Building an app with Claude Code or Codex?
Don't build the foundation. Build your product.
Bump is everything your product needs, already built. You just connect the tech that powers it, then build your product on top, bumping you ahead months.
Buy once, own forever: a private codebase you and your AI tools build on.
Already wired in
Everything an AI-powered tech business stands on, already built.
Ten months of foundation decisions, already made, so you can validate your idea from day one instead of building the plumbing. Scroll the rails you're standing on.
01 · The apps
One codebase. Real apps on iOS, Android and web.
01 · The apps
One codebase. Real apps on iOS, Android and web.
App Store builds run in the cloud (EAS) and push notifications are already wired.
11 · Security
Secure from the first commit.
The mistakes that leak customer data are already handled.
The part only you can build
Your product + Bump
Our production picks, wired in while building Koora. Your job is connecting them: your accounts, your keys, your product's story, with your agent guiding you through the repo. Any tool that doesn't fit, swap it or delete it. It's your repo.
Try the live demoGo-to-market, in the box
Anyone can build now. Distribution changes things.
Building was the easy part. AI saw to that. Getting your idea in front of people is where startups live or die, and it's the part every other kit leaves you to figure out alone. Bump ships the distribution stack we run ourselves:
A Reddit copilot.
The pattern across all three: AI does the drafting, you stay the sender. Nothing posts, sends, or quotes without your approval. It ships as playbooks and reference code you adapt to your product, not another dashboard to babysit: the first starter kit that takes go-to-market as seriously as code.
Who Bump is for
The side-hustle founder
You build evenings and weekends, and you want the idea live, not a six-week setup project. Bump starts you at the product, with the foundation already done.
The founder already in business
Your company needs a real app on web, iOS and Android, and hiring a platform team is not the plan. Start from a foundation that already runs in production.
The AI-tool builder
You ship with Claude Code or Codex and want a codebase your AI already understands. Bump ships the agent docs and rules that make your tools productive from the first prompt.
The hard parts, handled.
Three things founders lose weeks to, already done.
A user loses their phone.
From scratch
Weeks of auth edge cases: reset flows, recovery, sessions, each one found through a support ticket.
In Bump
Password reset and MFA recovery already exist end to end. An admin approves the reset behind a step-up check, and the audit log records it.
Stripe retries a webhook.
From scratch
Your handler runs twice, someone gets charged twice, and you spend the night in the logs working out who.
In Bump
The webhook is signature-verified and idempotent: a retry changes nothing, and a forged call is rejected.
Your first App Store build.
From scratch
Certificates, provisioning profiles and push entitlements, fought one cryptic error at a time, on a Mac you may not own.
In Bump
Builds run in the cloud (EAS) and push notifications are already configured. You submit; you don't fight.
A foundation you build on.
Built right, not just fast.
Auth, payments, security: the parts that quietly sink products when they're improvised. In Bump they were built by hand and hardened in production: row-level security on every table, verified webhooks, secrets kept server-side.
Your AI knows its way around.
Rules files and guardrails that make Claude Code and Codex genuinely good at this codebase. Setup is a conversation:
> /setupYours to make your own.
Restyle it once and it's yours everywhere. Every integration is a choice you're allowed to unmake: swap any tool, delete any module, no lock-in, not even to our choices.
The admin app
The back office you'd never get around to building.
Every product needs one. Almost nobody builds theirs until it hurts. Bump ships a real admin surface with the operational workflows already wired:
User management
Search any account, drill into a profile, change roles, leave admin notes. Emails and identities sit behind secured RPCs.
Organization controls
Member roles, ownership transfer, deactivation. The last admin of an org is protected from removing themselves.
Moderation queue
Review recent content across the whole platform and remove what shouldn't be there. Every takedown is logged.
MFA recovery
Reset a user's lost MFA factors only after a fresh admin step-up challenge. Every reset is audit-logged.
Audit log
Every admin action is recorded: who did it, what they did, and to whom. Accountability is built in, not bolted on.
MFA-gated
Admins must enroll in MFA before they can touch any of it. The gate can't be dismissed, by design.
It's a surface of the same app: one codebase, one theme, role-gated routes. Staff sign in like anyone else and see a different product.
Where this comes from
Bump grew out of Koora.
Koora is my startup: a career passport for care workers. I started building it in October last year.
I spent the next ten months building the engine underneath it: the auth, payments, apps, admin surface, AI, and security this page describes. Everything Bump sells is that backbone. Koora runs on it today, in production.
I'm building Koora as an AI-native company, with AI as the backbone of how it is built and run. That is the point of these rails: a small team that ships like a big one, doing with product and code what companies used to hire big teams and agencies for.
Every Bump sale helps me bootstrap Koora. You get the months back, and you back a team working to uplift the quality of care. We can all get behind that.
Pricing
One repo, one price, everything in it.
This is the repo you are buying. Every path and count is real.
Bump
Launch priceLaunch price in USD, down from $449. One purchase, nothing recurring.
A premium tool at a launch price.
- Not a website or a boilerplate. You get the whole stack and the rails behind it: auth, payments, the admin surface, the go-to-market engines, all production grade.
