Beginner guides.
No background assumed. What a database, a domain or an environment variable actually is, and how to get an app you built with AI online and keep it there.
131 posts · page 3 of 5
Supabase vs Firebase: Which Backend for Your First App?
Lovable and Bolt lean on Supabase; many tutorials use Firebase. How the two backends compare — database model, auth, security rules, real-time, pricing shape, and lock-in — and which one fits the app you're building.
Supabase Row-Level Security Explained (for People Who Didn't Write the Policies)
If your app talks to Supabase from the browser, row-level security is the only thing standing between your users' data and anyone who opens the developer tools. What RLS is, how to read the policies your AI tool wrote, the four mistakes that leave data exposed, and how to test it yourself.
Stuck in an AI Fix Loop? How to Break Out
You ask the AI to fix a bug. It says it's fixed. It isn't. Three rounds later, two other things are broken too. Why AI tools get stuck in loops, how to recognise one early, and a step-by-step way out that works far better than asking again.
Static vs Dynamic Websites: What's the Difference?
A static site is the same files for everyone; a dynamic site builds pages per request. What each means, where single-page apps and server rendering fit, why it matters for hosting, speed, SEO, and cost — and how to tell which one your AI tool built.
SSH Keys Explained: Set Them Up Once, Properly
SSH keys are how you log into servers and push to GitHub without passwords. What the two halves of a key pair do, how to create a modern one, using ssh-agent and a config file so you stop retyping things, and the habits that matter: passphrases, one key per device, never sharing a private key.
SQL vs NoSQL: Which Database Should a Beginner Choose?
Postgres or MongoDB? Supabase or Firebase? The real difference between SQL and NoSQL databases, what 'relational' and 'document' mean, where each shines, the myths about scale and flexibility, and why most new apps should start with SQL.
SQL Injection Explained: The Classic Attack and the One-Line Fix
SQL injection lets an attacker rewrite your database queries by typing into a form. How it works with a simple example, what damage it can do, why parameterized queries and ORMs prevent it, the places AI-generated code still gets it wrong, and how to check your app.
SQL for Beginners: The Queries You Need to Understand Your App's Data
You don't need to become a database expert to read your own data. The handful of SQL queries — SELECT, WHERE, ORDER BY, COUNT, JOIN — that let you answer real questions about your app, plus the two commands to be very careful with.
Social Preview Images: Make Your Links Look Good When Shared
When someone shares your app's link on Slack, X, LinkedIn, or iMessage, the preview card comes from Open Graph tags. What they are, the exact tags to add, the right image size, how to generate images per page in Next.js, how to test, and why your preview isn't updating.
"Sign in with Google" Explained: OAuth for Beginners
Social login lets users skip creating a password. How 'Sign in with Google' (and GitHub, Apple, Microsoft) actually works, what OAuth and OpenID Connect are, what redirect URIs and client secrets are, and why it breaks when you move from localhost to your real domain.
Should You Still Learn to Code If AI Writes It?
AI can now build working apps from a description, so is learning to code still worth it? An honest answer: what AI has genuinely made unnecessary, the skills that matter more than ever, and a practical learning path for people who build with AI.
SEO Basics for Your App: How to Get Found on Google
A beautiful app that search engines can't read is invisible. The fundamentals that matter for a small app or product site — titles and descriptions, crawlable pages, a sitemap, speed, and link previews — plus the single-page-app problem that hides many AI-built sites from Google.
How to Send Email From Your App Without Landing in Spam
Password resets, receipts, and sign-up confirmations that land in spam — or never arrive — are one of the most common launch-week problems. What SPF, DKIM, and DMARC actually do, how to set them up for your domain, and why your app should never send mail itself.
Semantic Versioning Explained: What 2.4.1 Actually Means
Version numbers like 2.4.1 follow a convention: major.minor.patch. What each number promises, what ^ and ~ mean in package.json, why '0.x' versions are different, how lock files fit in, and how to version your own app or library.
Why Does My App Look Broken on My Phone? Responsive Design Basics
It looks perfect on your laptop and falls apart on a phone: text too small, buttons off the edge, a page that scrolls sideways. What responsive design is, the five most common causes of broken mobile layouts, how to test properly, and what to ask your AI tool.
Replit Alternatives in 2026: What to Use Depending on Why You're Leaving
Replit bundles an AI agent, an editor, hosting, and a database. People leave for different reasons — cost, control, the agent, or outgrowing the platform — and each reason points to a different alternative. An honest guide to picking the right one.
Regular Expressions for Beginners: Reading Regex Without Panic
^[\w.+-]+@\w+\.\w{2,}$ looks like a cat walked on the keyboard. It's a regular expression, and AI tools write them constantly. The dozen symbols that cover most regex, how to read one piece by piece, how to test them, and when not to use regex at all.
Refactoring AI-Generated Code: Cleaning Up Without Breaking Things
Refactoring improves code's structure without changing what it does. When to refactor an AI-built app, how to do it safely with tests and small steps, the most valuable clean-ups, and prompts that stop the AI from rewriting everything.
What Is an IP Address and a Port? localhost:3000 Explained
Every network connection goes to an address and a port — the building and the apartment number. What IP addresses and ports are, the common port numbers, what 0.0.0.0 means, why 'address already in use' happens, and why your app works on your laptop but not on the server.
How to Plan Your First App Before You Ask AI to Build It
Thirty minutes of planning saves days of AI going in circles. How to define the one problem your app solves, cut it down to a first version, describe your users' journeys and your data, and turn it all into a brief an AI tool can build from.
Password Hashing Explained: Why You Never Store Passwords
A well-built app doesn't know your password — it stores a hash. What hashing is, why fast hashes like MD5 and SHA-256 are wrong for passwords, what salts do, why bcrypt and Argon2 exist, and how to check that your AI-built app got it right.
Open Source Licences Explained for People Building Apps
Your app is built on hundreds of open-source packages, each with a licence that says what you may do with it. What open source means, the difference between permissive licences like MIT and 'copyleft' ones like GPL and AGPL, and how to check your app isn't using something it shouldn't.
What Are npm and package.json? A Beginner's Guide
Every JavaScript project has a package.json and a giant node_modules folder, and AI tools run npm commands constantly. What packages are, what npm install actually does, what the lockfile is for, and the handful of commands and warnings you need to understand.
How to Move a Replit App to Your Own Hosting
Replit is a great place to build and a reasonable place to host — until the bill, the limits, or the lock-in start to matter. How to get your code and data out, where to put them, and the Replit-specific things that break on the way.