# Secure Vibe Coding

> Part of the NocoDB documentation (Apps). Index of all pages: https://nocodb.com/llms.txt. Any docs page is available as Markdown by adding `.md` to its URL.

URL: https://nocodb.com/docs/apps/security
Last updated: 2026-10-05

How NocoDB Apps keep AI-built work apps safe: teams and action grants, record rules, reviewed public pages, secrets in connections, scoped API tokens, environments and version restore.

<AskNocoAI>
  <Prompt>
    Let only [the managers team] [approve expenses]
  </Prompt>

  <Prompt>
    Let the [Members] team see only the [tickets] assigned to them
  </Prompt>

  <Prompt>
    Which actions can visitors run without signing in?
  </Prompt>
</AskNocoAI>

NocoDB Apps make vibe coding safe for enterprise-grade work apps. NocoAI writes the app, but the app can reach data only through **actions**. NocoDB checks every action against the access of the person who runs it. The access rules are part of the app from the first build, not a step that you add later.

## How NocoDB keeps an app safe

| Layer                            | What NocoDB does                                                                                                                                                                                           | Where to set it                                                                         |
| -------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------- |
| **Who can open the app**         | A person can open the app only when they are in a team that has at least one grant. People you invite to the app get no other access to the base.                                                          | [Members and teams](/docs/apps/members-and-teams)                                       |
| **What each person can do**      | Each team has a list of the actions its members can run. Actions are the only way that the app reads or changes data and calls other services.                                                             | [Grant actions to a team](/docs/apps/members-and-teams#grant-actions-to-a-team)         |
| **Which records each team sees** | Record rules, for example "members see only their own requests", use NocoDB [record-level security](/docs/product/collaboration/record-level-security).                                                    | [Limit records for each team](/docs/apps/members-and-teams#limit-records-for-each-team) |
| **What is public**               | An app has no public pages until you ask for them. A deploy that makes pages public, or lets visitors run actions, needs a review first. NocoDB limits how many actions each visitor can call each minute. | [Public access](/docs/apps/public-access)                                               |
| **Where secrets live**           | API keys and passwords stay in connections and workspace integrations, not in the code of the pages.                                                                                                       | [Connections](/docs/apps/connections)                                                   |
| **What programs can do**         | An app API token can never do more than the person who created it. You choose its actions and its expiry date.                                                                                             | [App API and MCP](/docs/apps/api-and-mcp)                                               |
| **What the in-app AI can do**    | The app assistant runs only the actions that the person in the chat can run.                                                                                                                               | [Assistant](/docs/apps/assistant)                                                       |

## Safe changes

A change to a live work app must not break the work of the people who use it. NocoDB Apps give you these controls:

| Control               | What it does                                                                                                                                                                                |
| --------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Live preview**      | Every change shows first in the [AI app builder](/docs/apps/app-builder) preview. People who use the app see it only after you deploy.                                                      |
| **Preview as a team** | **Viewing as** shows the app as a member of each team sees it, before you deploy.                                                                                                           |
| **Deploy review**     | A deploy that deletes data, makes pages public or lets visitors run actions shows what changes, and waits for you to confirm. See [Review a deploy](/docs/apps/deploy-app#review-a-deploy). |
| **Environments**      | Build and test changes in a copy of the base, for example **Staging**, then release them with one deploy. See [Environments](/docs/apps/environments).                                      |
| **Version history**   | Every deploy is a numbered version. Restore an earlier version with one click. See [Version history](/docs/apps/deploy-app#version-history).                                                |

## Who can build

Only base members with the **Owner** or **Creator** role can build, change and deploy an app. Every other person uses the app through the teams and grants that you set. See [Who can do what](/docs/apps#who-can-do-what).

## Good to know

* Team grants and public pages take effect only when you deploy. Changes to **Theme** and **Assistant** apply without a deploy.
* When one page of an app is public, anyone can download the code of the app pages. Keep secrets in actions and connections.
* Removing a person from a team removes only what that team allows in the app. Their base access does not change.

## Availability

| Capability                                                                 | Plan                          |
| -------------------------------------------------------------------------- | ----------------------------- |
| Teams, action grants, public access, deploy review and version history     | Every plan that includes Apps |
| App API tokens and the app MCP server                                      | Plus and above                |
| Record-level security for app teams, environments and per-user connections | Scale and above               |

## Related

* [Members and teams](/docs/apps/members-and-teams)
* [Public access](/docs/apps/public-access)
* [Deploy an app](/docs/apps/deploy-app)
* [Record-level security](/docs/product/collaboration/record-level-security)

---

## Related pages

- [Apps](https://nocodb.com/docs/apps.md): NocoDB Apps is an AI app builder for creating enterprise-grade work apps: describe the app, and NocoAI builds it on the data you already have, with teams, permissions, an API and an MCP server.
- [Vibe Coding with NocoDB Apps](https://nocodb.com/docs/apps/vibe-coding.md): Vibe coding is making software by describing it to AI. NocoDB Apps bring vibe coding to enterprise-grade work apps, on your own data, with teams, permissions and safe deploys.
- [Create an App](https://nocodb.com/docs/apps/create-app.md): Create a NocoDB app with AI: describe the app, and NocoAI builds it on your data. Start from the App tile in a base, with Build with AI, or in the NocoAI chat.
- [AI App Builder](https://nocodb.com/docs/apps/app-builder.md): Build and change enterprise-grade work apps in NocoDB's AI app builder: describe a change to NocoAI in the chat, and test it in the live preview.
- [Data for Apps](https://nocodb.com/docs/apps/data.md): Build NocoDB apps on the data you already have: NocoDB tables, your own PostgreSQL or MySQL database, and data that syncs from tools such as GitHub and HubSpot, with no record limit.
- [Members and Teams](https://nocodb.com/docs/apps/members-and-teams.md): Control who can use a NocoDB app and what they can do in it with app teams, members and action grants.
- [Public Access](https://nocodb.com/docs/apps/public-access.md): Make pages of a NocoDB app public, and choose which actions visitors can run without signing in.
- [Deploy an App](https://nocodb.com/docs/apps/deploy-app.md): Deploy a NocoDB app to make the current build live at its address, review risky changes before they go live, and restore an earlier version.
