White Label AI App Builder - Prompt-to-App Platform You Own Outright
Your own prompt-to-app product, bought once and self-hosted. Users type what they want built and get a working multi-file project that installs, previews and ships from the browser tab, with no remote sandbox to pay for.
One picker for 22 LLM providers, per-model credits that keep AI costs predictable, and an operator console for keys, prices, plans and flags that needs no developer.
Your AI Builder in 6 Days: Runs in the Browser22 ProvidersMetered per ModelOn Your ServersAdmin-ControlledWhite Label
⚡ The Short Version
6
Ways to Charge
subscription plans, model credits, key markup, seats, enterprise deals
0
Revenue Share
nothing owed to us per prompt, per seat or per sale
1
Key, Every User
your credentials are added on the server, never in the browser
100%
Yours to Rebrand
product name, colors, domain and model list are all settings
You Keep the Credit Margin
Price every model per plan, add your markup on the shared provider keys, and hand out promotional credits. The metering that converts raw token spend into profit is part of the source you receive.
User Projects Run Client-Side
Builds, installs and previews happen in each visitor's browser tab, so your server bill does not climb with every active user. That is why it scales where builders renting a VM per session get expensive.
🚀 Want a prompt-to-app product that belongs to you?
Try It Yourself
Live Demo - Builder Workspace, Paid Tiers & Admin Console
Skip the sales pitch and test the platform directly. There are four working logins, one per tier, and nothing to install. Prompt an app into existence, watch it run in the tab, then switch to the operator account and change what each tier can access.
FREE WORKSPACE
Free Tier Builder
The everyday build loop: describe an app in plain words, see multi-file code appear, run it live in the tab, and refine it in CodeMirror with a working terminal alongside.
-
Visit the builder in a browser tab
-
Sign in using the test login below
-
See the chat, editor, terminal and preview
-
Try: demo@mxbolt.com | demo1234
PRO TIER
22 Providers Plus One-Click Deploy
The paid workspace: all models from all providers, the complete template set, prompt enhancement, your own system prompts, MCP tools and one-click shipping to hosting.
-
Visit the builder in a browser tab
-
Sign in using the test login below
-
See providers, templates, deploys and MCP
-
Try: pro@mxbolt.com | pro1234
ENTERPRISE TIER
No Credit Cap, Team-Wide Access
The organization tier: metering switched off, longer context windows, white-label branding, custom agents and API access for programmatic use.
-
Visit the builder in a browser tab
-
Sign in using the test login below
-
See unmetered use, branding and the API
-
Try: enterprise@mxbolt.com | ent1234
OPERATOR ADMIN
Where You Run the Business
Where operators actually run things: provider keys, which models and prices each plan gets, user and credit management, feature flags and environment settings.
-
Visit the admin console in a browser tab
-
Sign in using the test login below
-
See keys, plans, users and flags
-
Try: admin@mxbolt.com | admin1234
See It Running
Video Walkthrough - Prompt, Live Preview & Operator Console
Prefer a guided tour? Book 30 minutes with our team to plan your launch: which providers to offer, how to price credits, how to shape plans, where to deploy, and the order of go-live steps.
Screen by Screen
Screens & Flows - Builder, Deployment, Admin & Integrations
See how each surface behaves before you buy. Building, deploying, running the console and connecting integrations are separate areas used by different people, so step through each one first.


















Need a walkthrough of one particular flow?
In Their Words
Client Reviews - What Operators Say After Launch
What Miracuves clients say about launching on a ready platform base and building their own layer on top.
A Real Deployment
Case Study - Governed AI Build Platform for an Enterprise Team
An enterprise platform team needed AI-assisted coding under its own controls. Here is how it went live on Miracuves. The client’s identity is withheld under NDA.
Confidential Deployment
Internal AI Build Platform
An in-house AI coding platform run on the client's own servers, with central provider keys and credit limits per team in place at launch.
- Offering AI coding help to engineers while keeping proprietary code away from outside SaaS tools
- Keeping API credentials central so no team ever held a raw provider key
- Turning unpredictable AI bills into a per-team credit budget
- Launch an internal AI builder without writing login, metering and controls from scratch
- Let the platform team decide which models run, what they cost and who can use them
- Trace every credit spent back to a team and a model
- Projects executed in the browser, with no sandbox servers
- Plan tiers, credit budgets & centrally held provider keys
- Models, prices and feature flags set by the operator
- One workspace to generate, edit, preview, ship & export
- An Express auth proxy in front of a Cloudflare workerd runtime
"The admin panel is what got this past our security review. Central keys, per-plan models, and nothing leaving our network."
Start Here
What Is a White Label AI App Builder?
A white label AI app builder is a prompt-to-app product you run under your brand: someone describes the software they need in everyday language, the AI produces a full multi-file project, and that project starts up and runs in the browser straight away. This one is the platform underneath our AI app builder clones, and it comes with what a paying business needs around that loop: accounts and sessions, subscription plans, per-model credit metering, an operator console for providers and prices, and one-click deployment to the hosts your users already rely on. You buy it once, host it yourself and set your own commercial terms.
Browser, Desktop and API Access
Runs in the browser first, with packaged Electron desktop builds for macOS, Windows and Linux, and API access for programmatic use on the enterprise plan.
Your Brand Throughout
Your product name, colors, theme and domain. Branding on the enterprise tier is a built-in feature rather than a search-and-replace job.
Controls Ship in the Box
Roles, plans, credit metering, provider access and feature flags already exist in the code, so governance is not a second project.
Browser, Desktop and API Access
What Do You Get With the Source Code?
The full architecture behind it: the PostgreSQL schema, the Remix application, the Cloudflare workerd runtime with an Express proxy handling auth, and a provider layer that hides twenty-two different LLM APIs behind one interface.
-
Buying the source means you:
-
Hold every line of the code
-
Go live in 6 days, not after months of building
-
Stay free of reseller contracts and lock-in
-
Plug in new providers, models and workflows whenever you like
Put simply, it lets you sell an AI app builder now instead of spending a year on the generation pipeline, provider routing, billing logic and admin controls that make one commercially viable.
