onboardbase Profile Banner
Onboardbase Profile
Onboardbase

@onboardbase

Followers
407
Following
762
Media
140
Statuses
972

The fastest secrets management for dev teams to ship securely. Creators of https://t.co/y7vu5LYbLm

United States
Joined November 2020
Don't wanna be here? Send us removal request.
@dantelex
Dante Lex
6 months
I can't believe Emily is managing secrets with a sheet of paper. Jack had to type it all in to start the project on his first day šŸ˜‚šŸ¤¦šŸ½
Tweet media one
0
2
2
@dantelex
Dante Lex
6 months
One of the most essential things vibe coders need is a Store or Vault. A secure and efficient way to store and retrieve secrets. A straightforward API providing an encrypted key-value store for your customers’ secrets. Use Cases 1ļøāƒ£ API keys - Secure your customer API keys. 2ļøāƒ£
0
2
7
@dantelex
Dante Lex
6 months
So Cursor uploads .env file with secrets despite .gitignore and .cursorignore. This is one of the biggest concerns I've seen with Cursor. I'm not sure using Cursor with repositories with secrets or personal information is safe. It's easy to fix this by using something like
0
1
2
@dantelex
Dante Lex
6 months
Vibe Code all you want. Onboardbase + Securelog keep it safe. 30 mins to bulletproof your SaaS. Go to https://t.co/IWp1GV5gdd & https://t.co/6rhkQdk8Mo—then show us your app. Million Kids, Million Wins. šŸš€ 8/8
Tweet media one
0
2
2
@dantelex
Dante Lex
6 months
A million vibes, a million shots. Don’t let yours crash. Try this, build that wild idea, and flex it. What’s your project? Drop it below—let’s hype it up! 7/8
1
2
2
@dantelex
Dante Lex
6 months
Real talk: Let's zoom out for a bit. Zoom got roasted for weak security, fixed it, and won. You can, too—without the drama. https://t.co/IWp1GV5gdd + https://t.co/6rhkQdk8Mo = free trials, no excuses. Protect your summer hit now. 6/8
1
2
2
@dantelex
Dante Lex
6 months
How to lock it down: 1ļøāƒ£ Deploy to Vercel (you’re already a pro) 2ļøāƒ£ Onboardbase for keys (10 mins) 3ļøāƒ£ Securelog for sanitization (10 mins) 30 mins total—back to vibing, but untouchable. 5/8
1
2
2
@dantelex
Dante Lex
6 months
@secureloghq = your growth bouncer. 1ļøāƒ£ Drop the SDK in NextJS 2ļøāƒ£ Spot and sanitize sketchy logins, secrets, agents, conversations 3ļøāƒ£ Scale from 50 to 5k users It’s your audit vibe—keeps the app tight when it blows up. 4/8
Tweet media one
1
2
3
@dantelex
Dante Lex
6 months
@onboardbase = your key management wingman. 1ļøāƒ£ npm i -g @onboardbase/cli 2ļøāƒ£ onboardbase setup 3ļøāƒ£ Pull keys, done. 5 mins, Multilayer encrypted, Vercel-ready. Keep coding, stay safe. 3/8
Tweet media one
1
2
4
@dantelex
Dante Lex
6 months
Why care? Your app’s a banger—meme generator, chat tool, flight simulator, boat cruise, whatever. But unprotected Supabase/Stripe keys = hacked in 5 mins. Trust gone, vibes dead. Security’s not a buzzkill—it’s your shield. 2/8
1
2
2
@dantelex
Dante Lex
6 months
A million kids are building a million SaaS ideas with v0,bolt,cursor,replit,etc. Vibe coding in the purest sense. But here’s the tea: your weekend project’s a sitting duck without security Don’t kill the vibe—save it with Onboardbase & Securelog. Let’s break it down. šŸ§µšŸ‘‡ 1/8
1
4
13
@dantelex
Dante Lex
6 months
Envkit - Auth or SSO for Env is coming along nicely. Here are some of the things to expect from it. āœ… EnvKit—An <Env/> component to replace your default project/repo start page. āœ… Missing envs—If you don't know the required envs, you will see this page, where you can add
3
2
6
@dantelex
Dante Lex
7 months
I have been thinking about this a lot. šŸ˜… An <env /> component to replace your default project start page. āœ… If you don't know the required envs, you see this page where you can put the env or connect with an env provider. āœ… Customize the page's look, no more default starter
Tweet media one
1
3
4
@dantelex
Dante Lex
7 months
✨ Securelog is very good for AI agents. It's a plug-and-play "security brain" that agents can call upon. It can handle everything from sanitizing training data to securing runtime interactions. Apply or create "Custom Rules," and it works; no code changes are needed.
Tweet media one
0
2
3
@dantelex
Dante Lex
7 months
Terraform stands out as one of the most reliable Infrastructure as Code (IaC) tools to provision and manage cloud resources: just write a few lines in a Terraform configuration file and spin up cloud services in minutes in any cloud provider. But this ease of use also brings
0
1
1
@dantelex
Dante Lex
7 months
Tweet media one
0
1
1
@dantelex
Dante Lex
7 months
šŸ”„ Custom Rules on Securelog. Rules can be anything from SSN, Credit Card, Phone number, DNA sequence, and API Token. Basically, anything you consider a secret. You can parse this directly into Securelog, and it will redact it quickly. ā˜ŗļø Link to try it out below šŸ‘‡šŸ½
1
2
2
@isamlambert
Sam Lambert
7 months
4
2
12
@dantelex
Dante Lex
9 months
I think https://t.co/IWp1GV5gdd works well here—especially the yaml file. You can add your secrets but still be able to override them for local use cases specific to you.
Tweet media one
@wesbos
Wes Bos
9 months
Are you sticking API endpoints in environmental variables? Or flipping them in config like this?
Tweet media one
0
2
2
@bentlegen
Ben Vinegar
9 months
even with the cold, still a fun turnout for devtools toronto #2 we had toolsmiths & hackers last night from @Stellate @github @Tempo_Labs @onboardbase @ShopifyEng @vltpkg @SST_dev @getsentry @wearedmno @noti_api and more šŸ™ big thanks to our sponsors @rootlyhq and @getsentry
@bentlegen
Ben Vinegar
10 months
šŸ‡ØšŸ‡¦ Due to popular demand, DevTools Toronto is returning on Wednesday, Dec 4th! Now with an even more impressive slate of VIP guests. RSVP here:
2
4
24