How to host a vibe-coded website
Your site works locally. Here's how to get it online with HTTPS — without learning a deployment platform. The short version is one sentence to your coding agent; the steps below explain what happens and how to fix the usual snags.
1. Make sure it runs locally
Ask your agent to start the project from a clean state and open it. If it needs environment variables (API keys, database URLs), list them now — they'll have to exist on the server too.
2. Static or app?
- Static — HTML, CSS, JavaScript; a React, Vue or Vite project that builds to a
dist/folder. It only needs files served over HTTPS. - App — anything with its own server process: Flask, FastAPI, Django, Express, a Next.js server, a database.
Not sure? Your agent can tell you — and it handles both cases.
3. Give your agent one prompt
What the agent does with it:
- reads SKILL.md — the instructions for agents,
- creates a server with one HTTP call and gets root SSH plus an HTTPS address,
- for a static site, builds it and copies the output into
/root/www— it's served immediately, - for an app, installs dependencies and starts it from
/root/run.shon port 80 — it's restarted if it crashes and after the server wakes, - gives you the URL.
4. Check it
Open the URL on your phone too. If something's off, tell the agent what you see — it has SSH access and can read the logs.
5. Optional: your own domain
With a verified phone you can serve the site from your own domain: point an A record for the apex
(example.com) and a CNAME for www, ask the agent to register both, and HTTPS is issued
automatically once DNS points to us.
6. Updating it
Change the code locally, then ask the agent to deploy again. It keeps the same server and URL.
Troubleshooting
A blank page
Usually a static build that expects to live in a sub-path, or assets that weren't copied. Ask the agent to check the build output and the base path setting.
The page shows the default placeholder
Your files aren't in /root/www, or the app isn't running from /root/run.sh. The agent can check which.
The app doesn't respond
It must listen on 0.0.0.0:80 — not localhost and not port 3000 or 5000.
The first visit after a while is slow
Idle servers sleep after about 10 minutes and wake on the next request within a few seconds. With a verified phone you can keep a server always-on.
Before you share the link: keep secrets out of the browser
Anything inside your frontend JavaScript is public — including API keys your agent may have pasted in. Keys belong in an environment file on the server, used by your backend. If a key has ever been in client code, restrict it in the provider's console or rotate it.
Try it: paste this to Claude Code, Cursor or Codex.