Base44 built the whole stack. We make it hold up for real users
Base44 is the most complete of the AI builders: it generates the React frontend, the data model, the auth, the backend functions and the hosting in one place. That is also why its problems are harder to see — there is no separate database or server to inspect. Here is what its output gets wrong in production, and what we do about it without taking Base44 away from you.
Taking a Base44 app to production means tightening what the platform's all-in-one model lets you skip: entity security rules broad enough that any signed-in user can read every record, backend functions reachable over plain HTTP that run with service-role access, API keys and paid integrations called straight from the browser, a schema that changed shape without migrations, and a Publish button with no test gate, preview environment or error tracking. Gen2Prod works through Base44's two-way GitHub sync, so you keep prompting in Base44 afterwards; the audit is free and every fix is a fixed price from $290.
What Base44 generates
A React single-page app, plus a managed backend: entities, auth, Deno-powered backend functions, integrations and hosting
Data
Entities defined as JSON Schema, with row-level and field-level security rules you are expected to write
Where it lives
Base44 hosting on app.base44.com or a custom domain; a GitHub repo with two-way sync on the Builder plan and above
What we work in
The synced GitHub repo, by pull request on main, so the Base44 editor keeps working when we're done
What it costs
Free audit first, then from $290 per fix; full sprint quoted in 24 hours
What Base44 apps get wrong in production
The list we find on most Base44 projects, in the order it matters. Each one links to the service that fixes it.
Entity rules that let every user see every record
Base44 secures data with per-entity read and write rules, and a rule written as "any logged-in user" is one prompt away from "only the record's creator". The difference is whether customer A can open customer B's invoices. We write the rules per entity and per field, and prove each one with a request that should fail.
A function invoked through the SDK carries the user's identity; one called over plain HTTP — a webhook, a cron, a public endpoint — has no user and runs with `asServiceRole`, which bypasses every entity rule. Any such function gets input validation, a secret or signature check, and the narrowest data access that still works.
Base44 makes it easy to call an LLM, send an email or hit a third-party API straight from a page, because that is where the prompt was. Anything that costs money or sends mail moves into a backend function with a rate limit, and the key moves into `secrets`, read inside the handler rather than at module level.
A schema that changed shape without anyone noticing
Entities update without migrations, which is wonderful while you are iterating and quietly dangerous afterwards: records created under the old shape keep the old fields, and nothing tells you. We reconcile the data against the schema, add the constraints and reference fields the queries depend on, and write down what each entity means.
The generator tends to keep adding to the page it started with: fetching, state, integrations and markup in one file that Base44 itself edits less reliably as it grows. We split it into components small enough that a prompt changes one thing at a time.
Deploys are a click, with no tests in the way and no preview environment. Once GitHub is connected, Base44's own version history stops covering earlier versions, so the repo is the only rollback you have. We add CI that runs the tests on every push to main, tag releases, and make the rollback path a command rather than a hope.
A backend function that times out at its five-minute limit, an integration that starts failing, a rule that rejects a write — all of it is silent unless something reports it. We add error tracking, uptime checks and alerts that reach a human.
A cleanup isn’t a rebuild. Base44 did real work, and most of it stays.
The React components — they are ordinary React, and Base44 knows how to edit them
Your entity schemas, on the whole; we add rules, reference fields and constraints rather than redesign them
Base44's auth and hosting, if they fit — moving off them is a separate decision and rarely necessary
The two-way GitHub sync, so the Base44 editor keeps working on the cleaned-up code
Base44 — questions we get asked
Can I keep building in Base44 after the cleanup?
Yes, and that is the point. We work by pull request in the GitHub repo Base44 syncs with (two-way sync needs the Builder plan or higher, and only the main branch), so every fix lands in the editor as well. We leave the project in smaller files with a short README that tells Base44 — and any human developer — where things belong.
Why can other users see data that isn't theirs in my Base44 app?
Almost always an entity rule that is too broad. Base44 secures each entity with read and write rules, and a rule that admits any logged-in user is the easiest one to write. The fix is a rule scoped to the record's creator or organisation, plus field-level rules on anything sensitive, each proven with a request that should be refused. The free audit lists every entity where that is currently not the case.
Do I have to move off Base44 to go to production?
No. Base44's hosting, auth and backend are a reasonable place to run a product with real users, and most of what needs fixing is inside the app, not under it. If you need your own database for SQL access, backups you control, or a compliance requirement, we'll say so and quote the migration separately — but we'd rather tell you it isn't needed.
How much does it cost to make a Base44 app production-ready?
The audit is free and comes back within 48 hours with a price against each finding. A single fix — the entity rules, say, or moving a paid integration server-side — starts at $290. Taking a typical Base44 app all the way, with security, data integrity, a deploy gate and monitoring, is quoted after the audit and usually lands well under the cost of a month of a freelancer.