@joyceketteringi
iAccount based inFrance
About this account
- Account based in
- France
- Connected via
- Web
Account-level information from X, not a live location or the device used for a specific post.
Now do more with @Stripe in WeWeb. A lot more ๐ณ
Sell a subscription โ send an invoice โ issue a refund โ build a billing dashboard... and more!
Try it out and tell us what's still missing ๐
Hereโs what you could do before vs. what you can do now ๐
๐จโ๐ป Vibe coding your app? Before you ship it, run this security checklist:
๐ AUTH & ACCESS
Test like a hacker.
โ Create two test users. Copy one user's read request as cURL, replay it in Postman with the other user's record ID. Do you get their data?
โ Replay the same request as an update. Does their record change?
โ Replay it as a delete action. Is their record gone?
โ As a normal user, call an admin or privileged endpoint directly. Does the backend reject you?
โ Change fields like `role`, `owner_id`, `user_id` or `workspace_id` in a request. Can you give yourself access you shouldnโt have?
โ Sign out completely. Replay a write request with the authorization header removed. Does the backend accept it?
๐๏ธ DATA & SECRETS
Consider it public until you test it.
โ Open DevTools โ Network and reload every sensitive page. Do any responses contain records or fields the current user shouldnโt receive?
โ Inspect request headers, payloads, frontend bundles and browser storage. Can you find any private API key, service credential or secret?
โ Are you storing sensitive data you donโt actually need?
๐งน INPUT & INTEGRATIONS
Never trust user input.
โ Replay a request without using the UI. Send missing fields, extra fields, invalid values and oversized input. Does the backend reject them safely?
โ Upload an invalid or oversized file. Does the backend enforce the same rules as the frontend?
โ Make a third-party integration fail or timeout in staging. Does your workflow fail safely without leaking internal details?
๐ฆ ABUSE PROTECTION
Never assume the user โwonโt find out".
โ Repeat a harmless action several times in staging. Do login, AI, email, upload and export actions eventually hit an appropriate limit?
โ Retry an action that should only happen once. Can it accidentally send two emails, create two payments or run twice?
๐ LOGGING & RETESTING
No app is 100% secure. Keep testing.
โ Trigger a failed login or denied request. Can you find the event in your backend logs without passwords, tokens or secrets being logged?
โ Change a role, workflow or data model, then rerun the permission tests. Do the same security rules still hold?
๐ก And one worth remembering:
Hiding a button, field or page in the frontend is UX.
It is NOT security.
Save this before your next launch. ๐
Joyce Kettering retweeted
WeWeb is now a verified @claudeai Connector! ๐
Coding agents are democratizing the power to build across teams.
Thatโs great... until IT is left worrying about the security and maintainability of what gets shipped.
Thatโs where WeWeb MCP comes in ๐
๐ฅ ๐๐ฑ๐ฑ ๐๐ ๐๐ผ ๐๐ผ๐๐ฟ ๐ฎ๐ฝ๐ฝ ๐ถ๐ป ๐ท๐๐๐ ๐ฎ ๐ณ๐ฒ๐ ๐ฐ๐น๐ถ๐ฐ๐ธ๐ with native integrations for @OpenAI, @AnthropicAI, and @GeminiApp.
1๏ธโฃ Choose an action: generate text, create images, or build embeddings
2๏ธโฃ Pick the best model for your use case
3๏ธโฃ Connect the output to your appโs data and logic
And once itโs live, ๐๐ฟ๐ฎ๐ฐ๐ธ ๐ฟ๐ฒ๐พ๐๐ฒ๐๐๐, ๐๐ผ๐ธ๐ฒ๐ป ๐๐๐ฎ๐ด๐ฒ, ๐ฎ๐ป๐ฑ ๐ฐ๐ผ๐๐๐ in one place.
Hear the full update from @msandys_ ๐
I made a textarea component that resizes depending on its content in @weweb_io
Here is the demo where I apply it for 3 use cases:
โ An editable title in a drawer
โ A note column in a table
โ A chat input
This video is larger than Cloudflare's 512 MB cache, so it can't be played through. More donations are needed to cover a larger cache. Donate
๐คฏ @SpotifyEng shipped Xirp, an agent-agnostic vibe coding environment.
We loved the idea, and of course, the team had to try it. So we connected the agents to WeWeb through MCP and gave them a few apps to build:
โ KPI Dashboard
โ Task Management
Under the hood, they share the same global design system, so every app stays on-brand as we build.
Plus, a routing skill that hands off tasks cleanly: mockups to Gemini, frontend to Claude, and backend to Codex.
And the end result isnโt a throwaway prototype.
Itโs a secure, working WeWeb app thatโs still easy to understand and edit visually when a human wants to jump in.
๐ซต What are you waiting for?
Bring your own agents and start building with a visual editor in the loop: weweb.io/product/mcp
๐ฒ Wow, what a UI library. Time to bring these components into WeWeb:
1. Paste the component code into Claude
2. Ask it to build the component in your WeWeb project
3. Restyle it, wire up the logic, and make it yours โจ
found a gold mine for design engineers building ai interfaces
beautiful-ui-five.vercel.appโฆ
๐งฉ Our marketing team is big fans of building HTML artifacts with Claude and ChatGPT.
Itโs fast. It feels interactive. No context switching.
The problem starts when the wider team needs to rely on it.
You can share these artifacts in one click. But suddenly itโs hard to answer:
โข Who can see and edit what?
โข Can someone on the team update this next week?
โข Is this a one-off file? Or is it becoming an actual internal tool?
With WeWeb MCP, our team is moving those HTML artifacts into WeWeb.
Same speed to build. Now the whole team can use it, maintain it, and control who gets access.
