
Vibe coding is a way of building software where you describe what you want in plain language, an AI model writes the code, and you judge the result by running it rather than by reading every line. You steer with prompts like “make the signup form shorter” or “the save button does nothing, fix it”, and the AI handles the syntax.
The phrase started as a half-joke from an AI researcher in early 2025. Within a year it was in Merriam-Webster and named Collins Word of the Year, and a whole category of tools had grown around it. This guide covers what vibe coding actually involves, where it works, where it goes wrong, and how to try it without shipping something you’ll regret.
What Is Vibe Coding?
At its simplest, vibe coding is programming by conversation. Instead of writing functions, you write requests. The AI generates the code, you run the app, and you react to what you see. If something breaks, you paste the error back and ask for a fix.
The defining feature is not that AI writes the code. Plenty of professional developers use AI to write code. What makes it vibe coding is that the person accepts code without fully reviewing or understanding it, and trusts the running result instead. That is what makes it fast, and it is also what makes it risky.
In practice the term now gets used loosely. Some people use “vibe coding” for any AI-heavy development. Others keep it for the original meaning: building by feel, with little attention to the code underneath. This guide uses the stricter meaning, because that’s where the useful distinctions are.
Where the Term “Vibe Coding” Came From
| Date | What happened |
|---|---|
| 2 February 2025 | Andrej Karpathy, an OpenAI co-founder and former head of AI at Tesla, describes “a new kind of coding I call ‘vibe coding’, where you fully give in to the vibes” in a post on X. He says he accepts AI changes without reading the diffs and pastes error messages back in without comment. |
| March 2025 | Merriam-Webster adds “vibe coding” as a slang and trending term. |
| Through 2025 | AI app builders such as Lovable, Bolt and Replit market themselves around the idea, and the term spreads well beyond developer circles. |
| 6 November 2025 | Collins names “vibe coding” its Word of the Year, defining it as the use of AI prompted by natural language to assist with writing computer code. |
Karpathy’s original post was clear about the limits. He described it as fine for “throwaway weekend projects”, not as a method for serious software. That caveat tends to get lost when the term is repeated.
How Vibe Coding Works
Most vibe coding sessions follow the same loop, whatever tool you use:
- Describe the app– You write a prompt explaining what you want: who uses it, what it does, roughly how it should look.
- The AI builds a first version– An app builder generates the interface, logic and often a database. An AI code editor creates or edits files in a project.
- You run it and react– You click around. Some things work, some don’t, some aren’t what you meant.
- You prompt changes– “Make the cards smaller.” “Add a login page.” “This error appears when I submit the form,” followed by the error text.
- Repeat until it’s good enough– The app grows one request at a time, and you rarely open the code yourself.
The loop is quick because the feedback is visual and immediate. The weakness is that each fix is local. The AI solves the problem in front of it, and over many rounds the codebase can pile up duplicated logic, half-removed features and patches on top of patches.
A Vibe Coding Example
Say a yoga studio owner in Mumbai wants a simple booking page. Her first prompt might be:
Build a class booking web app for a small yoga studio. Show this week’s classes with time (IST), instructor and spots left. Students enter name and phone number to book. Stop bookings when a class is full. Add an admin page where I can add classes.
An AI app builder would typically produce a working first version in a few minutes: a schedule page, a booking form, a database table for classes and bookings, and an admin screen.
Then the real work starts. She notices the times show in UTC, so she asks for IST. She wants WhatsApp reminders, so she asks for that and gets prompted to connect a messaging service. She realises anyone who finds the admin URL can add classes, so she asks for a password on it.
That last step is the important one. The app “worked” before she noticed the admin page was open to anyone. Nothing in the vibe coding loop prompted her to check. She caught it only because she thought about who could reach that page. That gap between “it works” and “it’s safe” is the core issue with vibe coding, and it comes up again in the risks section.
Vibe Coding vs Traditional Coding vs AI-Assisted Coding
| Traditional coding | AI-assisted coding | Vibe coding | |
|---|---|---|---|
| Who writes the code | The developer | AI drafts, developer edits | AI |
| Does the person read the code? | Yes, they wrote it | Yes, reviewed before merging | Mostly no |
| How correctness is judged | Code review, tests, reasoning | Code review and tests | Running the app and looking |
| Skill needed | Programming | Programming | Clear description and testing habits |
| Speed to first version | Slowest | Faster | Fastest |
| Fit for production software | Yes | Yes | Only with review added |
| Typical tools | IDE, compiler | Copilot, Cursor, Claude Code | Lovable, Bolt, Replit, Base44 |
The middle column matters. A developer using Cursor or Claude Code who reviews every change is doing AI-assisted coding, not vibe coding, even though the tools overlap. The same tool can be used either way. What changes is whether anyone checks the output.
Vibe Coding Tools
Tools fall into three groups, and which one suits you depends mostly on whether you want to see code at all.
AI App Builders: For People Who Don’t Code
These run in the browser and handle hosting, databases and deployment for you. You describe the app; they build and publish it.
- Lovable builds React web apps with a Supabase backend and is one of the most widely used tools in this category.
- Bolt works in a similar way, with a browser-based development environment you can inspect.
- Replit pairs an AI agent with a full online coding environment, so you can move from prompts to editing code in the same place.
- Base44 and Rocket.new focus on generating complete apps with backend features included.
Our best AI app builders roundup compares pricing and limits across these, and Replit vs Lovable goes deeper on the two most common starting points.
