that includes me or not? And we do this.
42:09And I bet if you go on it right now, you're going to see one from two weeks ago for Figma. I don't know if Amelia, if you're at your computer, you go to SAS today and tell me and nod your head, but you're probably going to see a two week old video on it. And every day I have to fix this every day. I have to fix this and a few other things. So this, the inability to have unit tests really work will drive you nuts. If you're serious about it, if you want to roll your own sales force. Okay. A couple other points. And, um, we might run out of time. And so if people want, we'll do a second session for more Q &A, but I think this stuff's important.
42:44Number six, this is, you know, when we had our original blow up with my agent deleting my database, I got a lot of advice here, but it was, I didn't understand it at the time, but now I get it. You have to understand how these AI agents work and that they're goal seeking. And that means they'll fabricate data. They'll fabricate results. They'll lie to finish a project. They'll lie to finish a project. Literally this happens to me this morning. Okay. This morning, I'm building this, again, this AI VC deck reviewer. It just worked. Hopefully, we'll push it out by next week. By the time we do this next one, we can talk about it.
43:19But it was struggling. Hours and after hours, it just wasn't working. It had to rag our data and combine it and then push it into the OpenAI API. It just wasn't working. And then finally, it said, oh, I fixed it all. And I said, this makes no sense. You can see it. This is from yesterday or maybe this morning. at the bottom right. You're absolutely right. The feedback's completely generic and useless. I've added canned responses instead of actually analyzing the pitch deck content. After all of this, it puts in, even though I put in the MD in the orders for Replit to never have fake or canned content, it still did it to make me happy because it couldn't get it to work.
43:59It couldn't get it to work. So after the third time we tried, it just started making the data up again. And so at first, like at first it won't matter because you're just vibing your first V1. You won't even see, and you're like, oh, okay. That's just a placeholder data. You call it placeholder data, but it's not so funny later when the data doesn't work and it puts in placeholder data when you ask. And even worse, as your app gets more and more complicated, you won't even know what's going on. So look, this is a huge headache, but these were all my JFCs in my original tweet thread. Now today I've learned to live with it.
44:35This is the most important thing. Your AI agent will lie. This is it. This is their version of hallucinating. It will say it, it will constantly say, once you start doing this, you do everything to say it's working great, Amelia. It's working great. Did you test it rapidly? No, I didn't test it. How do you know it's working great? No problem. Like literally this was all of me yesterday. It's working great. this deck reviewer i upload my my deck i made broken what do you mean are you sure it's working 100 sure it's working broken like 22 times it's just gonna make stuff up and you got to get good at this you got to get good at realizing it doesn't test stuff it makes stuff up and you will have to work around this or you will you'll never finish a project and if you look on the internet again a lot of folks will tell you 80 90 95 percent of vibe coded prosumer vibe coded apps are never finished.
45:29At best case, their prototypes are never finished. And this is number one reason people don't get their arms around that the AI agent is not truthful and you need to get comfortable with that. Okay. Number seven, this was one of the top mistakes I made and everybody makes it. It sounds simple, but it's not. Master the platform on day one. Master the platform. what do i mean i mean listen if you look at lovable and replet and bolt and whizzes base 44 and canvas offering and figmas they're all uh you know a simple prompt with uh with uh with a you know curved radii window that says tell me what you want it looks so simple we'll get it again point number one get it out of your system spend 60 minutes vibe coding whatever and then learn every icon, every button.
46:21How does it work? These platforms are super powerful. And I would say Replit, which I use is the nerdiest of them because I think because it started as an ID, a platform for developers 10 years ago, almost 10 years ago, and then blew up as a prosumer platform this year, going from one to 160 million already this year. Crazy, right? Crazy. But it's super nerdy because it's for developers. And so all these icons, half of them, I don't even know what they mean, but you got to learn them. You got to learn them. Like for example, on the right, on the upper right here, Replit just added this and kind of after our little fiasco, but build planner edit.
