
The Spare Key Everyone Already Has
An API that cannot find its signing key should not invent one. This week I found one that did, and it fell back to a key already sitting in the repo.
// writing
Notes on building full-stack and AI projects, and the lessons learned along the way, written to be readable whether or not you write code.

An API that cannot find its signing key should not invent one. This week I found one that did, and it fell back to a key already sitting in the repo.

A crew of AI agents fixed about eighty findings in one of my apps this week. The rule that made it work: an agent's report is testimony, not evidence.

I added a safety net to make failed data loads impossible to miss. Then I watched a page fail to load and say nothing at all.

I wrote a journal entry at breakfast and my app insisted the day had not happened yet. The code asked what day it is, but never asked whose day.

I know my own apps too well to test them. This week I planned ContentForge's test pass from the seat that matters, a paying subscriber who starts with nothing.

I wanted an audit and fix loop that runs unattended all night. The answer was not a smarter agent. It was a dumber one that runs a single phase and exits.

My tool generated a preview website for a real business and it read as generic slop. The fix was not a better prompt. It was encoding my taste somewhere the machine can reach it.

A backend with 748 passing tests still could not boot on the database it was built to ship on. The tests were never wrong. They just never ran the part that broke.

I let AI agents write code while I sleep. This week I made sure they cannot quietly run up a bill while they do it.

A local-first sync client was designed properly. The server behind it stored everything in memory and lost it all on restart. That was the right order.
No matches, try another word.