AI Code Editors and Agents: For People Who Can Read Code
These work inside a real codebase on your machine or repository. They suit developers, or non-developers who are willing to learn to read what the AI writes.
- Cursor is an AI-first code editor built on VS Code.
- Claude Code is a terminal-based coding agent that can edit files and run commands across a project.
- GitHub Copilot adds AI suggestions and an agent mode inside existing editors.
- Devin is positioned as an autonomous software engineer that takes on whole tasks.
See Claude Code vs Cursor, Cursor vs GitHub Copilot and Cursor alternatives for how they differ. Many of these agents can also connect to outside tools and data through the Model Context Protocol, explained in our MCP guide.
No-Code Builders: The Older Route
Visual builders such as Bubble and Glide predate vibe coding and use drag-and-drop instead of prompts, though both have added AI features. They are slower to start than an AI app builder but give you more predictable control over logic and data. Our drag-and-drop app builders list covers more.
What Vibe Coding Is Good For, and What It Isn’t
Where it works well:
- Prototypes and demos you want to show investors, clients or your team
- Internal tools used by a handful of trusted people, such as a dashboard over a spreadsheet
- Personal projects and one-off utilities
- Landing pages and simple marketing sites
- Testing whether an idea is worth building properly
Where it struggles:
- Apps that handle payments, health data, or personal information at scale
- Software that many people will maintain over years
- Systems with complex business rules where edge cases matter
- Anything regulated, where you must explain how the code works
- Performance-sensitive work, where AI-generated code is often correct but inefficient
A fair rule of thumb: the more it costs when the app does something wrong, the less suited it is to pure vibe coding.
The Risks of Vibe Coding
Security Gaps You Can’t See
AI models produce code that runs but is not necessarily safe. Veracode’s 2025 GenAI Code Security Report tested more than 100 large language models on 80 coding tasks and found that 45% of the generated code samples failed security tests against common vulnerability classes from the OWASP Top 10. Newer, larger models did not do noticeably better on security, even when they wrote more working code.
The problem is sharper for vibe coders because the usual safety net, someone reading the code, is missing. One 2025 case on a popular AI app builder showed how this plays out. A security researcher found that 170 of 1,645 sampled apps built on the platform exposed user data through 303 endpoints, because database access rules (Supabase row-level security) had not been switched on. It was logged as CVE-2025-48757. The apps worked fine for their owners. The flaw was invisible unless you knew to look for it.
AI Agents Doing the Wrong Thing
Agents that can run commands can also run the wrong ones. In July 2025, SaaStr founder Jason Lemkin reported that Replit’s AI agent deleted his project’s production database during a code freeze, despite instructions not to make changes, and then gave misleading answers about whether the data could be recovered. Replit’s CEO publicly apologised, and the company said it was adding automatic separation between development and production databases and improving rollback. Lemkin was able to recover the data.
The lesson is not specific to one tool. Any agent with write access to live systems can cause damage that a prompt cannot undo.
Code Nobody Understands
When the AI wrote everything and nobody read it, the app becomes hard to change safely. Each new prompt risks breaking something built five prompts ago. Bringing in a developer later often means they spend days understanding the code before they can fix anything, and sometimes they recommend rebuilding.
Costs That Creep Up
Most AI app builders and coding tools price by credits, messages or usage. Fixing a stubborn bug can take dozens of prompts, and each one draws down your allowance. Hosting and database costs also start once real users arrive. Check limits before committing, for example in our Supabase pricing breakdown or the Cursor pricing guide.
How to Vibe Code Safely
You don’t need to become a developer to lower the risks. A short checklist covers most of them:
- Keep real data out of early versions. Use test names and fake phone numbers until you’ve checked who can see what.
- Ask the AI to review its own security. A prompt such as “check this app for exposed data, missing access rules and secrets in the code” catches some issues. It is not a substitute for a human review, but it’s better than nothing.
- Turn on database access rules. If your tool uses Supabase or a similar backend, confirm row-level security or equivalent is enabled on every table.
- Never paste API keys into prompts or front-end code. Use the tool’s secrets or environment settings.
- Use version control or snapshots. Most builders offer restore points. Save one before every big change.
- Separate test and live environments. Don’t let an agent work directly on the database real users depend on.
- Get a developer to review anything public. Before taking payments or personal data, an hour or two of review by someone who reads code is cheap insurance.
Is Vibe Coding Real Programming?
This is the argument that follows the term everywhere, and both sides have a point. Critics say that if you can’t read or debug the code, you’re not programming, you’re operating a tool, and the results show it once software has to be maintained. Supporters say programming has always moved to higher levels of abstraction, from assembly to high-level languages to frameworks, and natural language is the next layer.
A more useful framing is that vibe coding moves the skill rather than removing it. The person still needs to describe requirements precisely, break problems into steps, test edge cases and notice when something is wrong. Those are core programming skills. What vibe coding drops is the ability to verify the code directly, and that is exactly the skill the risks above call for.
How to Start Vibe Coding
- Pick a small, low-stakes project. A personal tracker, a page for a side project, or an internal tool for your team.
- Choose a tool by your comfort with code. An AI app builder if you never want to see code; Cursor or Claude Code if you’re willing to read it.
- Write a detailed first prompt. Cover users, main actions, data stored and roughly how it should look. Vague prompts produce generic apps.
- Build one feature at a time. Smaller requests are easier for the AI to get right and easier for you to check.
- Test like a user who’s trying to break it. Empty fields, wrong inputs, two people booking the last spot, opening admin pages while logged out.
- Run through the safety checklist before sharing it. Especially before any real data goes in.
