You Built a Prototype. Here's What Stands Between It and a Real App
7 min readPublished By Ofer Regev
You built something with Claude Code or Cursor. It works. Then you send the link to a colleague and discover the truth: it runs for you, on your machine, and nobody else can use it. There's no login. There's no database. There's nowhere to put a file. Refresh the page and everything is gone.
You have a prototype. You don't have a product.
The gap is smaller than it looks. It comes down to six things.
The six things every real app needs
Infrastructure
Hosting: where your app lives and runs.
Auth: who can log in, and how.
Database: where your data lives and doesn't disappear.
Logic and files
Storage: files, images, user uploads.
Backend functions: server-side logic your frontend can call.
how code gets from your laptop to the world.
Deployment (CI/CD):
GitHub is the glue and the safety net
Before the stack, the repo. Every real platform auto-deploys from GitHub: push your code, and Vercel or Firebase picks it up. No more "works on my machine," because the repo is the truth.
It's also your undo button. Broke something? Roll back any AI-generated change instantly. Vibe coding without GitHub is building without a net, and it's what lets you experiment freely.
Two stacks, both fine
Stack A: Vercel + Supabase
Two tools, each excellent at its job.
Vercel is hosting and CI/CD: push to GitHub, live in seconds, with preview deploys for every branch.
Supabase is auth (email, Google, magic links), a real Postgres database, file storage and edge functions.
Stack B: Firebase
Google's all-in-one backend: one SDK, one console.
Auth with email, Google, Apple and phone.
Firestore, a flexible document database with real-time sync.
Cloud Functions, Storage, and Hosting with GitHub deploys.
How they compare, piece by piece
Supabase
Firebase
Auth
Providers configured in the dashboard, no code. Data rules use Row Level Security.
Same providers, set up in minutes. Security rules reference the logged-in user.
Database
Postgres: tables, rows and relations. SQL you may already know.
Firestore: documents and collections, JSON-like and flexible.
Storage
Buckets with policies tied to the auth user
Security rules tied to the user's ID, wired into Firestore
Functions
Edge Functions (Deno), run at the edge
Cloud Functions (Node.js), event-triggered
The auth difference worth knowing: Supabase ties access rules to database rows, Firebase ties them to documents.
And a rule that applies to both: if it has a secret key, it belongs in a server function. Calls to AI APIs, payments, webhooks and emails run server-side so the key never reaches the browser.
Which one for you?
Score your app on four criteria and see which column wins.
Criteria
Vercel + Supabase
Firebase
Data structure
Structured, relational
Flexible, document
SQL comfort
You like SQL
You prefer JSON
Deployment style
GitHub-first
Google ecosystem
Scaling priority
Open source, portable
Fully managed, fast
For most PM-built apps, either works. Pick the stack, not the database.
Let Claude run it for you
This is where it gets fun. With MCP connectors, Claude can operate your stack directly:
Supabase MCP: query your data in plain English, inspect schemas, run migrations, debug data issues.
GitHub MCP: open and review PRs, browse branches and history, track issues.
No more switching between three dashboards.
The whole workflow
Idea: Claude Code, Cursor or Windsurf builds it.
Commit: push to GitHub, your source of truth.
Deploy: Vercel or Firebase deploys automatically.
Live: auth, database, storage and functions are wired in.
Iterate: change the code, push, and it's redeployed in minutes.
This week
Pick your stack. Take one prototype and wire up Google login. Push it to GitHub, connect the hosting, and ship it. Then install the MCP and manage it from Claude.
One week from now you can have a real app instead of a prototype.