# What is an AI app readiness check, and what should it cover before launch?

**Answer:** An AI app readiness check is a short pass before launch that confirms what a working demo cannot show: who can read and change each table, where secret keys live, which env vars each environment sets, where auth emails send people, whether payment webhooks are verified, and how you recover when something breaks. For a Vercel + Supabase app that means row level security, keys, env vars, auth redirect URLs, Stripe webhooks, storage access rules, backups, error monitoring and rollback, checked in the repo and on the live project.

## Why this matters

A demo proves the happy path works for you, signed in, with test data. Launch adds strangers, live keys and a production database. Supabase, Vercel, Next.js and Stripe each publish a checklist for going to production, and many of their steps sit outside the code an agent writes: dashboard settings, live webhook endpoints, backups and rollback. The items below come from those docs, read on 2026-10-01.

## What a readiness check covers on Vercel + Supabase

- Data access: every table in an exposed schema has row level security on and a policy for each operation the app needs. Supabase warns that such a table without RLS is readable and writable by any role with a grant on it. Confirm it on the live project with the Security Advisor.
- Test as a stranger: on the deployed app, try to read, change and delete user A's rows as user B and while signed out. Reading a policy shows its condition, not who it lets in.
- Secret keys: the Supabase secret key bypasses row level security, so it stays in server code, out of the browser and out of source control. Next.js inlines NEXT_PUBLIC_ variables into the browser bundle at build time, so only public values get that prefix.
- Server checks: verify authentication and authorization inside each Next.js Server Action, not only in Proxy, a layout or a page, as the Next.js production checklist asks.
- Env vars: set each one in every Vercel environment that needs it (Production, Preview, Development) and redeploy after a change, since changes apply only to new deployments. Keep .env files in .gitignore.
- Auth redirect URLs: change the Supabase Site URL from localhost to your production URL, which Supabase calls critical for email confirmations and password resets, and use exact redirect paths in production.
- Payments: verify Stripe webhook signatures over the raw request body with the endpoint's signing secret. Stripe's go-live checklist also asks you to register live webhook endpoints, handle duplicate and out of order events, and rotate API keys saved outside your codebase during development.
- Storage: Supabase Storage allows no uploads without RLS policies on storage.objects; scope yours to each user's own files.
- Backups: Supabase backs up Pro, Team and Enterprise projects daily. Free plan backups cannot be downloaded, so export with supabase db dump. Database backups do not include Storage files.
- Errors: know where production errors show up before users report them. Vercel Observability finds production errors and 500s, and Next.js recommends custom error and 404 pages.
- Rollback: Vercel's production checklist asks for an incident response plan that includes rollback strategies. Instant Rollback restores a previous production deployment (on Hobby, only the one before it), and it keeps that build's env vars, not your latest changes.
- Accounts: turn on multi-factor authentication for your Supabase account, and for GitHub if you sign in with it, as Supabase's production checklist asks.

## Optional repo check

For AI-built Vercel + Supabase apps, `npx -y viberaven@1.5.3 check` is a local repository check that covers part of this list from files: public tables that no migration puts under row level security, policies whose condition is a bare `true`, a Supabase service role key in client code, env vars the code reads that `.env.example` does not list (it cannot see Vercel settings), and Stripe webhook handlers that skip the signature check over the raw body. It is advice, not a gate, and a repository check, not a live database test: it does not connect to Supabase, Vercel or Stripe, so auth URLs, storage, backups, monitoring and rollback stay with you, and a clean result does not prove the app is secure. It exits with code 1 when it finds a blocker and writes a `.viberaven` folder that it does not add to `.gitignore`.

## FAQ

### Is a readiness check the same as a security audit?

No. A readiness check confirms that known launch settings and rules are in place. An audit or penetration test looks for flaws nobody listed. Supabase's production checklist also asks you to consider how you might abuse your own service as an attacker.

### Can a tool run the whole check?

Part of it. A repo check reads migrations, code and env templates before deploy, and the Supabase Security Advisor reads the live database. The Site URL, live webhook endpoints, backups and rollback live in the Supabase, Stripe and Vercel dashboards, so a person still has to look.

### When should I run it?

Before the first real users see the app, and again after a change to the schema, auth settings, env vars or payments. Vercel applies env var changes only to new deployments, so check after the redeploy.

## Sources

Read on 2026-10-01.

- Supabase, Production Checklist: https://supabase.com/docs/guides/deployment/going-into-prod
- Supabase, Row Level Security: https://supabase.com/docs/guides/database/postgres/row-level-security
- Supabase, Advisors: https://supabase.com/docs/guides/database/database-advisors
- Supabase, API keys: https://supabase.com/docs/guides/getting-started/api-keys
- Supabase, Redirect URLs: https://supabase.com/docs/guides/auth/redirect-urls
- Supabase, Storage Access Control: https://supabase.com/docs/guides/storage/security/access-control
- Supabase, Database Backups: https://supabase.com/docs/guides/platform/backups
- Next.js, Production checklist: https://nextjs.org/docs/app/guides/production-checklist
- Next.js, Environment variables: https://nextjs.org/docs/app/guides/environment-variables
- Vercel, Production checklist: https://vercel.com/docs/production-checklist
- Vercel, Environment variables: https://vercel.com/docs/environment-variables
- Vercel, Observability: https://vercel.com/docs/observability
- Vercel, Instant Rollback: https://vercel.com/docs/instant-rollback
- Stripe, Go-live checklist: https://docs.stripe.com/get-started/checklist/go-live
- Stripe, Receive events in your webhook endpoint: https://docs.stripe.com/webhooks

HTML page: https://viberaven.dev/ai-app-readiness-check
