"Use the Platform" Is the Best Question to Ask an AI App Builder
A thread asking why more developers don't "use the platform" went around again this week. The web version of that argument is old and still correct: before you install a library, check whether the browser already does the thing. <dialog> instead of a modal package. <details> instead of an accordion component. Native form validation instead of 400 lines of state.
That same question is the most useful thing you can ask an AI app builder, and almost nobody asks it.
What the builders actually generate
Ask Lovable for login and it writes you login. A sign-in page, a sign-up page, a forgot-password route, session handling, Supabase calls, all as files in your project. Bolt and v0 work the same way. It's genuinely impressive and it demos beautifully.
Then it's yours. Password reset is now code you own, in a repo you weren't planning to read, written by a model that will cheerfully rewrite it the next time you ask for something nearby. Rate limiting on the reset endpoint, hashing parameters, lockout after repeated failures: that's the part that gets skipped, and OWASP has strong opinions about all of it.
What "use the platform" looks like inside a builder
On DontCode, accounts are not generated. Email and password, magic links, Google, Kakao, GitHub, Apple, MFA, sessions, roles, the users table: platform services, there from day one on every project, never produced by a build. Which also means they never cost credits.
Password recovery is the clearest example. There is no forgot-password page in a DontCode app and there doesn't need to be one. The sign-in form itself flips to a recovery step (email, then a six digit code, then a new password) and flips back. A bot check on sign-in, sign-up and reset is one switch. So are session length, remember-me, password rules, and two-step sign-in. Roles arrive in your app code as claims on the session.
Payments go the same way. KakaoPay, Toss, NaverPay, PayPal: merchant onboarding, signing keys and webhook callbacks are ours. No keys sitting in your app.
The tradeoff, honestly
Platform-owned means you can't fork it. If your product needs a sign-in flow with a bespoke five step identity check, generated code is the right answer and we're the wrong tool. Most apps aren't that. Most apps need the boring parts to be correct forever without anyone ever opening them.
A test you can run in ten minutes
Pick any AI builder. Ask it to add password reset. Then ask for something unrelated, a pricing page, say. Check whether the auth files changed.
If they did, you have a surface that can regress every time the model touches the project. That's the dimension worth comparing builders on: not how fast version one appears, but how much of your app the AI is able to break on a random Tuesday.
The full list of what ships as platform instead of generated code is at /en/docs/features, and you can poke at DontCode without talking to anyone. More posts over on the blog.