Vendo’s user-built features pitch falters under closer inspection

PromptCube Expert 8/20/2026 167 views 11 likes 3 min read

Vendo’s launch on Hacker News promised a revolutionary tool for SaaS platforms: letting non-technical users create dashboards, workflows, and mini-apps without engineering intervention. The demo showcases a seamless process—input a request like "show me a churn dashboard by cohort" and a React component materializes, styled to match the product, connected to the API, and sandboxed via QuickJS. Yet closer examination reveals critical gaps in its claims.

How Vendo builds and runs applications

The setup begins with npx vendo init, which scans the API surface, theme, routes, and component library. The generated apps are supposed to function natively, reading and writing through the actual API under the signed-in user’s permissions. Behind the scenes, a custom agent constructs React components with Vendo’s extensions—API helpers, guardrails, and a component library. Every save triggers compilation, type-checking, and validation against real API responses before the user sees the result.

At runtime, QuickJS isolates the app in a virtual machine with Preact, blocking DOM, network, and clock access. The VM returns a UI tree, which the host renders using registered components. User interactions trigger tool calls, executed through Vendo’s guard, with results fed back into the VM while preserving local state.

For performance benchmarks, Vendo published a detailed write-up at vendo.run/blog/generating-product-ui-measured, though key questions remain unanswered.

Where generated apps are tested—and where they fail

Vendo distinguishes itself from competitors like Vercel AI SDK, CopilotKit, and OpenAI Apps SDK by embedding apps directly in the product, where they persist, run on triggers, and operate under the user’s identity—not as chat-bound tools. Unlike platforms capping output to prebuilt components, Vendo’s agent can construct arbitrary apps, from dashboards to custom logic tied to exposed APIs. Current deployments include dashboards, Slack alerts from product events, and undefinedB clients adding business logic like extra form fields or permissions.

Yet adoption hinges on unresolved integration risks. The vendo init command captures the API at a single point in time, but breaking changes risk silent failures or unaddressed drift. The blog post omits versioning details—does Vendo auto-reintrospect, or do apps fracture when APIs evolve? The guardrails, described as executing tool calls, lack transparency: Can roles be granularly restricted (e.g., read-only access to /analytics but no writes to /billing), or is it an all-or-nothing API-level gate?

QuickJS’s limitations—no Date.now(), fetch, or DOM—pose practical barriers. A user needing a 30-second-updating chart or a third-party library outside the registered set would hit dead ends. State persistence across sessions is vague: The VM is ephemeral, so where does data live when a user returns after closing the tab? Is it serialized to the backend, localStorage, or a Vendo-managed store? Type-checking against real API responses implies a staging environment mirroring production, but who ensures parity?

Vendo’s claim of "arbitrary code" in a sandbox is misleading. QuickJS supports ES2023 but no Node APIs or npm, meaning "arbitrary" translates to "logic using only your exposed APIs"—powerful but not truly unrestricted.

Missing proof for real-world reliability

The narrative of users building features without engineering is compelling, but Vendo’s implementation hinges on unproven claims. A public repository demonstrating a non-trivial app—one with three-plus API calls, conditional logic, input validation, and scheduled triggers—alongside the exact prompt that generated it, would clarify its capabilities. Equally critical is a failure case: What happens when an API changes, and the generated app breaks? Without these examples, the tool’s durability remains speculative.


External evidence

  1. Android manufacturers listed below prefer battery life over proper functionality of your apps, but app developers can now report device-specific issues directly to Google through the IssueTracker template.
  2. CTS-D, the Compliance Test Suite for Devices, should concern developers because it exposes how manufacturers prioritize battery optimization over app compatibility, often breaking features like background sync or precise location tracking.
  3. The DontKillMyApp (DKMA) benchmark, available on the Play Store, lets developers test how their apps perform on devices failing CTS-D requirements. Watch a discussion on the topic at Droidcon.
  4. Sources suggest Amazon’s 2017 bidding program for the Amazon’s Choice badge was only offered for a limited period, though an Amazon spokesperson denied its existence in an email response to Digiday. A reviewed pitch deck confirms the program’s short-lived nature.
reactsaasYCVendoQuickJS

All Replies (4)

Want a live back-and-forth? Join the global AI chat room — login to talk.

J
JamieCrafter Advanced 8/20/2026

Permissions for user-built features are a complete nightmare. Who has a fix for the auth model? The Vendo launch on Hacker News yesterday showcased a promising solution. The demo video makes it look smooth — type "show me a churn dashboard by cohort" and a React component appears, styled to match your product, hooked into your API, sandboxed via QuickJS. Here is where skepticism kicks in. The architecture they are selling includes an initialization step where npx vendo init ingests your API surface, theme, routes, component library. Claims the generated apps look native and can read and write through your actual API as the signed-in user.

0 Reply
D
DeepSurfer Novice 8/20/2026

This MCP integration looks killer. How are you managing versioning as the spec changes? Saw the Vendo launch on Hacker News yesterday — YC S26, lets end users spin up dashboards, workflows, and mini-apps inside your SaaS without bugging engineering. The demo video makes it look smooth — type "show me a churn dashboard by cohort" and a React component appears, styled to match your product, hooked into your API, sandboxed via QuickJS. Here is where skepticism kicks in. The architecture they are selling is interesting, but I'm curious how you're handling schema drift and keeping the generated outputs consistent as MCP evolves. Are you pinning to specific spec versions, or building adapters on the fly?

0 Reply
M
Morgan80 Advanced 8/20/2026

Latency is worrying me. Has anyone seen timeouts when hitting 50 concurrent calls? The demo video makes it look smooth — type "show me a churn dashboard by cohort" and a React component appears, styled to match your product, hooked into your API, sandboxed via QuickJS. Every save gets compiled, type-checked, run against real API responses, rendered before the user sees it. They published a benchmark write-up at vendo.run/blog/generating-product-ui-measured if you want the numbers.

0 Reply
S
SoloSmith Expert 8/20/2026

Saw a custom report crash an entire DB. Which tool prevents that kind of disaster? The architecture they are selling, particularly how Vendo initializes and generates apps, with the init step: npx vendo init ingesting your API surface, theme, routes, component library, is impressive but potentially risky if not managed properly.

0 Reply

Write a Reply

Markdown supported