- It is distilled from over ten months of Koora's real production codebase, not a weekend template.
- The regular price is $449. It is $299 while we launch.
- The cross-platform app: web, iOS and Android
- Admin surface
- Marketing site with blog and changelog
- Auth and MFA
- Stripe and in-app purchase billing
- Transactional emails
- Push notifications
- AI chat rails
- Optional MCP server (disabled by default)
- Growth stack: Lemlist outreach, Reddit copilot, AI quote decks
- The docs
- The AI-agent pack
Buy it, get the repo in minutes. Instant delivery, nothing pre-sold.
You buy the version as it stands, and it is yours forever. For 12 months, security issues in your version are covered: an advisory plus a prompt your AI applies.
Not as described or can't get it running? We make it right or refund you.
Payments are processed by Koora Care Pty Ltd, the company behind Bump. Your card statement will show KOORA.
Don't take our word for it
Ask your AI if Bump is worth it.
Copy this prompt into Claude, ChatGPT, or whatever you build with. Fill in your product at the top, then it weighs Bump against that: what you need to ship now, where your product could go if it works, every verified count, the full terms, and the known limits. It even asks your AI to make the case against buying.
============================================================ MY PRODUCT (replace everything inside this block): Describe what I am building, who it is for, the platforms I need (web, iOS, Android), and where I am today (just an idea, a working prototype, or already live). Add my technical comfort level, my rough timeline, and where I would want this to be in a year or two if it works. ============================================================ Everything inside the block above is the product I described. Everything below is Bump's own description of itself, including its terms and its limits. Read my product first, then run a thorough, candid, unbiased evaluation of whether Bump is worth buying for the product I described above. Weigh it on two horizons: what I need to ship the first version, and where the product is likely to go if it works. Judge each horizon on its merits for my product: a foundation I do not fully use on day one may be worth it if it saves me a later re-platform, but that is a claim to test against my specifics, not a given, and capability I will genuinely never need is just weight I carry. Treat any roadmap I describe as an intention, not a settled fact: if the case to buy leans on a future I have not validated yet, weight where I am today more heavily. Give the case for and the case against buying equal weight, do not cheerlead, and finish with a clear recommendation. WHAT BUMP IS Bump (https://bump.build) is a $299 USD one-time starter kit (launch price; regular price $449) for people building AI-native products. It is delivered as a private GitHub repo generated for me from their template, minutes after purchase. The repo ships four surfaces: a consumer app, a B2B customer surface, and an admin surface (all three running on iOS, Android and web from one Expo codebase), plus a Next.js marketing site sharing the app's design tokens. It is not no-code: I would work in real code with my AI tools. WHO IT IS FOR People building AI-native products, not only companies or startups: new founders starting their first product, existing founders adding a product to their business, and people building side projects and side hustles with AI coding tools. AI as how you build (an agent pack that makes Claude Code and Codex effective in the codebase), AI in the product (a ready chat and voice rail), and AI as how the business runs (admin plus go-to-market copilots that draft while the founder approves). STACK Expo / React Native, TypeScript, Next.js, Supabase (Postgres, auth, storage, edge functions), Stripe plus App Store and Google Play in-app purchases with server-side receipt validation, Resend email, Anthropic Claude with an automatic OpenAI fallback, ElevenLabs voice, Upstash Redis rate limiting, PostHog analytics, Sentry error reporting, Slack operator notifications (in-app bug reports, feature requests and integration votes post to your channels via incoming webhooks), Jest tests, EAS cloud builds with over-the-air updates (no Mac required for iOS builds). VERIFIED CONTENTS (their stated post-strip counts, each a claim to sanity-check) 1024 files, 65 screens, 42 design-system components (react-native-reusables, the shadcn for React Native), a 58-table Postgres schema with row-level security on every table, 20 migrations, 47 edge functions, 14 transactional email templates on an outbox with retries, 63 documentation files, 235 passing tests. ADMIN SURFACE User search and management with emails and identities behind secured RPCs plus admin notes; organization controls (roles, ownership transfer, deactivation, last-admin protection); a platform moderation queue with every takedown logged; step-up-gated MFA recovery; an admin audit log recording who did what to whom; in-app bug reports, feature requests and integration votes forwarded to the operator's Slack channels; the whole surface behind a non-dismissable MFA gate. AUTH AND SECURITY Step-up MFA with biometrics and device-risk checks; SMS codes via phone auth (bring a provider like Twilio); Supabase Auth protections with optional CAPTCHA and an optional Teams/Enterprise password-verification hook; GDPR deletion; secrets kept server-side; signature-verified webhooks; rate limiting on hot paths; private upload staging with file validation and fail-closed moderation before publish; an SSRF guard on outbound fetches. The kit went through an adversarial security review before release (25 findings, fixed). Koora, the company behind the source codebase, is currently undergoing SOC 2 audit; Bump itself carries no certification (SOC 2 certifies organizations, not code), but the security posture was built with that audit in mind. AI RAIL Chat with streaming, tool calls and conversation history; long-term assistant memory (facts stored and retrieved across conversations via pgvector embeddings); retrieval over uploaded