Which host, and when it is chosen
Every project goes to one host, Netlify or Vercel, chosen before its first publish. The app suggests the account's default; change it per project if you like. Once a project has been published, it stays with that host — the site, its address and its history live there.
Both hosts have a free tier that covers a small site indefinitely. The account is yours: the app talks to the host's own API from your computer, with nothing of ours in between, and the site sits in your account under your terms.
Connecting an account
Netlify signs in through its own Authorize page in your browser: one press on Connect, one approval, done. No token to copy.
Vercel asks for a personal access token for now: make one on vercel.com, paste it into the app. Signing in with Vercel through the browser proves who you are but cannot publish for you, so the app does not offer it as a way to publish.
Credentials are kept in the app's own protected storage on your computer — the operating system's keychain on a Mac, its equivalent on Windows — and are never written into a project folder.
What a publish does
- Looks at the folder and decides what to send: the folder as it is for a static site, or the output of a build for a project with a build step.
- Builds, if needed, with the same Node.js and npm you would use in a terminal.
- Checks every file that would go up for leaked keys, and stops if it finds one.
- Uploads only what changed since the last publish.
- Remembers what went up, so the next time it can say what has changed.
The key check
AI tools write API keys into source files. Before any upload the app scans exactly the set of files it is about to send — source and built output — for the kinds of secret that cost money or access when they leak: Anthropic, OpenAI, Stripe, AWS, Google, GitHub, Slack and SendGrid keys, private keys, database passwords and signed tokens.
A finding stops the publish. The app names the file and the line, and gives you a sentence to paste into your AI that asks it to move the key out of the code. Nothing is uploaded until the scan is clean.
The same address, every update
The first publish makes a site in your account and remembers which one belongs to this folder. Every publish after that goes to that same site. The address does not change; only the changed files are sent.
The project page carries a badge with how many files differ from what was last published, and the list of them. For a folder that is a git clone of a repository the host builds, the badge counts what git has not sent instead — files not committed and commits not pushed — because for that site a push is the publish.
Versions, and going back
Every publish stays in the list on the project's Publishing tab, with when it went out. Making an older one live again is one press: the address stays, nothing is rebuilt, and the badge then measures the folder against that version.
Draft links
Share a draft publishes the folder as it is to a separate address, without touching the live site. Send it to whoever asked for the change; when they are happy, publish for real.
Forms
A contact form on a Netlify site collects its answers in Netlify. The app turns the feature on for the project and reads the verified responses into the project's Forms view, so there is no dashboard to visit. It refuses to publish a form that would silently collect nothing, which is what happens when the feature is off.
A site that is private
Netlify puts new sites on some accounts behind team access: the link you just sent asks the visitor to sign in. After publishing, the app checks and says so — "Only you can open it" — with the one button that makes it public. On a plan where Netlify will not allow that, the app says that too and sends you to the one setting on netlify.com that does it.
A site that is gone
Delete the site on the host's dashboard and the app notices the next time it looks: the project says the site was deleted and offers to publish it again, as a new site. Nothing in the folder is affected.
Connecting a folder to a site you already have
A folder can be linked to a site that already exists in your account instead of making a new one: Choose existing site lists what the account has. From then on the app updates that site.
Folders that came from GitHub
If the folder is a clone of a repository and the host already builds that repository, uploading files over the top would be the wrong thing to do. The app notices, and for such a project Publish means push: it sends the commit, and the host builds it the way it always has. The Git tab shows what has not been sent, and the key check runs before anything leaves your computer.
How many sites an account keeps
A free account keeps one published site. The count is on the account, not on this computer, so a second Mac or a reinstall sees the same number. Past the limit, a band across the window says so and publishing pauses: nothing already online comes down, and one button asks us for more.