What It Does
Platform Features - Prompt-to-App Generation, 22 Providers, Deployment & Controls
Coverage runs from the first prompt to a deployed app, along with the commercial layer that surrounds it. Each capability carries the same readiness label the technical docs use (Included, Supported, or Configuration required), so there are no surprises once you own it.
Plain-English Prompt to Working App
Write a description; the AI builds the whole project and starts it in the browser.
- Full multi-file projects from one description
- Frontend, backend routes, config files and dependency manifests
- Streamed output that continues across multiple segments
Whole-Project Context
Edits span the entire file tree in a single pass.
- Changes made across every file in the tree together
- Context picked to fit each model’s token budget
- Older turns trimmed first, never the system prompt or latest messages
In-Browser WebContainers
A full Node.js environment that runs inside each user's browser.
- Genuine Node.js on the client side
- Shell commands and npm install right in the tab
- Starts in three to five seconds with no remote sandbox
Instant Hot-Reload Preview
Saved files show up in the preview in less than half a second.
- Changes hot-reload into the preview in under half a second
- Nothing to build, deploy or wait for
- Aware of ten frameworks
CodeMirror 6 Editing With Diffs
Review each AI edit before it is applied to the project.
- Tabbed multi-file editing with syntax highlighting
- A visual diff for each AI change, ready to accept or reject
- More than ten language modes
Terminal That Feeds Errors Back
A working shell; when a command fails, the AI can be handed the error to fix.
- A working shell in the container
- Several terminals on paid plans
- Command failures passed back to the AI to fix
22 LLM Providers, One Picker
A single selector for every major provider, with local models through Ollama too.
- All 22 implement one BaseProvider contract
- Four providers on Free; all twenty-two on Pro and Enterprise
- A documented four-step order for resolving keys
OpenRouter Catalog
Hundreds more models, free and paid, in a searchable catalog.
- 365+ extra models via OpenRouter
- Each marked free or paid, with its context length
- Catalog cached for five minutes, with a static fallback
Starter Templates
Starter projects in eight categories, each plan's access set by the operator.
- More than 30 starters in eight categories
- Landing pages, web apps, dashboards and online stores
- Social, games, AI tools and learning apps
Prompt and Context Controls
Prompt enhancement, custom system prompts and context that respects the token budget.
- Enhancement turns a vague brief into a clear one
- Your own system prompts on paid plans
- AI behavior set per project
Deploy to Six Destinations
Publish to hosts your users already know, or download the project as a ZIP.
- GitHub, GitLab, Vercel, Netlify, Cloudflare Pages or a ZIP
- Ten frameworks detected automatically
- Status polling that returns the live URL
GitHub, GitLab, Supabase and MCP
Pull in repositories, generate database schemas and give the AI external tools.
- Repository import from GitHub and GitLab via an SSRF-protected proxy
- Supabase schemas, RLS policies and client code
- MCP tools over stdio, SSE or streamable-HTTP
Note for buyers: Everything listed here is white-label and can be switched by the operator through 45+ feature flags in eight categories. Deployment targets, Supabase and MCP need the end user’s own account or endpoint; the docs label these Integration required, and we do the same.
Where the Money Comes From
Revenue Models - Plans, Model Credits, Seats & Enterprise Licensing
Monetization lives in the database schema, not in an add-on. You get three subscription plans, credit prices per model that you set, and an enterprise plan with metering switched off for organizations that budget AI centrally.
Three Subscription Plans
Free, Pro and Enterprise, each with its own provider access, credit allowance, templates and deployment rights.
Credit Rates per Model
Choose input and output credit rates for each model on each plan, so an inexpensive open-source model and a frontier model are priced fairly side by side.
Markup on Provider Keys
Buy model capacity at wholesale rates and resell it to users as credits. The gap between what the API costs you and what a credit sells for is your margin.
Enterprise Seats
Accounts with no credit cap and allocated seats, for organizations that prefer one flat fee to metering each person.
Promotional Credit Grants
Admins issue credit blocks for trials, onboarding or win-backs, and each grant is logged in the transaction ledger with its reason.
Resell to Your Clients
Agencies and platform vendors can use enterprise branding to offer the builder to their own customers as their product.
Important: The platform prices, meters and records usage, but it does not take payments and has no checkout. Hooking up a payment provider such as Stripe is done by the operator during deployment, and the docs say so clearly.
No Developer Needed Day to Day
Admin Console - Provider Keys, Plan Pricing, Users & Feature Flags
The operator console is what makes this a business rather than a demo. Anything that affects cost, access or behavior can be changed live by a signed-in admin, with no redeploy and no code edits.
What the Console Covers
Live Stats Dashboard
Total and today's active users, signups this week, the plan mix and credits used.
Provider Keys
Add, edit, rotate or disable API keys for all 22 providers, shown as masked previews.
Models per Plan
Put any provider's model on any plan, each with its own input and output credit rate.
Token Caps per Request
Limit context size by plan and model, regardless of the model's own window.
User Management
Find users by email, username or plan and move anyone to a new tier from one page.
Manual Credit Changes
Add or remove credits, always with a reason, recorded in the transaction ledger.
Suspend Accounts
Switch an account off immediately while keeping its history and transactions intact.
45+ Server-Checked Flags
Eight categories checked on the server, so editing a cookie achieves nothing.
Runtime Settings
View and change runtime configuration, with sensitive values hidden in the UI.
- Runtime environment variables you can view and edit, secrets masked
- Templates, categories, covers and plan-level access, all managed in one place
- Subscription records showing status, billing period and cancellation
Template Management
Control templates, categories, cover images and which plans can use each one.
- Platform stats: total users, today’s active users, this week’s signups
- How users split across Free, Pro and Enterprise
- Credits used and bought, plus request volume per provider and the top models
Access control: Admins sign in through a separate session with its own cookie and a shorter 24-hour expiry, checked with a timing-safe comparison. With no admin password set, admin login simply fails instead of falling back to a default.
