PRD 003 - Go live Saturday, October 10, 2026
Status: Working plan. Written 2026-10-01, late evening. Section 2 is the brief for the CTO review on Friday morning. Owner: Sheila. Builder: Claude Code, in wtf-app, wtfisai-web, and a new wtf-builders repo. Where things are: web app on staging at staging.wtfisai.co, admin at /admin on staging only, website live at wtfisai.co. Production does not exist yet.
1What goes live on October 10
| Live on day one | Not yet |
|---|---|
| Free plan flow: sign in with an email code, intake, generated plan | The 101 course content (waits on the Storylane recordings) |
| Library with the Free shelf downloadable | Course purchase at $500 (stays "coming" with Notify me) |
| Three paid playbooks at $29 each, bought with a card inside the app | The $79 bundle of three (second Stripe pass, see 4.3) |
| Marketing opt-in captured at sign-up | Syncing the list to Kit or another email tool |
| Website pointing every CTA at the app, plus a Sign in link | Separate product pages on the website |
| Community card visible as "coming" | The $10 a month community subscription |
builders.wtfisai.co behind Cloudflare Access, holding this plan and the PRDs | The iOS app |
Decided 2026-10-01: paid playbooks are $29 each and $79 for three. Builders is a private documentation site behind Cloudflare Access. Target go-live is Saturday, October 10.
Decided 2026-10-01, late: money goes to the Tandem Stripe account. Builders is live at wtf-builders.pages.dev pending the custom domain and Access (section 6). Playwright smoke tests run against staging and production from wtf-app (section 2.7). Still open, needed by Sunday night: production gate on day one, open or allowlisted.
2The technical brief, for the CTO review on Friday
Everything below is already built or decided unless marked proposed. Questions for the CTO are at the end.
2.1 Repos and folders
One product, three repos. There are no per-environment folders. Environments are branches and deploy targets, not copies of the code.
| Repo | What it is | Deploys to |
|---|---|---|
wtf-app | The web app and its API. React + Vite front end, Cloudflare Worker back end, Supabase migrations, the content manifest | staging branch -> staging.wtfisai.co, main branch -> app.wtfisai.co |
WTFISAI-APP | Spec, PRDs, decisions, mockups. Nothing runs from it | Published as read-only pages, soon via builders |
wtfisai-web | The marketing site, Astro on Cloudflare Pages | wtfisai.co |
The iOS app, when it starts, gets a fourth repo. It will have two Xcode build schemes, Staging and Production, that differ only in the API base URL and the Supabase keys. Same rule: one codebase, two targets.
Why not wtf-app/staging-webapp and wtf-app/production-webapp: two folders drift. A fix lands in one and not the other, and within a month nobody knows which is true. A branch merge from staging to main is the only promotion step, and the diff between them is always visible.
2.2 Hosting and runtime
- Cloudflare Workers, git-connected. One Worker per environment:
wtf-app-stagingandwtf-app. The Worker serves the static bundle and answers/api/*. Workers rather than Pages because the app runs the plan agent server-side and will hand out signed download links. - Cloudflare Workflows run the plan agent as a durable multi-step job, so a slow model call survives a dropped connection.
- Cloudflare R2, proposed for this week: one private bucket for paid PDFs. The Worker checks the purchase and issues a short-lived signed URL. Free magnets stay in the public bundle.
- Secrets live in Cloudflare as Worker secrets, set with
wrangler secret put, never in the repo. Public-safe config is inwrangler.jsonc.
2.3 Identity and data
- Supabase Auth, email code only. No passwords, no social login, no Sign in with Apple at MVP. One project per environment:
wtfisai-stagingexists,wtfisai-prodis created this weekend. - Sign-in emails are sent through Resend over SMTP from
hello@wtfisai.co. Both Supabase templates, Confirm signup and Magic Link, carry the code, because Supabase uses one for new addresses and the other for returning ones. - Postgres in Supabase for
profiles,plans,waitlists, and this weekpurchases. Row Level Security is on with no policies, so the browser's publishable key can read nothing. All data access goes through the Worker with the secret key after verifying the user's JWT. - The future iOS app calls the same
/api/*routes with the same Supabase token.