46:58Okay. A week ago, they didn't have this. What does this mean? You could ignore it. You could ignore it, but the most important one is build. It will build it plan. It won't break your website. It will just talk to you. Okay. You got to know that it's there. Like they just added that or you will you will not know about this function the second one this sounds basic if you've built software you get it but the one thing these platforms do really really well is rolling back the second one so when the ai agent goes off the rails when it breaks something when it deletes something it shouldn't when it makes a change it's not supposed to you can roll back you can roll back you just got to get good at it and in the old days like when i built saas software honestly rolling back never used to work it was something your developers would tell you and then you'd be like, you know, that release on Friday night at 1 a.m.
47:47It didn't really work. Dan, can we roll back? He'd be like, actually, we can't really roll back. That was something they would just tell you. 11 ,000 kudos to these platforms. It's magical. It's magical. You can roll back almost to any point in time, but you got to learn what that means. You got to learn if you're more than 10 or 15 minutes in and the agent just can't get something, you got to go back in time 10 or 15 minutes and you got to know where those rollback points are and get really good at it. And I would say, frankly, if you're not rolling back once a day, you're not doing it right.
48:19This is how you can fix things that are otherwise unfixable. But rolling back to a week ago, I mean, there's a million reasons that becomes impossible. There's a hundred checkpoints. The real problem is if you go too long without rolling back, you may lose three, four, five features, not 10 minutes of work. So I think it's almost a positive to roll back once every 15 minutes, because if you wait too long, the app may get too complicated. Um, okay. We hit rollback, break everything into chunks. And the last one I'll say when you get frustrated, I just put up on, I was just trying to get this, uh, this VC tech done before this call for fun.
48:59And if you look what I just wrote on X right before this, I wrote, here's the thing I do when I get frustrated. I just write dude. Okay. Obviously this is not acceptable developer language, but I do a screenshot of the bug and I just write dude. Okay. When that happens, you got to roll back or take a break. Okay. And just two more, two more quick points. And then Amelia, if we have time, we'll take some questions. This is where I think the marketing and I look again, I love, I love all these apps. I'm a replet fan despite the drama, but mainly because that's what I picked. I picked, I could tell you why it really doesn't matter.
49:33If I'd started with Lovable, I'd probably be a Lovable fan if I'd started with Bolt. I actually don't think it matters. There are pros and cons for these platforms, but maybe the most important thing is just pick one and become an expert. Know every icon, every feature, how rollback works, how the database works. It's much more important to be an expert in one of these platforms than to spend six months agonizing over which one to pick a leader and just become an expert. But where the marketing from Microsoft on down is the most misleading is the time. If you seriously want to put a simple but real B2B app into production with real users, collecting real information and charging for it for real, and you want it to be any good budget, a month.
50:13A month. And 60 % of your time will be QA and testing. Okay? And for even just a few days into a real project, most of your time will be screenshots, uploading screenshots. This broke. This doesn't work. You will be doing so much functional QA. You cannot believe it. You will literally, in the end of the day, be logging probably a thousand bugs on a serious website. This will become your life. Maybe you used to have people to do this for you. I used to have a team of QA engineers to do this for me. Now it's me. Now my life is screenshot and bugs. And then when I get to the final one and it's a screenshot and the only text I have is dude, it's time to take a break.
50:52Okay. But this will be your life. So if you're serious, look, if you want to build a prototype, if you want to build something and tell all your friends you're a vibe coder at Starbucks. You don't need to budget for this time. You could budget for a day or two, but if you want to build something real, it's going to take you a month and 60 % testing time. And if you look at this chart on the right, this is, I just pulled this from Replet. This is our new Saster AI website, which I would argue, yeah, it's going to have 15 or 20 ,000 people, but we haven't fully rolled it out. Most of our traffic is still going to saster.com and probably will for months.
51:23And so where are we? Well, you can see, you know, maybe august 10th looking at this was our real soft launch with any users 16 000 so far you know we're a month into it and we're not we're in production but we're not rolled out not really and i gotta test this thing every day every day and look at this fun one from this morning a parser extracts 12 but made it 12 million you're gonna have to deal with this why did parser decide 12 should be 12 billion that this that you had 12 million customers not 12 i don't know, but, um, every day you're going to be doing this. Okay. This last one, we kind of hit it, but then I'll break.
