Skip to main content
Every prompt here is written for Vibely specifically — it names the things the agent’s own quality bar checks for, so you get the finished version instead of the first draft. Copy one, replace the bracketed parts, send it. How to read an entry. Each has a web prompt, a one-line what you get, and a mobile variant that routes to the right Expo module. The last section is mobile-only: six things a web build cannot have.
These assume a project that already exists. For turn 1, start with First build. Anything touching accounts, saved data, file storage or a server-side API key will raise the Supabase connect card — the agent keeps building in that same turn on sample data and rewires it once you connect. See Connectors → Native.

Copy-paste prompts, web and mobile

1. First build

What you get: a direction committed before any UI (tokens, type pairing, restyled primitives), the screens that journey needs, every add/edit/delete wired into a dialog with a toast, loading/empty/error states, and a real sign-in route — not a stack of placeholders. Mobile variant
Turn 1 on mobile also does branding — a name and scheme in app.json, a generated icon over assets/images/icon.png, splash colours carrying your direction. Say “portrait only” or you may get both.

2. Auth and roles

What you get: a sign-in route plus the email-callback route in the same turn, a user_roles table with an app_role enum and a SECURITY DEFINER has_role() function, RLS policies keyed on auth.uid(), and a protected layout that redirects logged-out visitors.
A role column on profiles is a privilege-escalation hole and the agent will refuse to build one. If you already have one, ask it to migrate you off it.
Mobile variant
Routes to expo-linking for the return URL and adds an auth-callback screen that exchanges the code for a session.

3. Dashboard

What you get: tiles wired to real aggregates, a table with at least one of sort/filter/search, skeletons while data loads, and a designed empty state with a primary action rather than a blank panel. Mobile variant
Raw Date and price values are a visual defect on mobile — String(created_at) renders the full timezone string inside a list row. The agent routes through the template’s format helpers.

4. File upload

What you get: a private storage bucket, signed URLs fetched at render time (never persisted to a column, because they expire), conditional rendering so there is no empty src request, and a real failure branch. Mobile variant
Routes to expo-image-picker (photo library) and expo-camera (capture). Both need their permission config written in the same turn — NSPhotoLibraryUsageDescription / NSCameraUsageDescription and the matching Android permissions.

5. CSV import and export

What you get: a preview-before-write flow rather than a blind insert, a per-row validation report, and an export that respects the filters on screen. Mobile variant
Sharing a generated file is the mobile-native equivalent of a download. Say so explicitly or you may get a browser-style download that does nothing on a device.

6. Payments and subscription tiers

What you get: Checkout and webhook as Edge Functions reading STRIPE_SECRET_KEY and STRIPE_WEBHOOK_SECRET server-side, a subscription table the webhook writes, and gating checked on the server, not in the client. Mobile variant
Stripe is not an option for digital goods in a mobile app — Apple and Google require in-app purchase, and a Stripe subscription in an iOS build is an automatic rejection under Guideline 3.1.1. Mobile monetization routes to revenuecat. See Connectors → Catalog.
The paywall renders empty in Expo Go and the web preview because there is no StoreKit or Billing there. That is correct, not a bug — do not ask the agent to “fix” it with mock packages.

7. Notifications

What you get: a notifications table with RLS scoped to the recipient, optimistic mark-as-read, and the email path in an Edge Function with the API key registered as a secret rather than sitting in the bundle. Mobile variant
Routes to expo-notifications, which also needs POST_NOTIFICATIONS on Android — without it, Android 13+ silently shows nothing. Push does not work in the web preview; test in Expo Go on a real device. Full wiring in Native capabilities.