One-Time Pricing
How Much Does a White Label AI App Builder Cost in 2026?
Owning a prompt-to-app product with Miracuves begins at $3,699, paid once, for the complete platform with source and your branding. The final figure moves with your provider mix, credit design, deploy targets, extra integrations and hosting footprint.
Unsure which route
fits your plans?
Tell us what you want to launch, by when and on what budget. We will recommend the setup that fits, with straight answers and no upsell.
Everything Handed Over
What's Included - Source Code, Apps & Deployment
The whole platform arrives with its documentation, the same build we demo rather than a trimmed sample.
Builder Web App
The Remix and React workspace for prompting, previewing and building, on your domain.
- Remix 2.15 plus React 18.3, styled with UnoCSS
- A CodeMirror 6 editor beside an xterm.js terminal
- 25 nanostores that persist to localStorage
Desktop Apps
Electron builds for macOS, Windows and Linux that update themselves.
- Electron 33 builds targeting macOS, Windows and Linux
- Native logging and built-in auto-update
- Compiled from the codebase that powers the web app
Auth Proxy Service
An Express service that holds sessions, credits and server-side provider keys.
- An authentication proxy on Express 5.2
- Handles sessions, rate limits and every database call
- Adds provider keys on the server, out of the browser
Generation Runtime
A workerd process that handles generation, streaming, MCP and deploys.
- An AI runtime on Cloudflare workerd
- Recoverable LLM streaming and MCP orchestration
- Proxies for deployment and git operations
Data & Model Provider Layer
The complete PostgreSQL schema plus one abstraction over all 22 providers.
- A PostgreSQL schema of six tables
- One provider abstraction spanning all 22 providers
- Plain parameterized queries everywhere, with no ORM
APIs & Integrations
REST endpoints in eleven modules and the code for each third-party service.
- REST endpoints organized into eleven modules
- Integration code for GitHub, GitLab, Vercel, Netlify and Supabase
- An MCP client supporting three transports
Your Brand Throughout
Your product name, logo, colors, theme and domain on every screen.
- Product name, logo, colors, theme and domain set to yours
- Enterprise white-label branding comes standard
- Miracuves appears nowhere in what your users see
Launch & Ongoing Support
Cloud setup, Docker and Kubernetes files, then support and updates after launch.
- Set up on the cloud provider you choose
- Ships with Docker Compose files and Kubernetes manifests
- 60 days platform guidance, 6 months priority bug fixes, 1 year of updates
Scope note: No mobile application is included. This is a browser-first product with packaged desktop builds, and we prefer to tell you now rather than have you find out after purchase. If your roadmap needs native mobile, we can scope it as custom development.
Explore Every Angle of the White Label AI App Builder
Four guides to owning an AI app builder outright: the feature set, the one-time price, how to choose a provider, and how credits and plans earn.
Features
Prompt, preview and deploy from the browser: 22 LLM providers behind one picker, per-model credit metering, six deploy targets, desktop builds and an operator console.
See the full breakdown →Development Cost
$3,699 once for the full source, live on your servers in 6 days, no per-prompt fee to us, and the running costs you carry, including the StackBlitz runtime license.
See exact pricing →Provider
Reseller plans, script vendors, agencies and Miracuves compared, plus nine questions for any provider, from whose keys power generation to who licenses the in-browser runtime.
Compare options →Business Model
Five levers you set yourself: per-model credit rates, margin on shared keys, plans, seats and branded resale, and which one to switch on first.
See the playbook →Who Buys It
Who Is a White Label AI App Builder For?
It fits any business that wants to own the step from a plain description to working software, whether you sell that step to customers or provide it to your own teams.
Dev-Tool Startups Launching a Prompt-to-App Product
Go to market with your own AI app builder, where users describe software and get a runnable project they can preview and deploy.
- Offer 22 LLM providers behind one model picker in a workspace carrying your brand
- Charge through plans and per-model credits with margins you set yourself
- Start from source you own, deployed in 6 days, instead of a rented reseller seat
Agencies & Product Studios
Turn client prototyping into a repeatable service that runs on a builder you control, not on individual developer accounts.
- Produce working client prototypes in days, previewed live in the browser
- Keep provider keys central so no staff account holds raw API credentials
- Hand projects over through GitHub, GitLab, a hosting deploy or a ZIP export
SaaS Companies Adding AI Generation
Add prompt-to-app generation to an existing SaaS product, so your customers can build extensions, pages or tools inside your ecosystem.
- Gate models, templates and features per plan from the admin console
- Meter usage from real input and output token counts per model
- Swap or add models later as configuration rather than a rebuild
Education & Training Providers
Give every learner an identical coding environment that needs no install and no local setup.
- Run Node.js projects inside the browser on ordinary student laptops
- Let faculty author templates for assignments and course starter projects
- Control spend with plan gating, credit limits and ZIP export for submissions
Enterprise Platform & Internal Tools Teams
Provide AI-assisted development across the engineering organization on infrastructure you host.
- Self-host the platform and keep generated code executing in the browser
- Govern which teams reach which models, features and budgets
- Bring a VAPT report mapped to known control objectives into your security review
Resellers & Multi-Brand Operators
Run several branded AI app builders for different markets or clients from one codebase, each with its own commercial terms.
- Launch separate brands, each with its own provider strategy and pricing
- Layer your own onboarding, consulting or custom template services on top
- Keep the credit margin, with no per-prompt or per-seat fee paid to us
If you want AI-assisted building while keeping control of the models, the costs and where the code runs, this is the product shape to look at.
Where It Fits
White Label AI App Builder Use Cases - Dev Tools, Agencies, Enterprise & Education
One codebase, very different operators, depending on which layer you lean on. A commercial launch leans on credit metering and tiers. An internal deployment leans on governance and enterprise accounts. A teaching deployment leans on templates and spending limits. All of it is configuration, never a fork.
