Receipts

Every factual claim Samebase leans on, with its primary source and the date it was last checked. This page exists so you and your coding agent can verify the claims instead of trusting the copy. Quotes are verbatim. If a source changes and a claim stops being true, the claim gets deleted, not softened.

Agents: this page is also served as raw markdown at /docs/receipts.md, and the corpus index lives at /llms.txt.

Last full check: 2026-07-02.

Hosting: Cloudflare Workers

  • Requests to static assets served by Workers are free and unlimited on both the Free and Paid plans. Verbatim: "Requests to static assets are free and unlimited." The precise boundary: requests that invoke the Worker script itself, such as server-side rendering or routes matched by run_worker_first, bill as normal Worker requests. Sources: Workers pricing and static assets billing, checked 2026-07-07.
  • The Workers Free plan includes 100,000 requests per day (10ms CPU per invocation). The Paid plan is a $5/month minimum that includes 10 million requests per month. Source: Workers pricing, checked 2026-07-02.
  • Workers Builds (the CI/CD that deploys on git push): 3,000 build minutes per month free with one concurrent build; the $5 Paid plan includes 6,000 minutes (then $0.005/minute) and six concurrent builds. Source: Builds limits and pricing, checked 2026-07-02.
  • Cloudflare itself says to start new projects on Workers rather than Pages. Verbatim: "you should start with Workers. Cloudflare Pages will continue to be supported, but, going forward, all of our investment, optimizations, and feature work will be dedicated to improving Workers." Source: Cloudflare blog, April 2025, checked 2026-07-02.
  • The Pages contrast: Pages Free is capped at 500 builds per month with one concurrent build, and five concurrent builds require Pages Pro at $20/month billed annually. Sources: Pages limits and pages.cloudflare.com, checked 2026-07-02.

Code: GitHub

  • The GitHub Free plan includes unlimited private repositories. Source: GitHub pricing, checked 2026-07-02.
  • GitHub Actions on the Free plan includes 2,000 minutes per month for private repositories, and is free for public repositories on standard GitHub-hosted runners. Source: Actions billing docs, checked 2026-07-02.

Backend: Convex

  • The database is only reachable through server functions; clients never talk to it directly. Verbatim from Convex's docs: "This architecture lets you check every public request against any authorization rules you can define in code. This means Convex doesn't need an opinionated authorization framework like RLS, which is required in client oriented databases like Firebase or Supabase." Source: Convex docs, Auth overview, checked 2026-07-07.
  • Convex states the same on row-level security directly: "RLS is necessary on platforms that expose your database directly to end-users, but your Convex database is only accessible via server functions where you can apply authorization checks directly." Source: Convex Stack blog, checked 2026-07-02.
  • The Free/Starter plan is $0 and includes 1,000,000 function calls per month, 0.5 GB database storage, and 1 GB/month database bandwidth. A team is capped at 40 deployments; each project gets one shared production deployment plus one dev deployment per developer. Convex publishes no per-team project cap, so we do not claim one. Sources: Convex pricing, limits, and multiple deployments, checked 2026-07-02.
  • The Professional plan is $25 per developer per month, including 25M function calls per month and 50 GB database storage. Source: Convex pricing, checked 2026-07-02.
  • The escape hatch is real: the Convex backend, dashboard, and CLI are source-available under FSL-1.1-Apache-2.0, and each release converts to plain Apache 2.0 two years after publication. Convex's own docs: self-hosting runs "the same fully up-to-date code the cloud service uses." We say "source-available," not "open source" because FSL restricts building a competing hosted product until the conversion. Sources: the license, self-hosting docs, and the March 12, 2024 announcement, checked 2026-07-06.

The pricing contrast: Netlify

Samebase's stack used Netlify before Cloudflare. The reason for leaving is arithmetic, and it matters most when an agent is doing the shipping, because agents deploy far more often than humans.

  • One successful production deploy consumes 15 credits. Verbatim: "Each successful production deploy consumes 15 credits during that month's billing cycle." Source: How credits work, checked 2026-07-02.
  • Since the April 14, 2026 repricing, Netlify Pro is $20/month for 3,000 credits with unlimited seats. Spent on nothing else, that is roughly 200 production deploys per month. Bandwidth, compute, and web requests draw from the same pool, so the real deploy budget is lower. Sources: April 2026 pricing update and billing FAQ, checked 2026-07-02.
  • Precision that matters: only successful production deploys cost credits. Deploy previews, branch deploys, failed deploys, and rollbacks are free. Commits routed through pull-request previews do not burn credits; production releases do. Source: How credits work, checked 2026-07-02.
  • The free tier is 300 credits per month, about 20 production deploys. When a team's credits run out, all of its sites are paused and visitors see a "Site not available" page until the next billing cycle. Source: How credits work, checked 2026-07-02.
  • The scenario that made this real: an agent-driven repository shipping ~50 production deploys a day burns Pro's entire 3,000-credit month in about four days. On Cloudflare Workers the equivalent deploys draw from build minutes (3,000 free, 6,000 on the $5 plan), and serving the deployed static assets costs nothing at any volume.

