# Build brief — a focused alternative to Shopify

> **Verdict:** Not faithfully · **Buildability:** 6/100 · **Category:** Commerce
> **Source:** https://www.canitbevibecoded.com/shopify
> Independent editorial assessment from Can It Be Vibe Coded? Not affiliated with, endorsed by, or derived from Shopify. Verify current pricing and capabilities before acting.

## Context

**Shopify** — Hosted ecommerce platform for stores, payments, checkout, and operations. It currently costs $39/mo.

You can build a small store, but Shopify's product is hosted checkout, payments, tax/shipping integrations, app marketplace, fraud/risk tooling, and merchant operations.

This brief describes a focused, single-operator replacement for the part of Shopify that is genuinely reproducible. It is deliberately narrower than the product it replaces, and it says so in writing. Build the useful core; do not pretend to have rebuilt the rest.

## What you are building

For a tiny shop, build catalog/cart/checkout via Stripe, order emails, and simple admin; do not expect Shopify parity.

- Build a focused single-user workflow with real persistence, search, and export.
- A responsive interface with real empty, loading, success, and error states.

## Requirements

### Functional

- Payment processor.
- Tax/shipping logic.
- Database.
- Hosting.
- Emails.
- Inventory/order admin.

### Non-functional

- Accessibility: semantic markup, labelled controls, visible focus, and reduced-motion support.
- Security: server-side secrets, validated input, and no credentials in the client bundle.
- Reliability: retries with backoff on external calls, and a clear failure state when a provider is down.
- Portability: the operator can export their data and leave without losing it.

## Implementation brief

Build me a small self-hosted shop for a handful of products, the honest small
slice of Shopify. Requirements:

- Node + Express + better-sqlite3 on a VPS; products in products.json (slug,
  name, price, images, stock count), server-rendered catalog and product pages.
- Cart in a session cookie; checkout hands off entirely to Stripe Checkout
  (keys in .env). Never touch card data.
- Stripe webhook records the order, decrements stock, and emails me and the
  buyer via Resend (key in .env).
- An /admin page behind basic auth: order list and a mark-shipped button that
  emails the buyer with an optional tracking number.
- Flat shipping rates per region in a config file; sold-out products stay
  visible but cannot be bought.
- No customer accounts, no telemetry; orders stay in my SQLite file.
- Out of scope: discount engines, multi-currency, POS, and tax automation. Use
  Stripe Tax for tax; do not write tax logic.
- README: Stripe webhook setup, a plain warning that I am now the fraud
  department, and a note that this is not Shopify, whose trusted checkout,
  payment risk handling, and app ecosystem cannot be rebuilt; if volume grows,
  move to Shopify or Medusa rather than growing this.

## Delivery standard

- Inspect the repository first, then write a short implementation plan before writing code.
- Deliver the smallest complete end-to-end workflow first; every primary control must work against persisted data.
- Use real validation and storage; never substitute fake dashboards, decorative controls, hard-coded success states, or mock integrations.
- Include responsive layouts plus genuine empty, loading, success, validation, and failure states.
- Keep secrets server-side in environment variables, provide .env.example, and never commit credentials or user data.
- Add structured logs around every external call and return actionable errors without leaking sensitive details.
- Write unit tests for the core logic and one automated test of the main user journey.
- Finish with a README covering setup, architecture, data location, backups, tests, deployment, and known limitations.

## Acceptance criteria

- [ ] A clean install starts the app using only the README and .env.example.
- [ ] The primary journey works from first visit through saved result, reload, edit, export, and deletion where applicable.
- [ ] Invalid input, missing configuration, provider failure, and an empty database each have a usable state.
- [ ] The interface works at 390px and 1440px, is keyboard navigable, and shows visible focus on every control.
- [ ] Tests, type checking, linting, and a production build all pass with no ignored failures.
- [ ] No part of the interface implies a live integration, security guarantee, or scale capability that was not actually built and verified.

## Non-goals

Do not build these, and do not claim to have replaced them:

- Trusted checkout.
- Payment risk.
- App marketplace.
- Themes.
- Compliance, licensing, and legal accountability are core features.
- The buyer and seller network cannot be generated with code.

## What you still own after launch

- Run migrations, backups, restores, and dependency updates.
- Test the critical journey after every model, API, or hosting change.
- Monitor failures and fix the edge cases a first prompt will miss.

## Risk

**High consequence.** Use this as a prototype or personal aid. Keep a qualified human and an established provider in the loop for consequential decisions.

Editorial confidence in this assessment: high. No independent one-shot implementation is linked yet.

## Prior art

Working open-source software you can read, fork, or borrow from before starting:

- [Medusa](https://github.com/medusajs/medusa) — Open-source commerce platform for custom stores; substantial prior art but not Shopify's h

---

Generated by [Can It Be Vibe Coded?](https://www.canitbevibecoded.com) · Full report: https://www.canitbevibecoded.com/shopify
