Workshop: your app with accounts, data and payments
Lesson 2 of the module "Get compliant, deliver and go live" in the course "Add a database, authentication and payments to your app".
Lesson objective
By the end of this workshop, you will have delivered your own app with user accounts, stored data protected by RLS and a Stripe test payment held by webhook, together with a verification file that proves each piece and that you can have reviewed.
Where it fits
Get compliant, deliver and go live
What must be settled before welcoming real users and taking real payments?
Lessons in this module
- GDPR and switching to live mode
- Workshop: your app with accounts, data and payments (this lesson)
- Exit kit and application plan
What you will learn in the course
This lesson is part of the course Add a database, authentication and payments to your app
- Decide what stays in the browser and what must move to the server, and choose a back-end platform that fits your app, your budget and your data.
- Manage environment variables and secrets (public VITE_ variables, secret keys on the server only, .env files kept out of Git, rotation after a leak).
- Have the agent design a data model and its migrations, then check that data is actually stored and linked to the right user.
- Write, have written and test Row Level Security rules that guarantee each user only accesses their own data and that plan limits are enforced in the database.
- Add sign-up, sign-in, sign-out and password reset, and verify the flows, email confirmation and redirect URLs.
- Integrate Stripe Checkout in test mode (product, price, session created on the server, test cards) without exposing the secret key.
- Hold payment status on the server with signed, deduplicated Stripe webhooks, tested with the Stripe CLI or the Dashboard.
- Apply GDPR basics (information, account deletion, processors) and a go-live checklist before taking real payments.
Related courses
- Build and ship a web app with an AI coding agentJunior · ~2 hr 45 min
- Work with Claude Code on a real project: context, planning, reviewAdvanced · ~3 hr
- Git for PMs: ship as a team without putting production at riskAdvanced · ~3 hr 30 min