deepidv
Vibe CodingSeptember 29, 202612 min read
N° 284

Vibe-Coded TCG Grading: Build a Card Grading App Fast

Build a card pre-grading and authenticity app with Lovable, Cursor or Claude Code and the deepidv MCP server. Real config, real endpoints, real security.

You can build a working TCG grading app with a vibe-coding tool and an API in a weekend: a capture screen that takes one photo of a binder page, an authenticity result and grade estimate per card from deepidv's engine, a submission flow for cards worth sending to a grader, and identity verification for the submitter. The parts you must not vibe are the backend rules (row level security on every table), the API keys (server side only) and the verification itself (an API, never a prompt). This guide gives the prompts, the MCP config, the endpoints and the checklist.

Vibe coding, the term Andrej Karpathy coined in February 2025 for describing an app in natural language and letting an AI write it, became Collins Dictionary's word of the year in November 2025; the full state of the category is in vibe coding in 2026. It also produced a run of security failures that this guide is built to avoid: Lovable-generated apps with no row level security on their Supabase tables, an agent on Replit that deleted a production database, and a vibe-coded social network that exposed 1.5 million API tokens. A grading app holds card images and, for submitters, identity data. Build it right.

What should the app do?

Scope for a weekend, in priority order:

  1. Capture. One photo of a binder page or a stack; every card recognized and queued. deepidv's Capture SDK does the single-photo batch step; the pricing you can plan on is free up to 500 cards a month and under a tenth of a cent per card after.
  2. Authenticate and pre-grade. For each card, an authenticity result (real or flagged, with the signals) and a grade estimate in PSA and CGC terms. From deepidv's TCG Authenticity Verification, priced from $0.05 a check, which fits inside a subscription tier.
  3. Decide. Show the collector the raw-versus-graded value gap so they know which cards are worth submitting.
  4. Submit. Collect the cards into a submission with declared values, verify the submitter's identity above a threshold, and generate a shipping label.
  5. Prove. Give every result a proof link at proof.deepidv.com so a buyer can verify it later.

Leave out for the weekend: a marketplace, chat, and anything that stores payment details.

Which vibe-coding tool should you use?

Any of them builds this. Choose on where you want the backend to live.

How do you add deepidv to Cursor or Claude Code?

deepidv publishes a hosted MCP server at https://mcp.deepidv.com/v1/mcp (Streamable HTTP, OAuth with PKCE) and an npm wrapper for clients that only speak stdio (docs, repo). Verification for vibe coders is the product overview.

Direct connection:

{
  "mcpServers": {
    "deepidv": {
      "url": "https://mcp.deepidv.com/v1/mcp",
      "transport": "http"
    }
  }
}

Stdio wrapper:

{
  "mcpServers": {
    "deepidv": {
      "command": "npx",
      "args": ["-y", "@deepidv/mcp-server"]
    }
  }
}

Sign in with your deepidv account when prompted. The server exposes tools for sessions, workflows, screening and phone checks (create_verification_session, create_workflow, run_pep_sanctions_check, run_carrier_age_gate_check and more). Your assistant can now build the verification steps against real objects instead of guessing.

deepidv also publishes agent skills for Claude Code, Codex, Cursor and Windsurf that teach the assistant the verification flow.

The prompt sequence

Paste these in order. Each one is scoped so the assistant cannot wander.

Prompt 1, the shell. "Build a mobile-first web app called [name]. Screens: Scan, Results, Submission, Account. Use Supabase for auth and data. Enable row level security on every table you create and write policies so a user can only read and write their own rows. Never put any API key in client code; all third-party calls go through server functions that read keys from environment variables."

Prompt 2, capture. "On the Scan screen, integrate the deepidv Capture SDK so one photo of a binder page returns a list of recognized cards. Store each card with the source image reference, recognized name, set and collector number in a cards table owned by the user."

Prompt 3, authenticate and grade. "For each recognized card, call the deepidv card authentication endpoint from a server function and store authenticity_result, authenticity_signals, grade_estimate and proof_id. Show the result on the Results screen with the proof link https://proof.deepidv.com/a/{proof_id}."

Prompt 4, submitter identity. "When a user creates a submission with a total declared value above $500, create a deepidv verification session from a server function with POST https://api.deepidv.com/v1/sessions (header x-api-key), redirect the user to the returned session_url, and handle the session.status.verified webhook by marking the user verified. Do not let a submission ship until the user is verified."

