vibes-diy sharing 13 states · Restricted | Public · docs
who's in. who's out. what they can do.

You made your thing.
Now run who sees it.

Every link you share lands someone on a decision: do they get in, or do they see a door? This is the full reference — every access state, Restricted or Public, Data and Code for each member, Clone vs Remix, all of it.

access states
13
settings per member
2
switch positions
2
buttons on the door
2
the door

Every state the door can be in.

When someone follows your link, the platform resolves one state. Here's all of them.

state what it means what they see
ownerIt's their thingFull controls — Edit, Share, Update
granted-access.editorApproved as editorApp loads, can comment
granted-access.viewerApproved as viewerApp loads, read-only
granted-access.submitterApproved as submitterApp loads, submitter-level interaction
public-accessPublic sharing is on; no personal grantApp loads as anonymous viewer
accepted-email-inviteRedeemed an email invite linkApp loads, treated as editor
req-login.requestPrivate; visitor is logged outLanding card: Request access
req-login.inviteHas a pending invite; not logged inLanding card: Join collab
req-login.auto-joinAuto-approve is on; visitor not logged inLanding card: Join collab
pending-requestRequest submitted; owner hasn't approved yetLanding card: button disabled → "Requested"
revoked-accessHad access; it was revokedLanding card: button disabled → "Revoked"
not-foundDoesn't exist, or no grant on a private thing"App not available"
not-grantExists but this visitor has no grantSame as not-found
the door, when you're outside

What they see when they don't have access.

A centered card over a grid background. App title, screenshot if one exists, one button.

/ 01 / SHOW UP

They clicked your link.

They don't have access. Instead of the app, they see a card: the thing's title, a screenshot if one's been generated, and one button. No blank error page. Always the card.

/ 02 / CHOOSE

One button. One transaction.

Request access / Join collab — asks to join yours. Label changes by state. "Requested" or "Revoked" means it's disabled.

No copy from the door. Remix and Clone are a read of your source, so they only exist for someone who can already open the app — the Remix button inside it.

Request access
/ 03 / ROUTE

Logged out? The platform remembers.

If they're not signed in and click the button, the URL gets ?intent=join, a login screen appears, and the request fires automatically after sign-in. No lost clicks.

share your app

A link to send. A code to scan.

Tap the Vibes switch in the bottom-right corner, then Share. Copy link copies the app's address and reads “Copied” for a moment. QR code shows a code to scan. For a published app anyone can open, Embed gives you code for your own site, and Pin it saves it to Pinterest.

embed on your site

The frame follows the app. You never type a height.

A published, publicly readable app can live on your own page. The Share tab offers two snippets. “Copy embed code” is a plain <iframe> with a fixed height. “Copy auto-height embed” is the one below: the frame sizes itself to the app, on every tap, so your visitor sees one page and one scrollbar.

Why a fixed height is never right

The height an app needs is a property of what your visitor has done in it so far, not of the app. A form that reveals sections as it is filled in grows by hundreds of pixels per choice. Too small a frame scrolls inside the page; too large leaves a blank band under it.

The app already knows exactly how tall it is. The embedded document reports its height up to your page as a vibes.diy:embed-height message, and the script in the snippet applies it.

No script? The fixed height is the best available.

A plain <iframe> cannot be resized from inside — that is a browser boundary, not something the platform can route around. If your page cannot run a script, use the fixed-height snippet and add ?vibesClearance=off to its address so the frame stops at the app's last row.

Squarespace's Embed Block runs scripts on every plan (the Code Block is the plan-gated one), so the auto-height snippet works there.

<div data-vibe-embed="ursula-barton/cityscape-art-estimator">
  <iframe
    src="https://vibes.diy/embed/ursula-barton/cityscape-art-estimator?vibesClearance=off"
    title="Cityscape art estimator"
    scrolling="no"
    style="width:100%;border:0;display:block;height:600px"
  ></iframe>
  <p><a href="https://vibes.diy/vibe/ursula-barton/cityscape-art-estimator">Open it in a new tab</a></p>
</div>
<script>
(function () {
  var wrap = document.currentScript.previousElementSibling;
  var frame = wrap.querySelector("iframe");
  var id = wrap.getAttribute("data-vibe-embed");
  var min = parseInt(frame.style.height, 10) || 0;
  addEventListener("message", function (e) {
    var d = e.data;
    if (!d || d.type !== "vibes.diy:embed-height") return;
    if (e.source !== frame.contentWindow) return;
    if (id && d.ownerHandle + "/" + d.appSlug !== id) return;
    var h = Math.round(d.height);
    if (h > 0 && h < 100000) frame.style.height = Math.max(h, min) + "px";
  });
})();
</script>

What the snippet keeps

The e.source check, because any page can post a message. The size clamp. The data-vibe-embed match, so two apps on one page each keep their own height. The plain link under the frame, which works when script is blocked.