And this isnโt unique to our team. Across companies, non-engineers are building and shipping the tools they need themselves.
It makes sense. Theyโre the people closest to the problem.
Then IT gets pulled in to review data security and permissions. And too often, the โsafeโ answer is to ban citizen development altogether.
That fixes the mess. It also kills the momentum.
With WeWeb, teams donโt have to choose between speed and control:
โ Vibe code when you want to move fast.
โ Open the visual editor when you need visibility into workflows, data, and access rules.
Hereโs a glimpse of how authentication and user data are handled ๐
Here is my workflow when I want to improve a coded component in @weweb_io
I wanted to create a floating comment input on my Rich text editor. I went through this process:
First I needed to understand how the toolbar visibility was controlled. It allowed me to implement my feature the best way. I've used Claude Code to help me in those steps.
Then, to mock it up, I used WeWeb MCP along with a simple screenshot of Claude UI to recreate the design on my page.
๐ฌ It always starts with a spreadsheet.
Then someone adds a form, a few automations.
Then a second spreadsheet to fix the first one.
Before long, the team is running an important process through a system nobody intentionally designed.
Today, the person closest to the problem can build the tool properly.
An internal CRM. An approval portal. A work-order tracker. An inventory app. An admin dashboard. And more.
1๏ธโฃ Give AI the messy idea.
2๏ธโฃ Get a clear build plan.
3๏ธโฃ Build the app with AI, then refine it in WeWeb.
Keep improving it as the process evolves.
No waiting for IT. No forcing fitting your workflow into another SaaS tool.
Go find the internal tool hiding in your spreadsheet and start building today: weweb.io/use-cases
Shoutout to @jptrinhh who is building a library of WeWeb components, blocks, and logic.
Check it out: community.weweb.io/t/weweb-lโฆ
He'd love your feedback and requests ๐
๐โโ๏ธ What's your go-to component library? @21st_dev?
Here's the fun part: with the WeWeb MCP, you can import any component from your favorite library straight into your WeWeb project, as code.
Then use it like any other no-code component, fully styleable and wireable into your logic with properties, variables, and triggers.
Custom code power meets no-code control โค๏ธ
Follow along as Matthew imports a scroll-wheel date picker ๐
๐งโ๐ป It's settled: you can prompt an app to life in a weekend. BUT...
If you're not a developer, can you actually control what AI ships?
Or are you just trusting a black box you can't read or change?
In this build guide, @msandys_ starts with a prompt and builds it into a real, secure project management app in WeWeb.
You'll see exactly how the whole app gets built inside the visual editor, from screens to data to APIs to auth.
You're not left to prompt and hope.
Follow along and build the app with him ๐
Joyce Kettering retweeted
For 2 years, "vibe coding" gave non-coders a superpower and a curse: they could build anything, and trust none of it.
Today that ends.
We just shipped WeWeb's MCP server and it changes what "building with AI" means.
Starting now, you can point your favourite AI coding agent (Claude, Codex, etc.) straight at WeWeb. The agent builds. You watch every output land in a visual canvas you can see, edit, and trust.
In other words: WeWeb is now a visual harness for the world's best models. The AI generates. WeWeb keeps it deterministic, editable and production-grade.
And the MCP is free. It runs on your existing Claude or Codex subscription. Zero WeWeb AI tokens billed. The latest frontier models, with no markup.
Here's what that unlocks ๐
Non-coders finally get the raw power of frontier models merged with the control, comfort, and transparency of a drag & drop editor.
For the first time, anyone can build with an AI agent and review every single output on a visual canvas.
This is the end of AI slop for non-coders. No more black-box generation you can't inspect. No more apps stuck forever at the prototype stage. You can finally vibe code with confidence and ship to production.
I've spent the last few weeks building in WeWeb from Claude Code myself. It's been spectacular:
โ Output quality is top notch
โ It runs on my own Claude subscription
โ I drive it through Claude's UX, which is excellent
โ I can modify EVERYTHING by hand in the WeWeb canvas
โ I can read and edit every workflow as a diagram
โ Claude is guardrailed by the WeWeb "way of building": secure and scalable by design
โ And I keep every WeWeb superpower: one-click publish, collaboration, design system, native integrations, automated code upgrades, automated security patching, automated backups, automated database migrations, etc.
The dream we had of making visual development & AI merge has finally come to fruition. A new era for no-code platforms has just begun, and it only gets better from here.
WeWeb MCP is here.
Your favorite AI agents can now build directly inside WeWeb.
Bring Claude Code, Cursor, ChatGPT, Codex, Antigravity, or any agent you choose.
Your agent can help build secure web apps using WeWebโs pages, components, workflows, API requests, databases, integrations, auth, storage, and more.
You decide what it can work on: the full app, or only specific parts of your project.
Everything stays visible and editable in WeWeb, so you can review what was built, make changes visually, and keep maintaining the app with your team.
No black box.
Open beta starts today.
This video is larger than Cloudflare's 512 MB cache, so it can't be played through. More donations are needed to cover a larger cache. Donate
WeWeb MCP is here.
Your favorite AI agents can now build directly inside WeWeb.
Bring Claude Code, Cursor, ChatGPT, Codex, Antigravity, or any agent you choose.
Your agent can help build secure web apps using WeWebโs pages, components, workflows, API requests, databases, integrations, auth, storage, and more.
You decide what it can work on: the full app, or only specific parts of your project.
Everything stays visible and editable in WeWeb, so you can review what was built, make changes visually, and keep maintaining the app with your team.
No black box.
Open beta starts today.
This video is larger than Cloudflare's 512 MB cache, so it can't be played through. More donations are needed to cover a larger cache. Donate