# Build brief — a focused alternative to Softr

> **Verdict:** Partly, if you narrow it · **Buildability:** 49/100 · **Category:** No Code Apps
> **Source:** https://www.canitbevibecoded.com/softr
> Independent editorial assessment from Can It Be Vibe Coded? Not affiliated with, endorsed by, or derived from Softr. Verify current pricing and capabilities before acting.

## Context

**Softr** — No-code portals and internal apps on Airtable/Google Sheets and databases. It currently costs $59/mo.

A client portal over Airtable can be built, but Softr's block library, auth, roles, data sources, payments, and publishing workflow are the product.

This brief describes a focused, single-operator replacement for the part of Softr that is genuinely reproducible. It is deliberately narrower than the product it replaces, and it says so in writing. Build the useful core; do not pretend to have rebuilt the rest.

## What you are building

Build a CRUD portal with auth, role-gated pages, list/detail views, forms, and Airtable/Postgres backing data.

- Build a focused single-user workflow with real persistence, search, and export.
- A responsive interface with real empty, loading, success, and error states.

## Requirements

### Functional

- Frontend framework.
- Auth.
- Hosting.
- Payment/email integrations.

### Data and integrations

- Database or Airtable API.

Each of these needs a real account, credential, or quota. Set them up before writing feature code.

### Non-functional

- Accessibility: semantic markup, labelled controls, visible focus, and reduced-motion support.
- Security: server-side secrets, validated input, and no credentials in the client bundle.
- Reliability: retries with backoff on external calls, and a clear failure state when a provider is down.
- Portability: the operator can export their data and leave without losing it.

## Implementation brief

Build me a client portal to replace Softr: one portal for my own clients, not a portal
builder. Requirements:

- Node + Express + nunjucks, server-rendered; data stays in Airtable via its REST API
  (base ID and token in .env) so records keep being edited there.
- Magic-link login: a client enters their email, gets a signed link via Resend (secret
  in .env); sessions in signed cookies. Allowed emails live in an Airtable Clients
  table.
- Each client sees only rows linked to their client record: a list view with the columns
  named in views.json, and a detail view per record.
- One submission form that appends a row to a chosen table, with file upload passed
  through to Airtable attachments.
- A role flag on the client record (client vs admin); admins see all rows.
- Cache Airtable reads for 60 seconds to stay under rate limits.
- Runs on my VPS behind HTTPS; no telemetry, no third parties beyond Airtable and the
  email sender.
- Out of scope: a drag-and-drop page builder, payments, and memberships. Pages are
  defined in config files, that is the builder.
- README: Airtable token scopes, expected table and field names, and email sender setup.

## Delivery standard

- Inspect the repository first, then write a short implementation plan before writing code.
- Deliver the smallest complete end-to-end workflow first; every primary control must work against persisted data.
- Use real validation and storage; never substitute fake dashboards, decorative controls, hard-coded success states, or mock integrations.
- Include responsive layouts plus genuine empty, loading, success, validation, and failure states.
- Keep secrets server-side in environment variables, provide .env.example, and never commit credentials or user data.
- Add structured logs around every external call and return actionable errors without leaking sensitive details.
- Write unit tests for the core logic and one automated test of the main user journey.
- Finish with a README covering setup, architecture, data location, backups, tests, deployment, and known limitations.

## Acceptance criteria

- [ ] A clean install starts the app using only the README and .env.example.
- [ ] The primary journey works from first visit through saved result, reload, edit, export, and deletion where applicable.
- [ ] Invalid input, missing configuration, provider failure, and an empty database each have a usable state.
- [ ] The interface works at 390px and 1440px, is keyboard navigable, and shows visible focus on every control.
- [ ] Tests, type checking, linting, and a production build all pass with no ignored failures.
- [ ] No part of the interface implies a live integration, security guarantee, or scale capability that was not actually built and verified.

## Non-goals

Do not build these, and do not claim to have replaced them:

- Visual builder.
- Templates.
- Role permissions.
- Data-source integrations.
- The last 20 percent is sync, migration fidelity, speed, and edge cases.
- Connectors, OAuth flows, and vendor API changes require constant upkeep.

## What you still own after launch

- Secure credentials, rotate secrets, and handle provider rate limits.
- Run migrations, backups, restores, and dependency updates.
- Test the critical journey after every model, API, or hosting change.
- Monitor failures and fix the edge cases a first prompt will miss.
- Maintain every third-party integration as APIs and OAuth rules change.

## Risk

**Operational risk.** The code is achievable; dependable data, integrations, and ongoing operations are the real cost.

Editorial confidence in this assessment: high. No independent one-shot implementation is linked yet.

## Prior art

Working open-source software you can read, fork, or borrow from before starting:

- [Budibase](https://github.com/Budibase/budibase) — Open-source low-code platform for internal tools and portals

---

Generated by [Can It Be Vibe Coded?](https://www.canitbevibecoded.com) · Full report: https://www.canitbevibecoded.com/softr