2.4 Payments, proposed design
- Stripe Checkout, hosted by Stripe. The app never touches card data. One item per checkout, no cart.
- Buy button -> Worker creates a Checkout Session with the Stripe price id from the manifest and the user id in metadata -> Stripe hosted page -> redirect back to the Library.
- A webhook
/api/stripe/webhookverifies Stripe's signature and, oncheckout.session.completed, inserts a row inpurchases. The Library reads entitlements from that table, so the item flips to Yours. The redirect is cosmetic. The webhook is the source of truth. - Promotion codes are on in Checkout from day one, which is how discount and affiliate codes work without building a code system.
- Test mode on staging, live mode on production. Two sets of keys, two webhook endpoints, both registered in the Stripe dashboard.
- The $79 bundle is a fourth Stripe product that grants three entitlements in one webhook event. Second pass.
2.5 Admin and the builders site
- Admin is a CRM at
/admin, allowlisted by email in the Worker config. By policy from September 13 it is reachable only on staging and reads production data through read-only secrets. Admin routes return 404 on production, so the production Worker holds no path to customer data beyond each user's own. - Builders, proposed: a static site at
builders.wtfisai.co, generated from the markdown inWTFISAI-APPandWTF-DESIGN, behind Cloudflare Access with Google sign-in restricted to a list of emails. Zero cost under fifty users. Admin gets a Builders link in its submenu. Admin stays data, builders stays documentation.
2.6 Testing, proposed
- Playwright lives in
wtf-app/tests.npm run e2e:stagingandnpm run e2e:productionrun the same suite against each environment on desktop Chrome and a phone profile. Four smoke tests pass on staging tonight: health names the environment, the welcome form renders with no console errors, the library refuses without a session, admin is guarded on staging and 404 on production. - Real sign-in test: the suite mints the email code through the Supabase admin API instead of reading an inbox, types it, and expects the path screen. It needs the environment's Supabase URL and secret key in the shell and skips without them. First real run is the Friday morning session with the CTO.
- GitHub Actions workflow
e2e.ymlruns the suite on every push tostagingandmain, after waiting for the Worker to answer. It is committed locally and not yet pushed, because the GitHub login on this laptop lacks theworkflowscope. One command fixes it:gh auth refresh -h github.com -s workflow, thengit push.
2.7 Questions for the CTO
- Stripe account, decided: Tandem. Anything you would flag about selling under a brand of Tandem and Community, Inc. from that account, for payouts or reporting?
- Production gate. Open sign-ups from the moment
app.wtfisai.coanswers, or an allowlist until the 10th? The admin policy already makes the staging allowlist the admin list, so this only affects production. - R2 signed URLs for a $29 PDF: is a sixty-second link with the user id in the object key enough, or do you want per-download logging in the
purchasestable from day one? - Webhook idempotency. Plan is a unique constraint on the Stripe session id so a retried webhook is a no-op. Anything else you would insist on before live mode?
- Backups. Supabase Pro has daily backups. Staging is on the free tier. Should production start on Pro ($25 a month) on day one, or only once there are paying customers?
- Playwright. Is minting the code through the Supabase admin API acceptable for the sign-in test, or do you want a real inbox? What else belongs in the suite before live mode: a test-mode purchase end to end?
- Anything in 2.1 to 2.7 you would do differently while it is still cheap to change.
