Skip to content
Breezy Sites, Home

AI app launch

Take Your Replit App to Production

Replit Agent builds fast, and it builds a real backend while it's at it: a database, an auth flow, server endpoints it wrote itself. That's different from a static prototype, and it's exactly why a production launch needs a security review, not just a custom domain.

Is Your Replit App Ready for Production?

Replit Agent apps ship with a real backend: a live database, working auth, and server code it wrote itself. That backend needs a security review before real customers touch it, not just a custom domain. Launch Essentials ($950 fixed) covers custom domain and DNS setup. Production Hardening ($2,950 fixed) adds a security pass, auth debugging, and baseline SEO.

How do you set up a custom domain on a Replit app?

A Replit custom domain attaches to a published Deployment, with an A record and a TXT record at your registrar (Replit docs: custom domains, checked 10 October 2026). The mechanics are short; the docs do not cover whether the backend behind the domain is safe to expose.

  1. Publish a Deployment first

    The Domains tab appears after a successful Deployment.

  2. Add your domain in the Domains tab

    Guided setup, or copy the records by hand.

  3. Add the A record and the TXT record

    The A record points at Replit; the replit-verify TXT validates the certificate.

  4. Leave the TXT record in DNS

    Removing it breaks certificate renewal.

  5. Run a security pass on the backend

    Before real traffic hits it.

What does Replit document for domains, deployments, and secrets?

The setup is documented and short; the risk sits in the code behind it. Linked facts come from Replit documentation, checked 10 October 2026; unlinked cells are our description.

What the docs say

DNS records
Custom domains need an A record and a replit-verify TXT record. Replit supports only A records, so AAAA records conflict (Replit docs: custom domains).
TXT record
The TXT record must stay in DNS for the life of the domain. Removing it makes the next certificate renewal fail (Replit docs: custom domains).
Cloudflare and www
Set Cloudflare records to DNS only, since proxy mode interferes with SSL provisioning. Each subdomain, including www, needs its own records and TXT entry (Replit docs: custom domains).
Deployment type
Autoscale adjusts resources to usage, Reserved VM gives a consistent amount of compute that runs continuously, Static serves sites that do not change with user input, and Scheduled runs at times you choose (Replit docs: deployments).
Secrets
Secrets are encrypted at rest, exposed to code as environment variables, and available on every deployment type except Static. Multiplayer collaborators can see values (Replit docs: secrets).

What it means in practice

DNS records
A domain that will not verify usually has a leftover AAAA record or a second A record pointing elsewhere.
TXT record
The site works for months, then goes down at renewal. Treat the record as permanent, not as setup scaffolding.
Cloudflare and www
Connecting the apex does not cover www. Add both, and redirect one to the other.
Deployment type
An app with a database and auth is not a Static deployment. Autoscale suits variable traffic, Reserved VM suits an always-on server.
Secrets
Secrets are only as private as the people with access. Rotate any key a former collaborator could read, and keep keys out of code and chat.

Sources, checked 10 October 2026

Is your Replit Agent app safe for production?

A Replit Agent app is not safe for production by default. The failure modes are specific and repeatable, and none show up by clicking through the app.

  • SQL built by string concatenation instead of parameterized queries
  • API routes with no auth check where one's needed
  • Secrets committed into the repl's file history
  • A repl that's public, or was, with credentials in its version history
  • Error responses leaking stack traces or raw query text

A security review reads the code, not the UI.

A software engineer reviewing backend code for security issues

Should you stay on Replit Deployments or move off-platform?

Replit offers Autoscale and Reserved VM deployments for running an app in production.

In our launch work, Lovable and Bolt apps usually lean on a hosted backend such as Supabase, while a Replit app's backend runs on Replit's own compute. Moving off means migrating a real server, on the website migration services page, or building fresh on AWS infrastructure.

Staying on Replit Deployments compared with moving off-platform
Factor Stay on Replit Move off-platform
CostBilled by Replit under the deployment type you choose: Autoscale, Reserved VM, Static, or Scheduled (Replit docs: deployments)Priced by the infrastructure you run
ControlReplit manages the infrastructure and adjusts resources to usage on Autoscale (Replit docs: deployments)You control compute and networking
EffortNone, no migrationMigrating a real backend server
Best forVariable or moderate trafficCompliance, scale, custom observability

What's on a production hardening checklist for an AI-generated backend?

