WTF is AI BuildersInternal

Plans · updated 2026-10-01

PRD 003 - Go live Saturday, October 10, 2026

Status: Working plan. Written 2026-10-01, late evening. Section 2 is the brief for the CTO review on Friday morning. Owner: Sheila. Builder: Claude Code, in wtf-app, wtfisai-web, and a new wtf-builders repo. Where things are: web app on staging at staging.wtfisai.co, admin at /admin on staging only, website live at wtfisai.co. Production does not exist yet.

1What goes live on October 10

Live on day oneNot yet
Free plan flow: sign in with an email code, intake, generated planThe 101 course content (waits on the Storylane recordings)
Library with the Free shelf downloadableCourse purchase at $500 (stays "coming" with Notify me)
Three paid playbooks at $29 each, bought with a card inside the appThe $79 bundle of three (second Stripe pass, see 4.3)
Marketing opt-in captured at sign-upSyncing the list to Kit or another email tool
Website pointing every CTA at the app, plus a Sign in linkSeparate product pages on the website
Community card visible as "coming"The $10 a month community subscription
builders.wtfisai.co behind Cloudflare Access, holding this plan and the PRDsThe iOS app

Decided 2026-10-01: paid playbooks are $29 each and $79 for three. Builders is a private documentation site behind Cloudflare Access. Target go-live is Saturday, October 10.

Decided 2026-10-01, late: money goes to the Tandem Stripe account. Builders is live at wtf-builders.pages.dev pending the custom domain and Access (section 6). Playwright smoke tests run against staging and production from wtf-app (section 2.7). Still open, needed by Sunday night: production gate on day one, open or allowlisted.

2The technical brief, for the CTO review on Friday

Everything below is already built or decided unless marked proposed. Questions for the CTO are at the end.

2.1 Repos and folders

One product, three repos. There are no per-environment folders. Environments are branches and deploy targets, not copies of the code.

RepoWhat it isDeploys to
wtf-appThe web app and its API. React + Vite front end, Cloudflare Worker back end, Supabase migrations, the content manifeststaging branch -> staging.wtfisai.co, main branch -> app.wtfisai.co
WTFISAI-APPSpec, PRDs, decisions, mockups. Nothing runs from itPublished as read-only pages, soon via builders
wtfisai-webThe marketing site, Astro on Cloudflare Pageswtfisai.co

The iOS app, when it starts, gets a fourth repo. It will have two Xcode build schemes, Staging and Production, that differ only in the API base URL and the Supabase keys. Same rule: one codebase, two targets.

Why not wtf-app/staging-webapp and wtf-app/production-webapp: two folders drift. A fix lands in one and not the other, and within a month nobody knows which is true. A branch merge from staging to main is the only promotion step, and the diff between them is always visible.

2.2 Hosting and runtime

2.3 Identity and data

2.4 Payments, proposed design

2.5 Admin and the builders site

2.6 Testing, proposed

2.7 Questions for the CTO

  1. Stripe account, decided: Tandem. Anything you would flag about selling under a brand of Tandem and Community, Inc. from that account, for payouts or reporting?
  2. Production gate. Open sign-ups from the moment app.wtfisai.co answers, or an allowlist until the 10th? The admin policy already makes the staging allowlist the admin list, so this only affects production.
  3. R2 signed URLs for a $29 PDF: is a sixty-second link with the user id in the object key enough, or do you want per-download logging in the purchases table from day one?
  4. Webhook idempotency. Plan is a unique constraint on the Stripe session id so a retried webhook is a no-op. Anything else you would insist on before live mode?
  5. Backups. Supabase Pro has daily backups. Staging is on the free tier. Should production start on Pro ($25 a month) on day one, or only once there are paying customers?
  6. Playwright. Is minting the code through the Supabase admin API acceptable for the sign-in test, or do you want a real inbox? What else belongs in the suite before live mode: a test-mode purchase end to end?
  7. Anything in 2.1 to 2.7 you would do differently while it is still cheap to change.

3Working backwards from the 10th

Today is Thursday, October 1. Nine days. The weekend is the build window. Monday to Wednesday is content and polish. Thursday is a freeze. Friday is slack.

DaySheilaClaude CodeDone looks like
Fri Oct 2Morning: CTO review of section 2. Afternoon: create wtfisai-prod in Supabase (section 5), create the three Stripe products in test mode (section 4), keys into the keys documentOpt-in checkbox on the welcome screen, stored and shown in admin. purchases migration. Builders repo scaffoldedCTO notes captured as changes to this PRD. Production keys exist.
Sat Oct 3Click through a test purchase on staging with card 4242. Review the three playbook PDFs and blurbs for finalStripe Checkout, webhook, entitlements, R2 private bucket, signed downloads, all on staging in test modeA test card buys a playbook on staging and it flips to Yours. The PDF downloads only for the buyer.
Sun Oct 4Cloudflare: connect main to the production Worker. Sign in on app.wtfisai.co from your phone. Decide the gateProduction secrets pushed, migrations 0001 to 0006 run, admin Live CRM connected to production. Website: CTAs to the app, Sign in link, Library section with cards. Builders live behind Accessapp.wtfisai.co answers, a real sign-in works on phone and desktop, the site sends people to it.
Mon Oct 5Testimonials: three quotes and approvals. Final names for the Library cards. Email tool decision if you want sync in week oneContent pass: manifest names, blurbs, Source lines removed. Playbook PDFs into R2. Testimonials inEvery Library card has its final name, blurb, price, and status.
Tue Oct 6Stripe: switch to live mode, create the same three products live, keys into the keys documentLive keys on production, live webhook registered. Website Library cards match the appProduction is ready to take a card. Nothing bought yet.
Wed Oct 7Buy one playbook on production with your own card. Refund it in StripeWatch the webhook, the entitlement, the download, and the refund. Fix anything that breaksOne real dollar in and out, with the purchase visible in admin.
Thu Oct 8Full pass on phone and desktop as a new user: sign up, plan, free download, buy, sign out, sign back inFreeze. Only fixes from your passA list of zero, or a list we fix Friday.
Fri Oct 9Rest, or write the launch postBuffer for Thursday's listNothing new ships.
Sat Oct 10Open the gate if it was closed. AnnounceOn callLive.