Metered AI App Builder
Sell app generation as a usage-based product, pricing credits per model and per plan so your margin follows what each provider really charges.
Agency Prototyping Service
Cut client prototype cycles from weeks to days on a workspace carrying your brand, with central provider keys that keep raw API credentials off staff accounts.
Internal Developer Platform
Roll AI-assisted building out to an engineering organization where self-hosting and in-browser execution are what clear the security review, rather than a policy exception.
Classroom & Training Lab
Hand each student the same zero-install workspace, with templates written by faculty, gating by plan and ZIP export for handing work in.
Vertical AI Product Base
Put the generation pipeline underneath a niche AI product and change models or pricing as the market shifts, without rewriting the app on top.
Multi-Brand Licensing
Launch several times under separate brands for separate markets, each with its own branding, provider strategy and commercial terms.
One codebase, many setups. All six use cases share the same schema and the same four tiers: free, pro, enterprise and admin. Plans, credit rates, provider mix and branding are what you change, so there is never a separate fork to maintain.
Why Now
Why Launch a White Label AI App Builder in 2026?
AI-assisted building is no longer an experiment; teams now treat it as core tooling. What remains open is commercial and operational: which models, at what price, running where, and for whom. This platform puts those decisions in your hands, which is precisely what rented, hosted tools hold back.
Own It Instead of Renting
Rented AI builders charge per seat and lock you into their model choices. Owning the platform ties cost to real usage and leaves model selection with you.
Execution Stays in the Browser
The AI pipeline writes the code; WebContainers run it on the user's machine. For teams with IP or compliance limits, that separation usually settles the decision.
22 Providers as Insurance
Model prices, quality and availability keep shifting. With 22 providers behind one interface, a price change means editing config, not migrating code.
No Preview Servers to Pay For
Many builders spin up a remote VM or container for every preview. Running previews in the browser takes that cost off your bill.
Sell It or Run It In-House
One build serves as a commercial product with metered plans, or as an internal platform with enterprise accounts and central control.
Governance Wins the Deal
Central provider keys, model access per plan, credit limits and feature flags are what move an AI demo through procurement.
The Platform in Numbers
The opening exists because most AI builders were designed for solo developers, not for the organizations that pay for them, set the rules and answer to a security review.
How It Runs
Tech Stack - Remix, workerd, PostgreSQL & WebContainers
The design splits responsibility on purpose. An Express proxy handles anything that touches the database; a Cloudflare workerd runtime handles anything that touches the AI pipeline. workerd is quick and suits the edge, yet it cannot open the raw TCP connections PostgreSQL needs, so the Express proxy serves as the bridge to the database and passes every other request through. Three practical results follow: database credentials live only inside the Express process where workerd can never leak them, each tier scales on its own, and during a database outage authentication falls back to a 503 while users on their own keys keep generating.
Frontend
Remix 2.15 · React 18.3 · UnoCSS · CodeMirror 6 · xterm.js · nanostores
- A server-rendered Remix app built with Vite, including hot module replacement
- 25 nanostores that persist to localStorage and stay in sync across tabs
- One workbench pairing the CodeMirror 6 editor with an xterm.js terminal
Browser Runtime
StackBlitz WebContainers
- A full Node.js environment that runs inside the user’s browser
- npm install, shell commands and a genuine filesystem API on the client
- Starts in three to five seconds, with preview hot-reload in under half a second
Auth & Data Layer
Express 5.2 · PostgreSQL · postgres.js
- Handles sessions, rate limits, credit metering and server-side provider keys
- Six tables reached only through parameterized tagged-template queries, no ORM
- A connection pool capped at ten, with idle and connect timeouts
AI Pipeline
Cloudflare workerd · Vercel AI SDK 4.3
- 22 LLM SDKs wrapped by one BaseProvider contract
- Streaming capped by a 45-second timeout, with two retries and structured error notes
- Context trimmed to fit each model’s token budget before every call
Integrations
GitHub · GitLab · Vercel · Netlify · Supabase · MCP
- Repository import and push routed through a proxy with SSRF protection
- Deploys that detect the framework automatically, across ten frameworks
- An MCP client over stdio, SSE and streamable-HTTP, gated by an approval step
Desktop & Deployment
Electron 33 · Docker · Kubernetes · Cloudflare Pages
- Self-updating builds for macOS, Windows and Linux
- Docker Compose files and Kubernetes manifests in the package
- Comfortable on 2 vCPU and 4 GB; the minimum is 1 vCPU and 2 GB
Note for tech buyers: The stack is plain on purpose: Remix, Express, PostgreSQL and hand-written SQL, with no ORM or niche framework to learn first. A new provider takes two files; a new plan takes a type union and one config row. One licensing point to plan for: StackBlitz WebContainers is licensed commercially by StackBlitz, so production use in a for-profit product needs a license from StackBlitz, which you obtain directly.
Step by Step
How a White Label AI App Builder Works - Prompt, Generate, Preview, Iterate & Deploy
From the outside an AI builder looks effortless; underneath, identity, generation, execution and metering run in a strict order. This is the route from a new signup to a live app and a charged account.
The User Path - Signup to Live App
Account Creation
A new user signs up, and their account, tier and opening balance are set up before the workbench loads.
- Email, username and password checked at the API boundary
- Passwords stored as bcrypt hashes with 12 salt rounds
- A 256-bit session token issued and saved only as its SHA-256 hash
- The free tier applied with a welcome credit balance
Picking a Template
The user starts blank or from a template, which loads a complete working project into the browser runtime instead of an empty folder.
- 30+ templates in eight categories, each carrying its own generation prompt
- Filter by category or search names, descriptions and tags
- Operators decide which templates each plan can use
- The selected template fills the WebContainer with a full project tree
Prompting the Model
The user describes the app. The platform routes the request, attaches a key, meters it and sends it to the chosen model.