8. Team workspace

What you get: a team_id on every tenant table, membership and invite tables, policies that join through membership, and a switcher that actually changes what the queries return.
This is the change worth planning first. Start with “Switch to plan mode and tell me everything multi-tenancy would touch.”
Mobile variant

9. AI assistant

What you get: the call behind an Edge Function (no key in the bundle), streamed tokens rather than a spinner that sits for twenty seconds, and a failure branch the user can see. Mobile variant
Vibely AI is on by default at the workspace level — no key to bring. See Connectors → Catalog.
What you get: a migration enabling vector with an index, a trigger or Edge Function that keeps embeddings current, and a query that ranks by distance. Keep the keyword path — semantic-only search fails badly on exact identifiers like an invoice number. Mobile variant

11. SEO metadata

What you get: per-route metadata rather than one global title, structured data where it earns a rich result, and the internal pages left out of the sitemap. Mobile variant
That copy is what you paste into App Store Connect and Play Console yourself; neither store API accepts it from a build. See Ship to stores.

12. Audit log

What you get: an append-only table (an insert policy and no update/delete policy), the admin read gated through the role function, and a filterable view rather than a raw dump. Mobile variant

13. Feature flags

What you get: a default-off lookup (so a missing flag can never accidentally ship a half-built feature), a per-team override table, and one hook instead of scattered checks. Mobile variant

14. Schema change

What you get: an additive, idempotent migration; the GRANTs and RLS in the right order; and the UI updated in the same turn instead of a schema that drifts ahead of the app. Mobile variant

15. Design change

What you get: a token-level change that propagates, rather than fifty one-off class edits that drift apart on the next turn. Mobile variant
If dark mode looks wrong after a restyle, it is almost always a hex literal left in a screen instead of a theme token. Say “no hex literals in screens” and it gets fixed.

16. Bug report

What you get: a root-cause turn instead of a guess. “Investigate first” is the load-bearing sentence — without it you often get a plausible patch on the wrong file. Full method in Debugging. Mobile variant
Always say which surface — web preview or a real device. Half of mobile bugs only exist on one of them, and that fact alone usually names the cause.

17. Refactor

What you get: a scoped refactor with a file list you can veto, instead of a diff that also reformats half the repo. Mobile variant

Mobile only

Six things a web build cannot do, and one for when a store says no.

18. Push notification flow

Module: expo-notifications. Needs POST_NOTIFICATIONS on Android — without it, nothing shows and nothing errors. Local reminders need no server; remote pushes go out from an Edge Function. Not testable in the web preview.

19. Camera and scan capture

Module: expo-camera. Requires NSCameraUsageDescription and android.permission.CAMERA, written in the same turn as the install. Camera does not work in the browser preview — ask for the fallback or you will think it is broken.

20. Biometric unlock

Module: expo-local-authentication, with NSFaceIDUsageDescription. Biometrics gate access to a session token already on the device — they are never primary auth. The no-enrolment branch is the one people forget, and it locks real users out.

21. Offline cache

Module: @react-native-async-storage/async-storage (pre-installed). One storage key per collection, loaded on mount and written back on every mutation. Data held only in component state is gone on the next launch — that is a mockup, not an app.
Module: expo-linking plus the scheme in app.json. Cold start is the case that breaks — the link arrives before the router mounts. Universal links (https://…) additionally need apple-app-site-association and assetlinks.json served from your domain; ask the agent for the exact files. See Deep links.

23. In-app purchase paywall

Connector: revenuecat (API key tier — two public EXPO_PUBLIC_ SDK keys, one per store). Real purchases need a native build plus products configured in App Store Connect and Play Console. In Expo Go the paywall renders empty, which is correct.

24. Store rejection fix

What you get: a targeted fix rather than a rewrite. Paste the note verbatim — the guideline number is what pins the cause. The usual culprits are a missing or vague permission usage string, placeholder content still shipping, a login wall with no way to try the app, and web checkout for digital goods. Guideline 4.8 is its own trap: offering Google or Facebook sign-in obliges you to offer an equivalent privacy-preserving option, and plain email/password does not satisfy it. Rejections and resubmissions cost nothing beyond the one turn that triggered the build. See Ship to stores.

Next

Prompting

The method behind these: plan mode, scope per turn, design vocabulary, Knowledge.

Debugging

When the prompt is right and the build still isn’t.