Vibe Coding in 2026: Tools, Numbers, Failures, and Fixes
What vibe coding is, who uses it, what it costs, what has broken, and how to ship a vibe-coded app safely with the verification layer done right.
Build a card pre-grading and authenticity app with Lovable, Cursor or Claude Code and the deepidv MCP server. Real config, real endpoints, real security.
You can build a working TCG grading app with a vibe-coding tool and an API in a weekend: a capture screen that takes one photo of a binder page, an authenticity result and grade estimate per card from deepidv's engine, a submission flow for cards worth sending to a grader, and identity verification for the submitter. The parts you must not vibe are the backend rules (row level security on every table), the API keys (server side only) and the verification itself (an API, never a prompt). This guide gives the prompts, the MCP config, the endpoints and the checklist.
Vibe coding, the term Andrej Karpathy coined in February 2025 for describing an app in natural language and letting an AI write it, became Collins Dictionary's word of the year in November 2025; the full state of the category is in vibe coding in 2026. It also produced a run of security failures that this guide is built to avoid: Lovable-generated apps with no row level security on their Supabase tables, an agent on Replit that deleted a production database, and a vibe-coded social network that exposed 1.5 million API tokens. A grading app holds card images and, for submitters, identity data. Build it right.
Scope for a weekend, in priority order:
Leave out for the weekend: a marketplace, chat, and anything that stores payment details.
Any of them builds this. Choose on where you want the backend to live.
deepidv publishes a hosted MCP server at https://mcp.deepidv.com/v1/mcp (Streamable HTTP, OAuth with PKCE) and an npm wrapper for clients that only speak stdio (docs, repo). Verification for vibe coders is the product overview.
Direct connection:
{
"mcpServers": {
"deepidv": {
"url": "https://mcp.deepidv.com/v1/mcp",
"transport": "http"
}
}
}
Stdio wrapper:
{
"mcpServers": {
"deepidv": {
"command": "npx",
"args": ["-y", "@deepidv/mcp-server"]
}
}
}
Sign in with your deepidv account when prompted. The server exposes tools for sessions, workflows, screening and phone checks (create_verification_session, create_workflow, run_pep_sanctions_check, run_carrier_age_gate_check and more). Your assistant can now build the verification steps against real objects instead of guessing.
deepidv also publishes agent skills for Claude Code, Codex, Cursor and Windsurf that teach the assistant the verification flow.
Paste these in order. Each one is scoped so the assistant cannot wander.
Prompt 1, the shell. "Build a mobile-first web app called [name]. Screens: Scan, Results, Submission, Account. Use Supabase for auth and data. Enable row level security on every table you create and write policies so a user can only read and write their own rows. Never put any API key in client code; all third-party calls go through server functions that read keys from environment variables."
Prompt 2, capture.
"On the Scan screen, integrate the deepidv Capture SDK so one photo of a binder page returns a list of recognized cards. Store each card with the source image reference, recognized name, set and collector number in a cards table owned by the user."
Prompt 3, authenticate and grade.
"For each recognized card, call the deepidv card authentication endpoint from a server function and store authenticity_result, authenticity_signals, grade_estimate and proof_id. Show the result on the Results screen with the proof link https://proof.deepidv.com/a/{proof_id}."
Prompt 4, submitter identity.
"When a user creates a submission with a total declared value above $500, create a deepidv verification session from a server function with POST https://api.deepidv.com/v1/sessions (header x-api-key), redirect the user to the returned session_url, and handle the session.status.verified webhook by marking the user verified. Do not let a submission ship until the user is verified."
Prompt 5, the audit. "List every table and its RLS policies. List every environment variable and where it is read. Confirm no key is present in client bundles. Add rate limiting to every server function."
Submitter verification, server side, with the official Node SDK (quickstart):
import { DeepIDV } from "@deepidv/server";
const client = new DeepIDV({ apiKey: process.env.DEEPIDV_API_KEY! });
export async function startSubmitterVerification(user: {
firstName: string; lastName: string; email: string; phone: string; id: string;
}) {
const session = await client.sessions.create({
firstName: user.firstName,
lastName: user.lastName,
email: user.email,
phone: user.phone, // E.164, e.g. +14165557890
externalId: user.id,
redirectUrl: "https://yourapp.com/submission/verified",
});
return session.sessionUrl; // send the user here
}
The same call with curl, for any stack (reference):
curl -X POST https://api.deepidv.com/v1/sessions \
-H "Content-Type: application/json" \
-H "x-api-key: $DEEPIDV_API_KEY" \
-d '{"firstName":"Jane","lastName":"Smith","email":"jane@example.com","phone":"+14165557890","externalId":"user_123"}'
Webhook handler: register the endpoint in the admin console, store the whsec_ secret, and act on session.status.verified, session.status.rejected and session.status.failed (webhooks). Return 2xx quickly; deepidv retries with backoff otherwise.
Card authentication: the endpoint is provided with TCG partner access, and the response carries the authenticity result, the signals and a proof id. Ask for access at cal.com/team/deepidv, and keep the call server side like every other one.
Testing: deepidv's sandbox key returns canned sessions at GET /v1/sessions/test_verified, test_rejected, test_submitted, test_pending and test_voided (sandbox); it is read-only, so wire your webhook handler against those states before going live.
The full pass is the vibe coding security checklist; these are the checks a grading app cannot skip:
Per the deepidv pricing you can plan on for this app: authenticity and grade estimate from $0.05 a check, Capture SDK free to 500 cards a month and under a tenth of a cent per card after, identity verification with liveness at the public list price on deepidv.com/pricing. A $4.99 monthly tier covers a collector who scans 50 cards a month with room left over. deepidv is also integrating with a small number of TCG apps on the App Store at no cost; ask.
You can build the app with a vibe-coding tool. You cannot skip the security rules: row level security, keys kept server side, and verification done by an API. The prompts above bake those in.
Yes. A hosted server at mcp.deepidv.com/v1/mcp with OAuth sign-in, and an npm wrapper, @deepidv/mcp-server, for stdio-only clients. It exposes session, workflow, screening and phone-check tools.
Treat it as a pre-grade: a consistent estimate that tells a collector whether a card is worth submitting. Every official grade still comes from the grading company. Authenticity screening is a separate result and the one that stops fakes.
Missing row level security on the database, followed by API keys in client code. Both were behind the largest 2025 and 2026 exposures.
Authenticity and grade checks from $0.05; batch capture free to 500 cards a month and under a tenth of a cent per card after.
Yes. Grading and collection apps are a standard category; the identity flow is hosted by deepidv and returns to your app. Keep the privacy policy accurate about what images you store.
Go live in minutes. No sandbox required, no hidden fees.
What vibe coding is, who uses it, what it costs, what has broken, and how to ship a vibe-coded app safely with the verification layer done right.
RLS, secrets, environments, dependencies, MCP configs, personal data, identity verification and app store rules. A pre-launch checklist with a prompt per fix.
What US and EU rules require of a fintech app, what the BaaS enforcement wave taught, and how to add KYC and AML with the deepidv MCP server and API.