- Chat history, file state and model settings packaged together
- For qualifying plans the Express proxy adds the operator's provider key
- workerd calls the chosen model via the Vercel AI SDK
- Output streams back as mixed text and action commands
Running & Previewing
Action commands run in the browser, not on your servers, and the preview refreshes as each file arrives.
- File writes, shell commands and package installs execute in the WebContainer
- The preview pane hot-reloads changes in under half a second
- Each change shown as a visual diff to accept or reject
- Terminal output on hand whenever a command fails
Refining & Metering
The user keeps refining with new prompts or manual edits, and the platform records exactly what was used.
- Awareness of every project file kept across follow-up turns
- A failed terminal command can be sent back to the AI to fix
- Cost worked out from real input and output token counts
- Balance checked on the server, then logged in an append-only ledger
Shipping & Export
The finished app goes to a host, a git remote or a local download.
- Vercel, Netlify, GitHub, GitLab, Cloudflare Pages or ZIP export
- Framework detected automatically across ten frameworks
- Deploy status tracked and the live URL shown in the workbench
- The whole project archive can be downloaded at any time
Flow at a Glance
Sign Up → Template → Describe → Generate → Preview → Refine → Deploy
Under the Hood
Platform Architecture & Backend Flow
Routing Requests
Auth, credit, admin and provider routes stop at the Express proxy; all other traffic passes to workerd. Two runtimes sit behind a single public entry point.
Server-Side Key Injection
For each chat request the proxy looks up the user’s plan, supplies an operator key where the user has none, rewrites the header and passes it on. The key never reaches the browser.
Credit Accounting
Each call is priced from its real input and output token counts at the rate for that plan and model, deducted on the server and logged in an append-only ledger with the resulting balance.
Streaming & Retries
A switchable stream combines multi-step replies while tracking total usage, inside a 45-second timeout with two automatic retries.
Feature Flags
Flags load from a cookie written when the session is validated and are checked again on the server in workerd, in under a millisecond, with no database call and nothing trusted from the client.
In-Browser Execution
Your servers never run generated code. WebContainers run it on the user's machine, which keeps your infrastructure cost down and your compliance story simple.
Performance
Built to Scale - Stateless Runtime, Pooled Reads & Room to Grow
The parts of a code-generation product that usually cost the most, such as editing, file handling, previews and the terminal, cost you nothing here because they run in the user’s browser. Your servers handle only AI relay traffic and database calls.
Where the Work Really Happens
This flips the normal scaling problem. workerd holds no state and replicates without limit. Express scales out behind a load balancer. PostgreSQL is the only part that needs genuine capacity planning, and it serves just six tables.
The connection pool is capped at ten with idle and connect timeouts, and every lookup (email, username, session token hash, a user’s transactions) is indexed.
Benchmarks in the Documentation
According to the technical documentation, one instance handles 500 concurrent users and 200 concurrent streaming sessions, with p95 database query latency of 8ms and 2.3ms of auth-proxy overhead on each request.
At idle the proxy uses 128MB and workerd 256MB, adding about 5MB for each active streaming session. Loading stores from localStorage takes under 50ms.
Failing Gracefully
Should PostgreSQL go down, the auth proxy answers authentication requests with a 503 and keeps forwarding all other traffic. Anyone using their own provider keys carries on working during the outage.
Model catalogs from each provider are cached for five minutes with a static fallback, so a provider outage cannot blank the model picker in the middle of a session.
Resilient Streaming
Every streaming attempt has a 45-second timeout and up to two automatic retries with exponential backoff. If recovery fails, the pipeline sends a structured error annotation instead of silently cutting the stream, giving the client something meaningful to show.
Stateless Generation Tier
workerd keeps no session state, so instances replicate freely behind a load balancer.
No Preview Servers
Because execution happens in the browser, preview and sandbox cost rides on your users’ machines rather than your cloud bill.
Pooled Connections
A pool capped at ten with idle and connect timeouts, and an index on every lookup path.
Degrades, Not Dies
When PostgreSQL is down, auth returns 503 and the AI pipeline keeps serving anyone on their own keys.
Cached Model Lists
Model lists are cached for five minutes with a static fallback, so one provider outage cannot empty the picker.
Ready for More Regions
With Cloudflare Pages deployment and a stateless runtime, spreading across regions is a deployment choice, not a rebuild.
Easy to Customize, Built to Last
You will find no ORM and no proprietary framework layer. Each database call is a literal SQL statement, each provider is a class behind one contract, and each plan is a type union with a few config rows. An engineer can trace the full data path in an afternoon.
That pays off over time. What changes most often in a product like this, meaning the models on offer, their prices and who may use them, lives in configuration rather than code. And the parts an auditor will inspect are simple enough to inspect properly.
Honest scaling note: Rate limits currently live in an in-memory map, so they reset when the service restarts and are not shared between instances. The documented step for running several instances is a Redis-backed limiter, and we raise it with you before you scale out rather than after.
Open to Inspection
Platform Security - Proxy-Isolated, Assessed Against OWASP & NIST Control Objectives
The platform comes with a VAPT report mapped against OWASP Top 10 (2021), NIST CSF 2.0 and SOC 2 control objectives. No certificate is held; it is an assessment with findings, severities and remediation status, not a marketing page. The strengths it records: parameterized postgres.js tagged-template queries everywhere, 256-bit session tokens kept only as SHA-256 hashes, constant-time comparison for admin credentials, SSRF protection on the git proxy through domain whitelisting plus private-IP and metadata-endpoint blocking, credit checks on the server that a tampered client cannot bypass, a separate admin session with its own cookie and validation, JSON body parsing limited to the routes that need it, and rate limits on authentication endpoints.
Assessed Against Recognized Control Objectives
The included VAPT report maps the platform against the OWASP Top 10 (2021), NIST CSF 2.0 and SOC 2 control objectives, listing each finding with its severity and remediation status. It is evidence for your own security review. No certificate is held, and the report says plainly which controls are shipped and which are hardening steps.