3Working backwards from the 10th
Today is Thursday, October 1. Nine days. The weekend is the build window. Monday to Wednesday is content and polish. Thursday is a freeze. Friday is slack.
| Day | Sheila | Claude Code | Done looks like |
|---|---|---|---|
| Fri Oct 2 | Morning: CTO review of section 2. Afternoon: create wtfisai-prod in Supabase (section 5), create the three Stripe products in test mode (section 4), keys into the keys document | Opt-in checkbox on the welcome screen, stored and shown in admin. purchases migration. Builders repo scaffolded | CTO notes captured as changes to this PRD. Production keys exist. |
| Sat Oct 3 | Click through a test purchase on staging with card 4242. Review the three playbook PDFs and blurbs for final | Stripe Checkout, webhook, entitlements, R2 private bucket, signed downloads, all on staging in test mode | A test card buys a playbook on staging and it flips to Yours. The PDF downloads only for the buyer. |
| Sun Oct 4 | Cloudflare: connect main to the production Worker. Sign in on app.wtfisai.co from your phone. Decide the gate | Production secrets pushed, migrations 0001 to 0006 run, admin Live CRM connected to production. Website: CTAs to the app, Sign in link, Library section with cards. Builders live behind Access | app.wtfisai.co answers, a real sign-in works on phone and desktop, the site sends people to it. |
| Mon Oct 5 | Testimonials: three quotes and approvals. Final names for the Library cards. Email tool decision if you want sync in week one | Content pass: manifest names, blurbs, Source lines removed. Playbook PDFs into R2. Testimonials in | Every Library card has its final name, blurb, price, and status. |
| Tue Oct 6 | Stripe: switch to live mode, create the same three products live, keys into the keys document | Live keys on production, live webhook registered. Website Library cards match the app | Production is ready to take a card. Nothing bought yet. |
| Wed Oct 7 | Buy one playbook on production with your own card. Refund it in Stripe | Watch the webhook, the entitlement, the download, and the refund. Fix anything that breaks | One real dollar in and out, with the purchase visible in admin. |
| Thu Oct 8 | Full pass on phone and desktop as a new user: sign up, plan, free download, buy, sign out, sign back in | Freeze. Only fixes from your pass | A list of zero, or a list we fix Friday. |
| Fri Oct 9 | Rest, or write the launch post | Buffer for Thursday's list | Nothing new ships. |
| Sat Oct 10 | Open the gate if it was closed. Announce | On call | Live. |
The one rule: anything not on this table waits until the 11th. The plan gap section, the 101 modules, the community subscription, the bundle, Kit sync, and iOS are all after.
4Stripe, step by step
4.1 Sheila, Friday, in the Stripe dashboard (test mode)
- Confirm which account, per CTO question 1. Toggle Test mode on.
- Products -> Add product, three times:
| Name in Stripe | Price | Our id in the manifest |
|---|---|---|
| Playbook 02: Which AI tool do I actually use? | $29.00 one time | pb-02-which-tool |
| Playbook 03: Audit Your Business for the AI Economy | $29.00 one time | pb-03-ai-audit |
| Playbook 04: Warm intros | $29.00 one time | pb-04-warm-intros |
- Copy each price id (starts
price_) into the keys document next to our id. - Developers -> API keys -> copy the test secret key (starts
sk_test_) into the keys document. - Developers -> Webhooks -> Add endpoint:
https://staging.wtfisai.co/api/stripe/webhook, eventcheckout.session.completed. Copy the signing secret (startswhsec_) into the keys document. - Products -> Coupons: one coupon, 50% off, with promotion code
TEST50, to prove codes work.
Tuesday, repeat 2 to 5 with Test mode off, endpoint https://app.wtfisai.co/api/stripe/webhook. Live keys go in the keys document under a separate heading.
4.2 Claude Code, Friday and Saturday
- Migration
0006_purchases.sql:purchases(user_id, item_id, stripe_session_id unique, stripe_payment_intent, amount_cents, currency, promo_code, status, created_at, refunded_at). RLS on, no policies. - Manifest gains
stripePriceIdper paid item, read from env so staging and production can differ. POST /api/checkout/:itemIdcreates the Checkout Session and returns the URL.POST /api/stripe/webhookverifies the signature and records the purchase.GET /api/libraryincludesownedper item frompurchases.- Buy button on the Library and item pages opens Checkout. Return page shows Yours.
- R2 bucket
wtf-paid, bound to the Worker.GET /api/download/:itemIdchecks ownership and returns a signed URL that lives sixty seconds. - Admin People card shows purchases. Admin gains a Purchases list.
