Vibe Coding in 2026: Tools, Numbers, Failures, and Fixes
What vibe coding is, who uses it, what it costs, what has broken, and how to ship a vibe-coded app safely with the verification layer done right.
INFORM Act and DSA Article 30 obligations, the four fraud patterns that kill new marketplaces, and the deepidv onboarding flow with identity, dedupe and proof.
A marketplace built with AI tools inherits the same obligations as one built by a hundred engineers: in the US, the INFORM Consumers Act requires collecting and verifying bank, ID, tax and contact details for any seller with 200 transactions and $5,000 in a year, and the FTC's first case settled for $2 million; in the EU, DSA Article 30 requires trader identity, payment and registration details before a trader can sell, and 2026 brought fines of €550 million and €200 million for marketplaces that failed to manage illegal and counterfeit goods. The fraud that kills small marketplaces first, ban evasion, account takeover, counterfeits and triangulation, is stopped by the same control the law requires: a verified seller tied to a verified payout. Here is the flow, and the code.
Marketplace verification is the deepidv vertical this guide draws on. Pair it with the vibe coding security checklist for the app itself and with marketplace fraud in 2026 for the enforcement detail. For card and collectibles marketplaces, the TCG marketplace guide applies the same flow to that vertical.
INFORM Consumers Act (US). A high-volume third-party seller is one with 200 or more transactions and $5,000 or more in gross revenue in a 12-month period. For each, the marketplace must collect and verify bank account, government ID, tax ID and contact information, recertify annually, disclose sellers above $20,000 to consumers, and offer a reporting mechanism. The FTC's first case ended with Temu paying $2 million in September 2025, over a missing telephonic reporting mechanism and missing disclosures in gamified and mobile listings.
DSA Article 30 (EU). Before a trader can sell, the platform must obtain name, address, phone and email, an ID document copy, payment account details, trade register details and a self-certification, make best efforts to verify them, suspend non-compliant traders, and retain the data six months after the relationship ends. The Commission fined AliExpress €550 million on 20 July 2026 and Temu €200 million in May for failing to manage the risk of illegal and counterfeit goods.
Four patterns, all documented in marketplace fraud in 2026:
The law and the fraud ask for the same thing. Build it once.
Attach the deepidv MCP server to Cursor or Claude Code (docs):
{
"mcpServers": {
"deepidv": {
"command": "npx",
"args": ["-y", "@deepidv/mcp-server"]
}
}
}
Prompt: "Using the deepidv MCP server, create a workflow named 'seller-onboarding' with ID_VERIFICATION, FACE_LIVENESS, ANTI_CHEAT and PEP_SANCTIONS. Add a server function that creates a verification session for a seller when they first attempt to list, redirects them to session_url, and stores verified status on the session.status.verified webhook. Block listing and payouts for unverified sellers. Add a scheduled job that creates a bank statement request for sellers whose payout account changed."
The generated code should look like this on the server (sessions, SDK):
import { DeepIDV } from "@deepidv/server";
const client = new DeepIDV({ apiKey: process.env.DEEPIDV_API_KEY! });
export async function verifySeller(seller: {
id: string; firstName: string; lastName: string; email: string; phone: string;
}) {
const s = await client.sessions.create({
firstName: seller.firstName,
lastName: seller.lastName,
email: seller.email,
phone: seller.phone,
externalId: seller.id,
workflowId: process.env.DEEPIDV_SELLER_WORKFLOW!,
redirectUrl: "https://yourmarketplace.com/seller/verified",
});
return s.sessionUrl;
}
Webhook handler: on session.status.verified, set seller.verified_at; on session.status.rejected or session.status.failed, keep the seller blocked and open a review (webhooks). Dedupe runs inside the workflow as ANTI_CHEAT; a DUPLICATE verdict against a banned face stops the enrollment (reference).
Step-up: when a verified seller changes payout details, create a new session with a workflow of FACE_LIVENESS only and hold the change until it passes. Payout account checks use the bank statement request tool exposed through the MCP server and the financial endpoints.
Test with the sandbox: GET /v1/sessions/test_verified, test_rejected, test_pending and test_voided return canned states (sandbox).
Buyers get a light check: phone trust at signup (POST /v1/screening/phone-trust) and full identity only when they cross a value threshold or open a dispute. Listings get screened by category: for cards and collectibles, deepidv's TCG Authenticity Verification reads the listing photos for counterfeit signals, and the seven TCG marketplace scams show what it is screening for; for other goods, the seller's verified status and history carry the weight.
At the public list prices at the time of writing: identity with liveness $0.50, biometric dedupe 1:N $0.30, PEP and sanctions $0.40, KYB $0.70, phone verification $0.15. A seller is verified once; a repeat check on a returning verified person is $0.05. On a marketplace taking 10 percent of a $50 order, the onboarding cost of a seller is recovered on their first sale. Marketplaces are a listed use case for the deepidv Startup Program.
Yes, from the moment any seller reaches 200 transactions and $5,000 in revenue in a year. The thresholds apply to sellers, not to the marketplace's size.
The EU rule requiring online platforms to collect and verify trader identity, contact, payment and registration details before a trader can sell, and to suspend traders who do not comply.
One-to-many face matching at onboarding. Email and phone bans are free to evade; a face is not.
The integration, yes. The verification runs on deepidv's engine through a hosted session and a webhook; with the MCP server attached, your assistant creates the workflow and the session code from a prompt.
Sellers get full identity, dedupe and payout verification because they are the regulated party and the fraud vector. Buyers get a light check unless they cross a value or dispute threshold.
Keep a tamper-evident record per check. deepidv seals every verification as a proof at proof.deepidv.com, with no personal data on chain.
Go live in minutes. No sandbox required, no hidden fees.
What vibe coding is, who uses it, what it costs, what has broken, and how to ship a vibe-coded app safely with the verification layer done right.
RLS, secrets, environments, dependencies, MCP configs, personal data, identity verification and app store rules. A pre-launch checklist with a prompt per fix.
What US and EU rules require of a fintech app, what the BaaS enforcement wave taught, and how to add KYC and AML with the deepidv MCP server and API.