- Findings, severities and remediation status recorded in one document
- Shipped controls separated from documented pre-production hardening steps
- Mapped to OWASP, NIST CSF 2.0 and SOC 2 objectives without claiming certification
Credentials Kept Server-Side
Secrets stay where the browser cannot reach them. Database credentials exist only inside the Express process, so the workerd runtime can never expose them. Operator provider keys are added at the proxy on the server and never appear in a response body. Passwords are stored as bcrypt hashes with 12 salt rounds.
- Database credentials isolated in the Express process, out of workerd
- Provider keys injected server-side and never returned to the client
- Retention, export and deletion automation built on request, not shipped by default
Hashed Sessions & Scoped Parsing
Session tokens are drawn from crypto.randomBytes with 256 bits of entropy and stored only as SHA-256 hashes, so reading the database never yields a working session.
- 256-bit session tokens kept at rest as SHA-256 hashes
- A separate admin session with its own cookie and validation path
- JSON body parsing limited to the specific routes that need it
Admin Access & Server-Side Enforcement
Access runs across four tiers: free, pro, enterprise and admin. Admin credentials are checked with a constant-time comparison, and there is no default password: if none is configured, admin login stays disabled. Credits and feature flags are enforced on the server.
- Timing-safe admin comparison with no fallback password
- Credit balances validated server-side, out of reach of client tampering
- Feature flags re-checked in workerd rather than trusted from the browser
Rate Limits & SSRF Protection
Authentication endpoints are rate limited, and the git proxy only talks to approved domains. Today the limiter is an in-memory map that resets on restart; a Redis-backed limiter is the documented step for multi-instance deployments.
- Rate limiting on login and other authentication endpoints
- Git proxy domain whitelist with private IP range and metadata endpoint blocking
- MCP tool calls routed through an approval step before they run
Browser Isolation, Headers & Known Gaps
Generated code runs in WebContainers inside the user's browser, never on your servers. Every response carries five security headers. Credit movements land in an append-only ledger. Persistent audit logging, CSP and HSTS are documented hardening steps you add before production.
- Generated code executes client-side, away from your infrastructure
- Five security headers on every response; CSP and HSTS added at deployment
- Append-only credit ledger today; a dedicated audit datastore on request
Parameterized SQL Everywhere
All database access goes through postgres.js tagged templates. The assessment found no string-built SQL in any of the six tables.
Sessions Hashed at Rest
Tokens carry 256 bits of entropy from crypto.randomBytes and are saved as SHA-256 hashes, so a database read gives no usable session.
Constant-Time Admin Check
Admin credentials are compared with a constant-time XOR check. There is no default password; without one configured, admin login is switched off.
Git Proxy Guarded Against SSRF
Wildcard domain whitelisting, blocking of private IP ranges and protection for cloud metadata endpoints.
Keys Stay Off the Client
Operator provider keys are added on the server at the proxy and never appear in any response body sent to the browser.
Five Headers on Every Response
X-Frame-Options, X-Content-Type-Options, X-XSS-Protection, Referrer-Policy and Permissions-Policy ship by default. CSP and HSTS are added at deployment.
Configuration required before production: Content-Security-Policy and HSTS headers are off by default and need adding. Demo accounts need disabling. Two-factor authentication, encryption at rest for the database and provider keys, persistent audit logging, CSRF token checks and admin IP restriction are documented hardening steps, not shipped defaults. We say so because the assessment says so, and your own security review would surface it anyway.
Extend It
Add-Ons - Payments, SSO, Hardening & Enterprise Scale
As delivered, the platform is complete and ready to demo. The modules below are the ones operators add most often, either because they depend on a third-party account or because their scale, security review or procurement team asks for them.
Native Mobile Apps
No mobile app ships today. Native iOS and Android apps for monitoring and reviewing projects can be built as custom development.
Payments
The platform meters and prices usage but does not take payments. Stripe or a similar provider is connected at deployment, with webhook signature verification.
SSO & 2FA
SAML or OIDC single sign-on and TOTP two-factor authentication can be added. Neither is on by default, and the assessment lists 2FA as a planned control.
Audit Logs & Data Retention
A separate audit datastore for admin actions, plus automated retention, export and deletion, are recommended in the docs and built when requested.
Shared Rate Limiting
A Redis-backed limiter and cache for multi-instance setups, replacing the in-memory map that clears on restart.
CSP & HSTS Setup
Content-Security-Policy and Strict-Transport-Security are off by default. Both are flagged as immediate deployment tasks, and we set them up on request.
Encryption at Rest
Encrypting the database and encrypting stored provider keys in the application are documented hardening steps, not shipped defaults.
Team Workspaces
Live co-editing, shared team workspaces and project version history are on the roadmap and can be built as custom scope.
Building More Than One AI Product? We Cover the Rest Too.
This AI app builder sits inside a wider suite of AI and no-code platforms. If your plans go past code generation, these pair with it naturally.
ChatGPT Clone
A conversational AI platform with threaded chats, model routing, prompt libraries and billing by usage.
Wix Clone
A drag-and-drop site builder with a visual editor, templates, hosting and domain management.
Squarespace Clone
A design-first site builder with commerce, blogging, scheduling and built-in hosting.
Apple AI ReALM Clone
On-device AI reference resolution for assistants and conversational interfaces that understand context.
The Business Case
Revenue Models - How a White Label AI App Builder Earns
A prompt-to-app platform is a developer product and a metered infrastructure business at once. Provider tokens are your cost; plans, credits and seats are your income. Margin sits in the gap between the two, and the admin console is where you set it.
Metering Built In
Every model carries its own credit rate on every plan, so retail pricing follows what each provider actually bills you.
Light Server Footprint
Builds and previews execute in the end user's browser. Per user, your servers carry an AI relay and some database rows.
Model Mix Pricing
Send routine prompts to quick open-source models and heavy work to frontier models, with each plan tier priced to match.
Governance Buyers Expect
Centrally held keys, plan-level model access and feature flags come up in enterprise reviews well before features do.
