A single-file HTML app that acts as a YC-style partner to pressure-test your startup idea. Powered by any OpenAI-compatible chat API, it asks 6 forcing questions to help you validate your wedge, target user, and core problem.
- Single file, zero backend — open
index.htmland go - Two modes — Startup (6 forcing questions + design doc) and Builder (hackathon/side project)
- OpenAI-compatible AI config — presets for OpenAI, DeepSeek, GLM/Zhipu AI, SenseNova, OpenRouter, Groq, Together AI, or a custom compatible gateway
- Bilingual — full EN/ZH UI toggle, AI responds in your selected language
- Cloud sync via Supabase — sign in with Google/GitHub to sync sessions across devices
- Offline-first — all data saved to localStorage; cloud is optional and silently degrades
- Design doc generation — auto-summarizes the session into a copyable design document
- Open
index.htmlin a browser (via HTTP server, e.g.npx serve .) - Click Settings in the header
- Choose a provider preset, or select Custom / self-hosted
- Enter:
- Base URL — provider root, such as
https://api.openai.com/v1orhttps://api.deepseek.com - Model ID — exact model slug from the provider
- API Key — stored locally in your browser
- Base URL — provider root, such as
- Click Test connection
- Close settings, pick a mode, describe your idea
Some providers have strict CORS policies. Use the included proxy:
node proxy.jsThen in Settings:
- Keep Base URL set to the upstream provider, not
localhost - Check Use Local CORS Proxy (localhost:3456)
Sign in with Google or GitHub to sync your sessions across devices. Without signing in, everything stays in localStorage — the app works exactly the same.
To enable cloud sync for your own deployment:
- Create a Supabase project at supabase.com
- Run the schema — paste
supabase_schema.sqlinto the SQL Editor - Enable OAuth providers — Dashboard > Authentication > Providers > enable Google and/or GitHub
- Configure OAuth apps — register your app in Google Cloud Console and/or GitHub Settings > Developer settings > OAuth Apps. Add the Supabase callback URL as a redirect URI.
- Set credentials — replace
SB_URLandSB_KEYinindex.htmlwith your project URL and publishable key
API Keys are never synced to the cloud. They stay in localStorage only. Preferences (base URL, model, proxy setting, language) sync on sign-in.
index.html — Complete app (HTML + CSS + JS)
proxy.js — Local CORS proxy for OpenAI-compatible APIs
supabase_schema.sql — Database schema, RLS policies, and GRANTs
supabase_mvp_plan.md — Original implementation plan
Browser
├── localStorage (always, offline fallback)
├── Supabase Auth (Google/GitHub OAuth)
├── Supabase DB (sessions + user_preferences)
└── AI API (OpenAI-compatible chat completions, direct or through local proxy)
Data flow:
- Not signed in → all data in localStorage, zero changes to existing behavior
- Signed in → localStorage + cloud sync; first login auto-uploads existing local data
- Offline → silently falls back to localStorage, cloud writes queue and retry
- API Keys stored only in
localStorage, never sent to Supabase - Supabase publishable key is safe for client-side code; security enforced by RLS
- RLS policies ensure users can only access their own data
- Explicit
GRANTstatements (required since Supabase April 2026) — no accidental data exposure
Built to help founders build what people want.