The one rule: anything not on this table waits until the 11th. The plan gap section, the 101 modules, the community subscription, the bundle, Kit sync, and iOS are all after.

4Stripe, step by step

4.1 Sheila, Friday, in the Stripe dashboard (test mode)

  1. Confirm which account, per CTO question 1. Toggle Test mode on.
  2. Products -> Add product, three times:
Name in StripePriceOur id in the manifest
Playbook 02: Which AI tool do I actually use?$29.00 one timepb-02-which-tool
Playbook 03: Audit Your Business for the AI Economy$29.00 one timepb-03-ai-audit
Playbook 04: Warm intros$29.00 one timepb-04-warm-intros
  1. Copy each price id (starts price_) into the keys document next to our id.
  2. Developers -> API keys -> copy the test secret key (starts sk_test_) into the keys document.
  3. Developers -> Webhooks -> Add endpoint: https://staging.wtfisai.co/api/stripe/webhook, event checkout.session.completed. Copy the signing secret (starts whsec_) into the keys document.
  4. Products -> Coupons: one coupon, 50% off, with promotion code TEST50, to prove codes work.

Tuesday, repeat 2 to 5 with Test mode off, endpoint https://app.wtfisai.co/api/stripe/webhook. Live keys go in the keys document under a separate heading.

4.2 Claude Code, Friday and Saturday

  1. Migration 0006_purchases.sql: purchases (user_id, item_id, stripe_session_id unique, stripe_payment_intent, amount_cents, currency, promo_code, status, created_at, refunded_at). RLS on, no policies.
  2. Manifest gains stripePriceId per paid item, read from env so staging and production can differ.
  3. POST /api/checkout/:itemId creates the Checkout Session and returns the URL. POST /api/stripe/webhook verifies the signature and records the purchase. GET /api/library includes owned per item from purchases.
  4. Buy button on the Library and item pages opens Checkout. Return page shows Yours.
  5. R2 bucket wtf-paid, bound to the Worker. GET /api/download/:itemId checks ownership and returns a signed URL that lives sixty seconds.
  6. Admin People card shows purchases. Admin gains a Purchases list.
  7. Refund handling: charge.refunded marks the row refunded and the item locks again.

4.3 Second pass, after the 10th

The $79 bundle as a fourth product granting three entitlements. The community at $10 a month as the first subscription, with customer.subscription.* events. The course at $500 with a one-year expiry.

5Production, step by step

Sheila, Friday afternoon, in dashboards. Each line was already done once for staging.

  1. Supabase: New project wtfisai-prod, same org, region US East. Settings -> API: copy Project URL, publishable key, secret key into the keys document.
  2. Supabase -> Authentication -> Emails -> SMTP Settings: enable custom SMTP. Host smtp.resend.com, port 465, user resend, password a new Resend API key named supabase-production, sender hello@wtfisai.co, sender name WTF is AI.
  3. Supabase -> Authentication -> Emails -> Templates: paste the code body into both Confirm signup and Magic Link. Both must contain {{ .Token }}.
  4. Supabase -> Authentication -> URL Configuration: Site URL https://app.wtfisai.co. Rate limit for emails 100 an hour.
  5. Supabase -> Authentication -> Providers -> Email: sign-ups on or off per the gate decision. Can flip any time.
  6. Cloudflare -> Workers & Pages -> Create -> Import repository wtf-app. Name wtf-app, production branch main, build npm run build:production, deploy npx wrangler deploy --env production. Non-production branch builds off.
  7. Anthropic Console: a second API key named wtf-app-production, into the keys document.

Claude Code then fills .env.production and the production vars, pushes the five secrets, runs migrations 0001 to 0006 in the production SQL editor with you, and confirms app.wtfisai.co answers.

6Builders

7Website changes, Sunday

SectionTodayBecomes
NavNo account linkSign in -> app.wtfisai.co
Hero CTAJoin the waitlistBuild my free plan -> app.wtfisai.co
Four waysFour cardsSame four, buttons deep-link into the app's Library items
New: LibraryNothingA row of cards, free and $29, each linking to the item in the app. The site shows, the app sells
Waitlist modalFive stepsNotify me when the 101 opens, one field, feeds the app's waitlist
Our story CTAJoin the waitlistBuild my free plan

No login, signup, or checkout is built on the website. The app owns identity and money. If a product page on the site ever earns its place through search traffic, it links to the same app item.

8Checklist