- subscription plans with included credits
- per-model credit pricing you set
- margin on operator-managed shared provider keys
- per-seat team licensing
- enterprise licensing with unmetered access
- promotional credit grants for trials and retention
Run well, the platform can grow into:
- a metered dev-tool business
- an agency prototyping service
- governed internal tooling for an engineering org
- the generation layer inside your own SaaS product
Illustrative Scenarios, Not a Forecast
Illustrative scenarios, not a forecast. Results depend on your market, your provider bills, how you price credits and how you sell. The platform supplies the controls each model needs; it does not guarantee an outcome.
Scenario A: Niche Developer Tool
Independent or vertical developer product
A focused user base on paid plans with metered credits.
Income combines plan fees with the spread between what providers bill you and what you charge per credit. Free users can bring their own keys, so they add little cost.
Scenario B: Agency & Studio Platform
Client prototyping service
Agencies run it under their brand for client projects.
Per-seat licensing with unmetered credits suits buyers who care more about fast prototypes and centrally managed keys than about counting tokens.
Scenario C: Enterprise Internal Platform
Governed tooling for an engineering org
A platform team offers AI-assisted development to every engineer.
Nothing is sold outside the company. The payoff is engineering hours recovered and source code that stays inside the network, often the argument that secures the budget.
Why Miracuves
Miracuves vs Other White Label AI App Builder Vendors
Prompt-to-app platforms come from open-source forks, freelancers, agencies, rented reseller plans, or documented source you buy once and own.
Why Buyers Pick Miracuves
Billing and Accounts Come Included
Sign-in, plan tiers, per-model credit metering with a transaction ledger, and an admin console. With an open-source fork you would build each of those yourself.
Governance You Can Click
Provider keys, plan-level model access, credit rates, user management and 45+ feature flags checked on the server, all changed at runtime instead of in a config file.
Many Providers, One Contract
All 22 provider SDKs sit behind a single BaseProvider contract with a documented key-resolution order. A new provider means two files, not a rewrite.
The Source Is Yours
You get the full Remix, Express, workerd and PostgreSQL codebase to change and deploy as you like. No per-seat fee to us, and no vendor rewriting the terms.
Documentation for Procurement
PRD, feature catalog, ERD, schema notes, API collection, technical dossier, security handbook and a formal VAPT report: what a procurement team asks for, beyond a demo.
Plain Readiness Labels
Every capability is marked Included, Supported or Configuration required, and CSP, HSTS, 2FA, payments and encryption at rest are listed as deployment work. You know before you buy.
Compare Side by Side: What You Own
When You Buy From Miracuves
| Criteria | Miracuves AI App Builder | Generic Script Vendor | Custom Dev Agency |
|---|---|---|---|
| Time to Go Live | 6 days to deploy | Unclear, mostly DIY | 6-9+ months |
| Who Owns the Source | ✔ You do, in full | Frequently encrypted or restricted | In most cases |
| Prompt-to-App Depth | Generation, 22-provider routing & credit controls | A prompt box and little else | Whatever the budget covers |
| Security Evidence | VAPT report & security handbook | Little or none | Inconsistent |
| Infrastructure Load | Low: builds run in the browser | Seldom planned for | Set by their architecture |
| Ways to Charge | Plans, per-model credits, seats | Few, extra work needed | Built to order (time & cost) |
| Admin Console | Providers, pricing, plans & flags | Thin or absent | Extra build, extra fee |
| Price, Speed & Quality | One-time price, 6 days | Low price, high risk | Expensive and slow |
| Support After Launch | 60-day, 6-month or 1-year plans | Rarely offered | Per contract terms |
An open-source AI builder fork gives you a demo. It does not give you accounts, plans, credit metering, provider governance or anything a procurement team will approve. That is the gap we close.
Industries
Industries & Buyers
This platform fits any organization that gains from turning plain-language descriptions into working software it controls. Developer-tool companies sell it as a metered product. Agencies and studios cut client prototyping from weeks to days and keep the work under their brand. Enterprise platform teams offer AI-assisted development in-house, where browser-side execution is often what clears the security review. Universities and training providers give each student the same zero-install workspace. AI startups put it beneath a vertical product as the generation layer. Consultancies fold it into delivery work. SaaS vendors embed it as an app builder inside their own product, and white-label operators run it under different brands for different markets.
- 🛠️ Developer Tools
- 🏢 Enterprise Platform Teams
- 🎨 Agencies & Studios
- 🎓 Education & Training
- 🤖 AI Product Startups
- ☁️ SaaS Vendors
- 💼 Consultancies
- 🌍 Regional Dev Platforms
- 🔬 R&D & Innovation Labs
- 🏦 Regulated Engineering
- 🚀 Accelerators & Incubators
- 🤝 White-Label Operators
Miracuves built it governance first: an AI code generation platform that adapts to your commercial model, metered where you need metering and carrying your brand throughout.
Changelog
AI App Builder Release Log - Versions & Changes
| Version | Date | What's New |
|---|---|---|
| v2026.3 | Aug 2026 | Fixes across generation, provider routing, credit deduction and the admin console. |
| v2026.2 | Jun 2026 | Bring-your-own-key added: users on any plan can enter their own provider API keys, next to shared keys the operator manages. |
| v2026.1 | Mar 2026 | First release: AI code generation platform with 22 providers, an in-browser runtime, credit metering, six deploy targets and an admin console. |
Blog & Resources
White Label AI App Builder - Insights & Guides
Read guides, trends and case studies on AI code generation, multi-provider LLM design and the economics of running a developer platform.
Hosted AI App Builder vs Platform Ownership: Comparing Control, Source Code, and Scalability
Last Updated on August 31, 2026 by samruddhi kadam Key Takeaways AI App Builder Platform…
How Do Prompt-to-App Platforms Turn Natural Language Into Working Applications?
Last Updated on August 31, 2026 by Yash Narayan Key Takeaways A prompt-to-app platform converts…
Ready-Made vs Custom AI App Builder Development: What Should AI Startups Choose?