- Refund handling:
charge.refundedmarks the row refunded and the item locks again.
4.3 Second pass, after the 10th
The $79 bundle as a fourth product granting three entitlements. The community at $10 a month as the first subscription, with customer.subscription.* events. The course at $500 with a one-year expiry.
5Production, step by step
Sheila, Friday afternoon, in dashboards. Each line was already done once for staging.
- Supabase: New project
wtfisai-prod, same org, region US East. Settings -> API: copy Project URL, publishable key, secret key into the keys document. - Supabase -> Authentication -> Emails -> SMTP Settings: enable custom SMTP. Host
smtp.resend.com, port465, userresend, password a new Resend API key namedsupabase-production, senderhello@wtfisai.co, sender nameWTF is AI. - Supabase -> Authentication -> Emails -> Templates: paste the code body into both Confirm signup and Magic Link. Both must contain
{{ .Token }}. - Supabase -> Authentication -> URL Configuration: Site URL
https://app.wtfisai.co. Rate limit for emails 100 an hour. - Supabase -> Authentication -> Providers -> Email: sign-ups on or off per the gate decision. Can flip any time.
- Cloudflare -> Workers & Pages -> Create -> Import repository
wtf-app. Namewtf-app, production branchmain, buildnpm run build:production, deploynpx wrangler deploy --env production. Non-production branch builds off. - Anthropic Console: a second API key named
wtf-app-production, into the keys document.
Claude Code then fills .env.production and the production vars, pushes the five secrets, runs migrations 0001 to 0006 in the production SQL editor with you, and confirms app.wtfisai.co answers.
6Builders
- Built 2026-10-01. Private repo
sheilala07/wtf-builders.build.pyrenders the markdown fromWTFISAI-APP/PRDs,WTFISAI-APP/docs,WTF-DESIGN, and its owncontent/folder (timelines, pricing sheet, messaging, product roadmap, the quiz brief) into one site../deploy.shbuilds and uploads. - Cloudflare Pages project
wtf-builders, live atwtf-builders.pages.dev. Custom domainbuilders.wtfisai.cois a dashboard step. - Cloudflare Access: Zero Trust -> Access -> Applications -> Self-hosted, domain
builders.wtfisai.co, policy Allow, include emails: the admin list. Login method Google, or a one-time PIN to the email, which needs no Google account. - Front page is this PRD's section 3 table, updated as days close.
- Admin gets a Builders entry in its submenu that opens
builders.wtfisai.coin a new tab.
7Website changes, Sunday
| Section | Today | Becomes |
|---|---|---|
| Nav | No account link | Sign in -> app.wtfisai.co |
| Hero CTA | Join the waitlist | Build my free plan -> app.wtfisai.co |
| Four ways | Four cards | Same four, buttons deep-link into the app's Library items |
| New: Library | Nothing | A row of cards, free and $29, each linking to the item in the app. The site shows, the app sells |
| Waitlist modal | Five steps | Notify me when the 101 opens, one field, feeds the app's waitlist |
| Our story CTA | Join the waitlist | Build my free plan |
No login, signup, or checkout is built on the website. The app owns identity and money. If a product page on the site ever earns its place through search traffic, it links to the same app item.
8Checklist
- Fri: CTO review done, changes folded into this PRD
- Fri:
wtfisai-prodcreated and configured, keys in the document - Fri: Stripe test products, test keys, test webhook,
TEST50 - Fri: opt-in captured on staging
- Sat: test purchase on staging flips to Yours, PDF downloads for buyer only
- Sun:
app.wtfisai.coanswers, real sign-in on phone and desktop - Sun: website CTAs, Sign in link, Library section live
- Sun:
builders.wtfisai.cobehind Access, this PRD on it - Sun: gate decision made and applied
- Mon: final names, blurbs, prices, testimonials
- Tue: Stripe live products and keys on production
- Wed: one real purchase and refund on production
- Thu: full new-user pass, list of fixes
- Sat Oct 10: live