
Onboardbase
@onboardbase
Followers
407
Following
762
Media
140
Statuses
972
The fastest secrets management for dev teams to ship securely. Creators of https://t.co/y7vu5LYbLm
United States
Joined November 2020
I can't believe Emily is managing secrets with a sheet of paper. Jack had to type it all in to start the project on his first day šš¤¦š½
0
2
2
One of the most essential things vibe coders need is a Store or Vault. A secure and efficient way to store and retrieve secrets. A straightforward API providing an encrypted key-value store for your customersā secrets. Use Cases 1ļøā£ API keys - Secure your customer API keys. 2ļøā£
0
2
7
So Cursor uploads .env file with secrets despite .gitignore and .cursorignore. This is one of the biggest concerns I've seen with Cursor. I'm not sure using Cursor with repositories with secrets or personal information is safe. It's easy to fix this by using something like
0
1
2
Vibe Code all you want. Onboardbase + Securelog keep it safe. 30 mins to bulletproof your SaaS. Go to https://t.co/IWp1GV5gdd & https://t.co/6rhkQdk8Moāthen show us your app. Million Kids, Million Wins. š 8/8
0
2
2
A million vibes, a million shots. Donāt let yours crash. Try this, build that wild idea, and flex it. Whatās your project? Drop it belowāletās hype it up! 7/8
1
2
2
Real talk: Let's zoom out for a bit. Zoom got roasted for weak security, fixed it, and won. You can, tooāwithout the drama. https://t.co/IWp1GV5gdd + https://t.co/6rhkQdk8Mo = free trials, no excuses. Protect your summer hit now. 6/8
1
2
2
How to lock it down: 1ļøā£ Deploy to Vercel (youāre already a pro) 2ļøā£ Onboardbase for keys (10 mins) 3ļøā£ Securelog for sanitization (10 mins) 30 mins totalāback to vibing, but untouchable. 5/8
1
2
2
@secureloghq = your growth bouncer. 1ļøā£ Drop the SDK in NextJS 2ļøā£ Spot and sanitize sketchy logins, secrets, agents, conversations 3ļøā£ Scale from 50 to 5k users Itās your audit vibeākeeps the app tight when it blows up. 4/8
1
2
3
@onboardbase = your key management wingman. 1ļøā£ npm i -g @onboardbase/cli 2ļøā£ onboardbase setup 3ļøā£ Pull keys, done. 5 mins, Multilayer encrypted, Vercel-ready. Keep coding, stay safe. 3/8
1
2
4
Why care? Your appās a bangerāmeme generator, chat tool, flight simulator, boat cruise, whatever. But unprotected Supabase/Stripe keys = hacked in 5 mins. Trust gone, vibes dead. Securityās not a buzzkillāitās your shield. 2/8
1
2
2
A million kids are building a million SaaS ideas with v0,bolt,cursor,replit,etc. Vibe coding in the purest sense. But hereās the tea: your weekend projectās a sitting duck without security Donāt kill the vibeāsave it with Onboardbase & Securelog. Letās break it down. š§µš 1/8
1
4
13
Envkit - Auth or SSO for Env is coming along nicely. Here are some of the things to expect from it. ā
EnvKitāAn <Env/> component to replace your default project/repo start page. ā
Missing envsāIf you don't know the required envs, you will see this page, where you can add
3
2
6
I have been thinking about this a lot. š
An <env /> component to replace your default project start page. ā
If you don't know the required envs, you see this page where you can put the env or connect with an env provider. ā
Customize the page's look, no more default starter
1
3
4
⨠Securelog is very good for AI agents. It's a plug-and-play "security brain" that agents can call upon. It can handle everything from sanitizing training data to securing runtime interactions. Apply or create "Custom Rules," and it works; no code changes are needed.
0
2
3
Terraform stands out as one of the most reliable Infrastructure as Code (IaC) tools to provision and manage cloud resources: just write a few lines in a Terraform configuration file and spin up cloud services in minutes in any cloud provider. But this ease of use also brings
0
1
1
š„ Custom Rules on Securelog. Rules can be anything from SSN, Credit Card, Phone number, DNA sequence, and API Token. Basically, anything you consider a secret. You can parse this directly into Securelog, and it will redact it quickly. āŗļø Link to try it out below šš½
1
2
2
I think https://t.co/IWp1GV5gdd works well hereāespecially the yaml file. You can add your secrets but still be able to override them for local use cases specific to you.
0
2
2
even with the cold, still a fun turnout for devtools toronto #2 we had toolsmiths & hackers last night from @Stellate @github @Tempo_Labs @onboardbase @ShopifyEng @vltpkg @SST_dev @getsentry @wearedmno @noti_api and more š big thanks to our sponsors @rootlyhq and @getsentry
šØš¦ Due to popular demand, DevTools Toronto is returning on Wednesday, Dec 4th! Now with an even more impressive slate of VIP guests. RSVP here:
2
4
24