Last Updated on August 31, 2026 by samruddhi kadam Key Takeaways AI App Builder for…
AI App Builder Unit Economics: How Token Usage, Credits, and Admin Controls Protect Margins
Last Updated on August 26, 2026 by Ashish Khan AI app builders look simple from…
AI App Builder Go-to-Market Strategy: Attract Users, Improve Activation, and Build Organic Demand
Last Updated on August 31, 2026 by Yash Narayan Key Takeaways An AI app builder…
FAQ
White Label AI App Builder FAQ - Pricing, Providers, Deployment & Governance
Answers to the questions buyers ask most about the Miracuves white label AI app builder.
A prompt-to-app platform you run as your own product. A user describes software in plain language and gets a runnable multi-file project that boots and previews in the browser, then deploys. Around that sit accounts and sessions, three subscription tiers, per-model credit metering, 22 LLM providers behind one picker, six deployment targets and an admin console for providers, pricing, plans and feature flags.
Yes. You set the brand, the commercial terms, the pricing, the model lineup and the policies. The software follows common prompt-to-app patterns rather than copying any protected asset, and generation runs through LLM accounts you open, under each provider’s terms.
Miracuves charges $3,699 one time for a white-label deployment with full source. Running costs are separate and paid directly by you: LLM provider usage on your own accounts, hosting, and a StackBlitz license. StackBlitz licenses WebContainers commercially, so production use in a for-profit product needs a license from StackBlitz, obtained by the operator.
Six days on our side. Because the platform already exists, our work is rebranding it and deploying it to your server, and that takes under six days. The calendar stretches only while we wait on you: brand assets, hosting access, provider API keys, and decisions on plans and credit pricing.
No. It is browser-first, with packaged Electron desktop builds for macOS, Windows and Linux. No Android or iOS app ships with it. Native mobile can be scoped as custom development if your roadmap calls for it; we prefer to say what ships up front.
Inside the user’s browser. WebContainers supply a full Node.js environment on the client, so npm installs, shell commands, builds and previews run locally. Your servers only relay AI requests and hold platform data. Teams with IP or data-handling constraints often decide on this point alone.
Every model has input and output credit rates you set per plan. When a generation finishes, the platform prices it from the real token counts, checks the balance on the server, deducts the credits and appends a ledger entry with the amount, new balance, model and description. Enterprise accounts skip metering altogether.
Operator keys are stored in the database, and the Express proxy adds them to requests on the server. No response to the browser ever contains them, and a user only sees keys that user entered. Encrypting stored keys at rest is a documented hardening step at deployment, not a default, and we tell you so before you buy.
It covers the subscription side: tiers, entitlements, credit allocations and the full transaction ledger. It meters usage but does not process payments. There is no built-in checkout, so Stripe or a similar provider is wired in at deployment. The docs say so plainly, and so do we.
Yes. Run local models through the Ollama provider, point provider settings at any OpenAI-compatible endpoint, or reach more models via the OpenRouter integration. A brand-new provider takes two files: a class that extends the base provider contract and one registry entry.
A Content-Security-Policy header and HSTS, since neither is on by default. Demo accounts switched off. Your own provider API keys and a strong admin password. If you bill users, a payment provider with webhook verification. At scale, add Redis-backed rate limiting, encryption at rest for the database and keys, and persistent audit logs. The documentation lists each of these as configuration required.
It comes with a formal VAPT report mapped against OWASP Top 10 (2021), NIST CSF 2.0 and SOC 2 control objectives (no certificate is held), plus a developer security handbook. The report records real strengths: parameterized queries throughout, session tokens hashed with SHA-256 at 256 bits of entropy, timing-safe admin comparison, SSRF protection on the git proxy, server-side credit checks and separate admin sessions. It is just as clear about what still needs configuration, and reviewers want both sides.
Yes, all of it: the Remix and React web app, the Express authentication proxy, the Cloudflare workerd runtime, the PostgreSQL schema across six tables, the provider layer for all 22 providers, Electron desktop packaging and every integration service. You own it and can change or extend any part.
Put your AI app builder
in front of real users.
A free consultation, a timeline you can plan around, and straight answers. Trust first, sale second.
What White Label Actually Means Here
Most white label AI app builders are rented: a monthly reseller plan on the vendor's servers, with your logo on their workspace. Here is where the line falls on this platform instead.
Your product name, logo, colors, theme and domain, the desktop builds for macOS, Windows and Linux, and every email and screen a builder sees, with no visible Miracuves branding anywhere. Plans, per-model credit rates, the model line-up and feature flags are settings in the admin console, so changing them does not mean a new release.
The full source code of the Remix workspace, the Express auth proxy, the workerd AI runtime, the PostgreSQL schema and the provider layer covering 22 LLM providers, plus the documentation set. There is no license fee, no revenue share and no charge per prompt or per seat from us, and nothing stops you from changing, extending or redeploying it.
It is not a model of our own and not a license to every component it uses. Generation runs through LLM provider accounts you open and pay for, under those providers' terms, and the in-browser runtime (StackBlitz WebContainers) needs a commercial license from StackBlitz for production use in a for-profit product. Payments, CSP and HSTS headers and two-factor sign-in are added at deployment. There is no mobile app, and the platform is hardened around your deployment before launch. One installation runs one operator brand.
Miracuves is an independent software development company. We are not affiliated with, connected to, sponsored by, or endorsed by Bolt.new, StackBlitz or any other AI app builder or code generation service.
“White label AI app builder” describes a category of product, not any one company. Brand names appear elsewhere on this site only to describe the kind of platform being built and the terms buyers search for.
We supply software, not rights to any AI model or runtime. Opening and paying for LLM provider accounts and staying within their terms, obtaining the commercial license StackBlitz requires for production use of WebContainers, your terms of service for the code your users generate, privacy notices and payment processing are your responsibility. We do not advise on any of it.
The entire design and codebase is built by our own team. The product contains no code, design, graphics, or content originating from any third-party AI app builder website or application. All third-party names and marks belong to their respective owners.