52:01We talked in the beginning about who's going to, who's going to do the pushes. Who's going to do it once it's in production. If you're serious, you've got to have an exit strategy. I'm not the first one to say this, but you got to have it. If you actually get your app into production, you actually charge for it. And you actually have paying customers and real users and real PII who will maintain it, who will build new features. You think you don't want a lot, a lot of the mythology around vibe coding somehow magically assumes once you launch, you won't want to add features. Of course, you know, if you've, but any founder, any SaaS executive here, B2B knows your, your ad features your whole life.
52:35Who's going to do it? Who's going to fix the bugs that you introduce when you add features? Okay. Who will restart the database? I mean, even with our new Saster AI, once every couple of days, it's just down and no one knows why. It's not just like, it literally just has some like database, not working error in the upper left. Now I go into Replit, I restart it, it works. Who's going to do that? Who's going to fix the workers? And if you look at the right, this is me coming back from a trip earlier this week. It's me guys. That's me on the plane doing it myself. You want that to be you? You are going to sign up maybe forever if you don't have an exit strategy here.
53:10So my thoughts on getting going, hopefully it's helpful. Go through this, learn the platform code, get it out of your system. Just one shot one and get out of your system. Find ones that are similar and then take security and all of it seriously because it's a month to get something real out and it's a lifetime making it secure. Thanks, everybody. We'll do more and really appreciate everyone's time. The biggest B2B and AI event of the year is back. It's the Sastra AI Summit in the SF Bay Area, aka the Sastra Annual. It'll be back in May, 2026. With 36 % of everyone coming CEOs, it's an incredible AI-first professional event.
53:49The very, very best S-tier folks will be there talking about sharing and learning how to scale AI and B2B in this new world. But here's the reality. The longer you wait, the higher ticket prices go up. They're really cheap at the beginning. And then, you know, just a few days before, they get kind of expensive. But you've been warned. Early bird tickets are available now, and I want to see you there. Once they're gone, you'll pay hundreds more. So book your spot today by going to podcast.sasterannual.com. That's podcast.sasterai.com to get you exclusive discounts for Saster AI SF 2026. We will see you there.
From the publisher
SaaStr 820: The Complete Guide to Vibe Coding Without a Developer with SaaStr CEO and Founder Jason Lemkin
Join us in this episode as we dive into the world of vibe coding with a prosumer approach. SaaStr CEO and Founder Jason Lemkin shares his extensive journey of building production-ready applications without a developer, using platforms like Replit and Lovable. From initial excitement to hard-earned lessons, learn about the strengths, challenges, and key takeaways from creating and deploying vibe-coded apps. Discover why the hype around 'building an app in 20 minutes' is often misleading, and understand the importance of thorough planning, competitive research, and mastering your platform. Whether you're a founder, aspiring app creator, or tech enthusiast, this episode will provide valuable insights into the future of no-code and low-code development.
----------------------- This episode is sponsored by Intercom
 Fin is the #1 AI Agent for resolving complex queries like refunds, transaction disputes, and technical troubleshooting—all with speed and reliability. See how Fin can deliver the highest resolution rates and highest-quality customer experience at fin.ai/saastr.
---------------------
If you're serious about B2B and AI, you need to be in London this December 2nd and 3rd. SaaStr AI London is bringing together more than 2,000 leaders and founders for two days of practical advice on scaling into the new year. We'll have speakers flying in from OpenAI, Wiz, Clay, Intercom, and all your favorite SaaS companies, including yours truly with Harry Stebbings for a live 20VC podcast. It'll be fun, and it's all in the heart of London. Don't miss out: get your tickets with my exclusive discount by going to podcast.saastrlondon.com
---------------------
Hey everybody, the biggest B2B + AI event of the year will be back - SaaStr AI in the SF Bay Area, aka the SaaStr Annual, will be back in May 2026. With 68% VP-level and above, 36% CEOs and founders and a growing 25% AI-first professional, this is the very best of the best S-tier attendees and decision makers that come to SaaStr each year. But here's the reality, folks: the longer you wait, the higher ticket prices can get. Early bird tickets are available now, but once they're gone, you'll pay hundreds more so don't wait. Lock in your spot today by going to podcast podcast.saastrannual.com to get my exclusive discount SaaStr AI SF 2026. We'll see you there.