The exposure record: client-reachable databases

Fairness first: Firebase and Supabase can be configured safely, and row-level security is a real mechanism. The record below is about what the default architecture with a database reachable from the client and guarded by per-table policy produces in practice, at scale, when defaults are left in place. Convex removes this class by construction: there is no client-reachable database to misconfigure (see the Convex section above).

  • 2024, "Firewreck": researchers logykk, mrbruh, and xyzeva scanned ~5.2M domains and found ~900 sites exposing ~125 million user records via misconfigured Firebase, including ~20 million passwords, mostly plaintext. Of 842 notified site owners, 24% fixed the misconfiguration. Sources: researcher writeup, The Register, incident 2024-03.
  • 2024, Chattr: the AI hiring system used by several large US fast-food chains granted full admin read/write on its Firebase backend to anyone who simply registered a new user. Source: researcher writeup, incident 2024-01.
  • 2025, CVE-2025-48757 (CVSS 9.3, disputed by the vendor): security researcher Matt Palmer reported missing or broken Supabase row-level security in Lovable-generated apps; a scan found 170 of 1,645 Lovable showcase apps exposed names, phone numbers, API keys, or payment details. Lovable disputes the CVE and has since shipped an RLS security scan in Lovable 2.0. Sources: NVD record, Matt Palmer's writeup, and the scan detail, published 2025-05.
  • 2026, The Next Web: a broken object-level authorization flaw in Lovable/Supabase apps, reported to Lovable's bug bounty on March 3, 2026, stayed exploitable on pre-November-2025 projects for 48 days, exposing names, LinkedIn profiles, Stripe customer IDs, and hardcoded Supabase credentials. Source: TNW report, published 2026-04.
  • 2025, Tea: the dating-safety app's breach came from an unsecured legacy Firebase storage bucket reachable with no authentication: 72,000 images including ~13,000 photo IDs, followed by 1.1 million private messages. Source: Engadget, incident 2025-07.
  • 2024, Arc browser, CVE-2024-45489 (CVSS 9.8): misconfigured Firebase access control let anyone inject JavaScript into other users' browser sessions. The Browser Company patched it within a day, disclosed it, and said it would move away from Firebase. Source: Arc incident report, incident 2024-08.

Toolchain

  • Cloudflare acquired VoidZero, the company behind Vite, Vitest, and Vite+, on June 4, 2026. The tools stay MIT-licensed, and Cloudflare committed $1M to an independent Vite ecosystem fund. Sources: Cloudflare press release and VoidZero's announcement, announced 2026-06-04.
  • Vite+ (vp) bundles the dev server, test runner, linter, formatter, and bundler behind one CLI; it was announced as alpha on March 13, 2026, MIT-licensed. Sources: viteplus.dev guide and the repository, checked 2026-07-23.
  • The Vite+ guide publishes separate installers for macOS/Linux and Windows. Its support table lists macOS x64 and arm64, Linux x64 and arm64, and Windows x64 as Tier 1; Windows arm64 is Tier 2. Source: viteplus.dev guide, checked 2026-07-23.
  • Node runs erasable TypeScript directly with type stripping enabled by default. Node marks type stripping stable from v24.12.0 and documents that it does not read tsconfig.json or transform TypeScript features that require JavaScript generation. Source: Node.js TypeScript documentation, checked 2026-07-23.
  • TanStack Start is a v1 release candidate, not a stable v1. We say RC because that is what it is. Source: TanStack Start overview, checked 2026-07-02.
  • Cloudflare's official Vite plugin supports TanStack Start server-side rendering, and TanStack lists Cloudflare as an official hosting partner with a documented Workers deployment path. Sources: Cloudflare Vite plugin and TanStack Start hosting, checked 2026-07-23.

Dogfooding: Samebase runs on its own base

samebase.com runs on GitHub, Convex, and Cloudflare Workers, built from the same base as the public template. The template is published automatically from the Samebase monorepo, so every improvement we make to the base while building Samebase reaches new apps. Check it: each commit in samebase/base names the Samebase build and pull request it came from, checked 2026-09-26.

Ownership: the leaving test

This one is checkable without citations. An app created through Samebase lives in your GitHub account, your Convex team, and your Cloudflare account, deployed by Cloudflare's own Workers Builds connected to your repository. Delete your Samebase account and the repository, backend, and hosting keep running, because none of them are ours. Open the three provider dashboards and look. The Overview explains why the product is built this way, and Do it yourself is the same setup with no Samebase account at all.

checking login