Sign-in with Google or a magic link, gated by an Airtable view you already keep.
Adding login usually means standing up a second system: a user database, password resets, and a membership list you now have to keep in sync with the spreadsheet where the real answer lives.
VibeKit skips the second system. It handles sign-in for your app — like a simple Okta or Auth0, but built around your Airtable. The list of who gets in is an Airtable view you point at, in the base you already maintain.
Point it at a view
Paste the view that holds your users and pick which field is the email. Then turn on the login methods you want: Sign in with Google, a magic email link (a one-time link), or both — there are no passwords to manage. Anyone who signs in is checked against your list; only people on it get in, and every attempt, successful or not, shows up in a login log. Want to accept new people too? Switch on signups and VibeKit creates their user row automatically, restrictable to certain email domains.
Membership that stays live
After login your app receives the user's record live, the same way it receives your other data. Edit their row in Airtable and the app updates. Remove their row and they're signed out automatically — access is re-checked on a schedule you set. Your base stays the single source of truth for who's in.
Groups from simple conditions
Need admin-only areas, or to treat paying customers differently? Define groups with conditions over who someone is (email ends in @yourco.com means admins) or over their record (a plan field is set means customers). Your app receives each user's groups, so it can show the right things to the right people.
Wired in by your agent
Your agent adds the whole thing from two short snippets: a login button with its callback, and a live-session hook with a route guard. While you develop, flip on log in as to sign in as any user by email and see the app exactly as they would — a development tool, disabled in production. And as with everything in VibeKit, your Airtable token never reaches the browser (see secure token vault).
Record-level security
Every request only ever returns the records that belong to the signed-in user — enforced on the proxy, not in the browser.
Request logs
Airtable keeps no record of individual API calls. The proxy logs every one — who called, what they read or wrote, and when.
Media caching
Airtable attachment links expire. VibeKit's don't — your photos stay up.
Try it on your own base
Paste a token, point at a view, hand the prompt to your agent.