Prompt 5, the audit. "List every table and its RLS policies. List every environment variable and where it is read. Confirm no key is present in client bundles. Add rate limiting to every server function."

Ready to get started?

Start verifying identities in minutes. No sandbox, no waiting.

Get Started Free

The code the assistant should produce

Submitter verification, server side, with the official Node SDK (quickstart):

import { DeepIDV } from "@deepidv/server";

const client = new DeepIDV({ apiKey: process.env.DEEPIDV_API_KEY! });

export async function startSubmitterVerification(user: {
  firstName: string; lastName: string; email: string; phone: string; id: string;
}) {
  const session = await client.sessions.create({
    firstName: user.firstName,
    lastName: user.lastName,
    email: user.email,
    phone: user.phone,          // E.164, e.g. +14165557890
    externalId: user.id,
    redirectUrl: "https://yourapp.com/submission/verified",
  });
  return session.sessionUrl;    // send the user here
}

The same call with curl, for any stack (reference):

curl -X POST https://api.deepidv.com/v1/sessions \
  -H "Content-Type: application/json" \
  -H "x-api-key: $DEEPIDV_API_KEY" \
  -d '{"firstName":"Jane","lastName":"Smith","email":"jane@example.com","phone":"+14165557890","externalId":"user_123"}'

Webhook handler: register the endpoint in the admin console, store the whsec_ secret, and act on session.status.verified, session.status.rejected and session.status.failed (webhooks). Return 2xx quickly; deepidv retries with backoff otherwise.

Card authentication: the endpoint is provided with TCG partner access, and the response carries the authenticity result, the signals and a proof id. Ask for access at cal.com/team/deepidv, and keep the call server side like every other one.

Testing: deepidv's sandbox key returns canned sessions at GET /v1/sessions/test_verified, test_rejected, test_submitted, test_pending and test_voided (sandbox); it is read-only, so wire your webhook handler against those states before going live.

The security checklist you cannot skip

The full pass is the vibe coding security checklist; these are the checks a grading app cannot skip:

What does it cost to run?

Per the deepidv pricing you can plan on for this app: authenticity and grade estimate from $0.05 a check, Capture SDK free to 500 cards a month and under a tenth of a cent per card after, identity verification with liveness at the public list price on deepidv.com/pricing. A $4.99 monthly tier covers a collector who scans 50 cards a month with room left over. deepidv is also integrating with a small number of TCG apps on the App Store at no cost; ask.

Frequently asked questions

Can I build a card grading app without knowing how to code?

You can build the app with a vibe-coding tool. You cannot skip the security rules: row level security, keys kept server side, and verification done by an API. The prompts above bake those in.

Does deepidv have an MCP server?

Yes. A hosted server at mcp.deepidv.com/v1/mcp with OAuth sign-in, and an npm wrapper, @deepidv/mcp-server, for stdio-only clients. It exposes session, workflow, screening and phone-check tools.

How accurate is AI card grading?

Treat it as a pre-grade: a consistent estimate that tells a collector whether a card is worth submitting. Every official grade still comes from the grading company. Authenticity screening is a separate result and the one that stops fakes.

What is the biggest security mistake in vibe-coded apps?

Missing row level security on the database, followed by API keys in client code. Both were behind the largest 2025 and 2026 exposures.

How much does it cost per scan?

Authenticity and grade checks from $0.05; batch capture free to 500 cards a month and under a tenth of a cent per card after.

Can I publish it on the App Store?

Yes. Grading and collection apps are a standard category; the identity flow is hosted by deepidv and returns to your app. Keep the privacy policy accurate about what images you store.

Start verifying identities today

Go live in minutes. No sandbox required, no hidden fees.

Related Articles

All articles

Vibe Coding in 2026: Tools, Numbers, Failures, and Fixes

What vibe coding is, who uses it, what it costs, what has broken, and how to ship a vibe-coded app safely with the verification layer done right.

Sep 29, 202614 min
Read more

The Vibe Coding Security Checklist: 14 Checks Before Launch

RLS, secrets, environments, dependencies, MCP configs, personal data, identity verification and app store rules. A pre-launch checklist with a prompt per fix.

Sep 29, 202611 min
Read more

Securing a Vibe-Coded Fintech App: KYC, AML and the Code

What US and EU rules require of a fintech app, what the BaaS enforcement wave taught, and how to add KYC and AML with the deepidv MCP server and API.

Sep 29, 202613 min
Read more