None of this is Replit-specific; it's what any AI-generated backend needs before holding real user data.

Every query is parameterized

Not string-built.

Every data-touching route checks authorization

Confirmed on the server side.

Rotate any exposed secret

Anything that ever appeared in a public repl, commit, or AI chat log.

Secrets live in the secrets manager

Not hardcoded config.

Rate limiting on public endpoints

Added where it was missing.

Error responses are checked

Don't leak stack traces or query text.

This is the core of Production Hardening ($2,950 fixed). Production-safe AI management covers the ongoing version once the app is live.

What does Replit Agent typically get wrong with databases, auth, and secrets?

Three patterns recur. Each is fixable alone, and the review is finding all three before someone else does.

What Replit Agent typically gets wrong with databases, auth, and secrets
Area What typically goes wrong
Database accessUser input gets concatenated into a query string, the textbook SQL injection setup
Auth checksWritten for the happy path, never enforced server-side, so a direct API call succeeds with no session
SecretsCorrect today, but an earlier version left in git history or a repl that was public before it was locked down

The pattern Replit Agent commonly generates for a lookup endpoint

Real before and after:

javascript

// Before: string-concatenated query, injectable
const user = await db.query(
  `SELECT * FROM users WHERE email = '${req.body.email}'`
);

// After: parameterized query
const user = await db.query(
  'SELECT * FROM users WHERE email = ?',
  [req.body.email]
);

Built on Lovable, v0, or Bolt Instead of Replit?

Going deeper

Replit to production questions

Is Replit safe for production apps?

Replit's hosting offers Autoscale and Reserved VM deployments for running apps in production. The risk isn't the platform, it's the code Replit Agent generated for you, which usually hasn't had a security review, unlike Lovable or Bolt's largely static output.

How do I deploy a Replit app with a custom domain?

Publish a Deployment, add the domain in the Domains tab, create the A record and the replit-verify TXT record, and wait for propagation, which Replit says is typically minutes to 48 hours (Replit docs: custom domains). Keep the TXT record in place, because removing it breaks certificate renewal. The security review is separate and matters more for apps holding real user data.

Why does my Replit custom domain fail to verify?

Replit's docs list conflicting DNS records (more than one A record, or AAAA records), Cloudflare proxy mode, a missing or modified TXT record, and propagation delays (Replit docs: custom domains). Remove the conflicting records, set Cloudflare to DNS only, and re-check the TXT value.

What's the difference between Replit Autoscale and Reserved VM?

Replit's docs describe Autoscale as automatically adjusting resources to your app's usage, and Reserved VM as a consistent amount of computing resources that runs continuously (Replit docs: deployments). Autoscale fits variable traffic; Reserved VM fits an app that should always be running.

Does Replit Agent write secure code by default?

In our launch work, no: generated code is built to make a feature work, not to be hardened, which is why a review reads the code rather than the UI.

My repl was public at some point. Does that matter now?

Yes, a repl that was ever public matters: treat any API key, database credential, or token that appeared in it, or in its version history, as exposed and rotate it.

Should I move my Replit app off Replit entirely?

Only if you need infrastructure control, compliance requirements, or cost structure that Replit Deployments doesn't offer, at which point AWS infrastructure is usually where it lands. Most apps at launch scale are fine staying on Replit with a custom domain and a security pass.

What does a Replit security review actually check?

A Replit security review checks database query construction, server-side authorization on every data-touching route, secrets management and rotation history, rate limiting on public endpoints, and error responses for information leakage. Production-safe AI management keeps those checks current after launch.

How much does it cost to get a Replit app production-ready?

Launch Essentials ($950 fixed) covers custom domain and DNS setup. Production Hardening ($2,950 fixed) adds a security pass, auth debugging, and baseline SEO. Both are published fixed-fee work, described on the AI app launch support page; compare builders on the AI builders page.

AI app launch

Get Your Replit App Production-Ready.

Launch Essentials ($950 fixed) or Production Hardening ($2,950 fixed), fixed fee, no quote process.