Secure Vibe Coding
Ask NocoAI
Copy a prompt, paste it into NocoAI in any base, and replace the words in [brackets] with your own.
- Let only [the managers team] [approve expenses]
- Let the [Members] team see only the [tickets] assigned to them
- Which actions can visitors run without signing in?
NocoDB Apps make vibe coding safe for enterprise-grade work apps. NocoAI writes the app, but the app can reach data only through actions. NocoDB checks every action against the access of the person who runs it. The access rules are part of the app from the first build, not a step that you add later.
How NocoDB keeps an app safe
| Layer | What NocoDB does | Where to set it |
|---|---|---|
| Who can open the app | A person can open the app only when they are in a team that has at least one grant. People you invite to the app get no other access to the base. | Members and teams |
| What each person can do | Each team has a list of the actions its members can run. Actions are the only way that the app reads or changes data and calls other services. | Grant actions to a team |
| Which records each team sees | Record rules, for example "members see only their own requests", use NocoDB record-level security. | Limit records for each team |
| What is public | An app has no public pages until you ask for them. A deploy that makes pages public, or lets visitors run actions, needs a review first. NocoDB limits how many actions each visitor can call each minute. | Public access |
| Where secrets live | API keys and passwords stay in connections and workspace integrations, not in the code of the pages. | Connections |
| What programs can do | An app API token can never do more than the person who created it. You choose its actions and its expiry date. | App API and MCP |
| What the in-app AI can do | The app assistant runs only the actions that the person in the chat can run. | Assistant |
Safe changes
A change to a live work app must not break the work of the people who use it. NocoDB Apps give you these controls:
| Control | What it does |
|---|---|
| Live preview | Every change shows first in the AI app builder preview. People who use the app see it only after you deploy. |
| Preview as a team | Viewing as shows the app as a member of each team sees it, before you deploy. |
| Deploy review | A deploy that deletes data, makes pages public or lets visitors run actions shows what changes, and waits for you to confirm. See Review a deploy. |
| Environments | Build and test changes in a copy of the base, for example Staging, then release them with one deploy. See Environments. |
| Version history | Every deploy is a numbered version. Restore an earlier version with one click. See Version history. |
Who can build
Only base members with the Owner or Creator role can build, change and deploy an app. Every other person uses the app through the teams and grants that you set. See Who can do what.
Good to know
- Team grants and public pages take effect only when you deploy. Changes to Theme and Assistant apply without a deploy.
- When one page of an app is public, anyone can download the code of the app pages. Keep secrets in actions and connections.
- Removing a person from a team removes only what that team allows in the app. Their base access does not change.
Availability
| Capability | Plan |
|---|---|
| Teams, action grants, public access, deploy review and version history | Every plan that includes Apps |
| App API tokens and the app MCP server | Plus and above |
| Record-level security for app teams, environments and per-user connections | Scale and above |
Related
Last updated on
Latest product updates?See Changelog