The starting height is a first-paint placeholder and the floor, not a guess: the first real measurement lands within a frame of the app painting, the frame grows and shrinks with the app from there, and it never goes below the height you started it at. Set it to the least height that looks right on your page.

The message, for your own page code

{ type: "vibes.diy:embed-height", height: 4045, ownerHandle, appSlug }. One integer in CSS pixels and the app's public identity. Nothing else rides on it, and nothing else ever will.

the controls

Restricted or Public. Then who, and what they can do.

The Share card's toggle decides who can open your app; the list under it names them.

Restricted | Public

Restricted: “Only the people below can open this app.” While requests are on (the default), everyone else sees a door with a “Request access” button. If you turn requests off in App Settings → Sharing, they see “App not available” instead.

Public: “Anyone with the link can open this app.” Going public first secures your app's data. The toggle shows “Securing…” while that runs; if it can't finish, it says “Couldn't make it public. Try again” with a Retry, and your app stays restricted until it succeeds.

Members: Data and Code

Invite by handle or email. Each member has two settings.

Data: Read | Write. Read lets them open the app and read its data. Write lets them add and change data too.

Code: Yes | No. Yes lets them change the app's code and publish it, and see all of its data, just as developer access does from the CLI. Changing Data never changes Code.

Read means read-only once you turn on Only editors can change data on the Share card: a Reader then can't add or change data in any of your app's databases, while editors and you keep writing to them. Until you turn it on, Read is a label: a Reader can still write to any database your app hasn't limited to people with Write. Your app's access functions and per-database pins can narrow editors further either way.

Requests

When someone asks to join, their request appears under Members with Data and Code already set. Approve lets them in with those settings. Not now declines the request. A badge on the switch and on the Share tab counts waiting requests. In See all members, New visitors can approve everyone automatically with the Data setting you choose.

Tap a member to change their settings or remove them. Removing someone stops what they receive going forward; it doesn't claw back data already on their device.

Your access

Everyone can open Your access on the Share card to see their own Data and Code settings. The owner turns Admin mode on and off there: it “Lets you see and change everyone's data in this app.”

Comments

"Only collaborators can comment" — off by default. Off means members (editors, viewers, owner) can post and delete. Public visitors on a public app are not members and cannot comment even with this off. On means editors and owner only.

Enforced server-side. The composer is also hidden client-side for viewers and anonymous users as a prefetch UX.

copy the thing

Clone lands you in the app. Remix lands you in the editor.

Both create a new copy under your account. One flag changes where you land.

Clone

Skips the editor entirely. Your copy goes straight to production. You land at /vibe/yourname/appname — the live app, running with your data.

Both need access to the source: the owner, a public app, or an approved grant. A private app whose owner hasn't let you in can't be cloned or remixed — ask first.

Remix

Opens the builder with ?view=code. Your copy starts in dev mode. You land in the editor, ready to change the source.

Same fork under the hood — one flag (skipChat) decides where you land.

what they can do

What each setting lets them do.

Data and Code are what you set. Submit exists for form-style apps and shows as read-only “Data: Submit” in the list.

/ DATA: WRITE

Full collaborator.

Can use the app and add and change its data. The thing responds to them the way it responds to you.

/ DATA: READ

Reader.

Can open the app and read its data. Turn on Only editors can change data and a Reader can't add or change data in any of your app's databases. Until then, Read is a label: a Reader can still write to any database your app hasn't limited to people with Write. Per-database pins and your app's access functions can narrow editors further either way.

/ CODE: YES

Can change the app.

Can change the app's code and publish it, and see all of its data, just as developer access does from the CLI. Separate from Data: changing one never changes the other.

the floating thing

The switch in the corner.

Bottom-right of any /vibe/ page. Tap it to open the bar: Home, Account, Code, Share. Tap a tab to open its card.

Four tabs · One badge · One chiclet

Home: make a new app, vibes.diy, My Vibes and recommended apps. Account: your handles, credits, memberships and settings. Code: ask for changes, or remix an app you don't own. Share: who can open it, members and your link. Badge (owner only): pending access requests. Draft chiclet beside the switch (owner only): you have unpublished changes.

Make your thing. Run it for your crew.

The sharing system is how your thing becomes their thing — or stays yours. Build it on Vibes DIY.

// want this for your specific app?
Clone any vibes.diy app and you get the full sharing system with it.
Public or locked down, invite-only or open door — the controls are the same.
Start from an existing app that does something close to what you need,
then describe what's different.