knowledge documents (RAG); ElevenLabs text-to-speech and transcription for voice in and out; usage tracking with hard daily caps, plus an optional AI credit system (off by default) with credit packs sold through Stripe or in-app purchase; an MCP server that ships disabled until its deployment checks pass; Claude-first with automatic OpenAI fallback on provider errors. The live demo ships seeded assistant conversations, so I can see the rail working before paying. THEMING Light, dark and system appearance shipped in both the app and the template marketing site. Every color resolves to one shared design-token file and border radius derives from a single knob, so one edit restyles the app and the site together. Ships system fonts only, with a documented path for adding my own brand font across all surfaces. ENTERPRISE / B2B Organizations, teams, roles and invitations; a REST API with API keys; outbound webhooks with retry; seat-based team billing on Stripe. The founder built Koora's own enterprise sales pipeline (CRM sync, enrichment, AI quote decks, Stripe quotes) on these rails in two days and documented it publicly. GO-TO-MARKET MATERIAL Cold outreach wired for Lemlist (AI drafts per lead, human approves every send), a Reddit copilot (scheduled sweep scores threads, drafts replies in your voice, you post), and AI quote decks (prospect to live branded proposal URL). The engines draft in the founder's voice, not generic AI copy: a growth settings surface stores the founder story, a writing sample, proof points, words to use and avoid, claims never to make, and per-channel voice and guidance fields (outreach, Reddit persona and engagement rules, per-slide guidance for quote decks), all rendered into the engines' prompts. Ships as playbooks and reference wiring adapted to your product, not turnkey software. AI-AGENT PACK AND DOCS CLAUDE.md and AGENTS.md (a CI check keeps the two in sync), rules files and a /setup skill built so Claude Code, Codex and Cursor all work well in the codebase: agent-led onboarding walks you through accounts, keys and first run. 63 docs include per-vendor setup guides, per-tool AI workflow guides (Claude Code, Codex, Cursor), a prompt cookbook, security guardrails, and troubleshooting written to be driven with an AI assistant. RUNNING COSTS Vendor free tiers cover development and early users (near zero at zero users). Unavoidable when shipping: Apple Developer $99/year, Google Play $25 once, Vercel Pro about $20/month for commercial use, AI usage pay-per-use. TERMS, LICENCE AND OWNERSHIP $299 USD one-time (launch price; regular price $449); no subscription and nothing recurring. The repo is a private GitHub repo that is mine forever: my copy is a versioned snapshot of the kit at purchase and becomes my codebase from day one, so the product is the head start, not ongoing maintenance. I can build unlimited products I own on it; I cannot resell or redistribute the kit itself, and each copy is watermarked to its licensee. For 12 months, security issues found in my version are covered: an advisory with a ready-to-paste AI patch prompt, plus the code fix if it still applies. No hosting, no sandbox, no per-seat fees: every service runs on accounts I own, so there is no lock-in. No change-of-mind refunds (full source is delivered immediately); if it is not as described or I cannot get it running, they make it right or refund, and mandatory consumer protection laws where I live are unaffected (for Australian buyers, the Australian Consumer Law). Payments are processed by Koora Care Pty Ltd. Delivery: Stripe checkout collects my GitHub username, and the repo is generated and shared with my account minutes after payment. PROVENANCE The kit is stripped from the production codebase of Koora (https://koora.care), a care-sector startup where these rails have run in production for over ten months. WHAT IS NOT INCLUDED No ongoing maintenance or version upgrades: I buy a snapshot, and new major versions are separate releases. No hosting, sandbox, or managed service: I run everything on my own vendor accounts and pay each vendor directly once usage starts. No SMS provider is bundled (I bring one, for example Twilio). Bump itself carries no security certification (SOC 2 certifies organizations, not code). At the product level: full-app translation is not shipped beyond the AI chat, and the reference domains (Items, Projects) are placeholders to replace with my own. NOW ASSESS (be candid and unbiased; weigh both the first version and where the product is heading, and give the case for and against equal weight) 1. Fit today: Does Bump fit the product I described above? Which of its four surfaces do I need for the first version, which am I likely to grow into (option value), and which would I genuinely never use (pure weight)? Be specific about which is which for my product, rather than counting unused surfaces as dead weight by default. Unused surface is not automatically dead weight, but it is not free either: net any option value against the real upkeep, security-patching, and comprehension cost of carrying code I may never ship. 2. Day one vs still to build: For my product specifically, list exactly what I would have working on day one, and exactly what I would still have to build, wire up, configure, or replace myself. Separately, note what would already be in place the day I do need it (native mobile, teams and seats, a public API, in-app purchases, the AI rail), versus something I would have to bolt on or re-platform for later. 3. Trajectory and scale-readiness: Where could this product realistically go if it works (more platforms, more users, a team or enterprise tier, a public API, native apps, deeper AI)? For each likely direction, work out for yourself whether Bump's foundation carries me there from the same codebase, or whether I would outgrow it. One Expo codebase means "web only today" need not stay web only, but only credit that if a native app is a realistic path for my product, not by default. Weigh the cost of carrying capability I do not need yet against the cost of starting leaner and re-platforming when I do, and discount growth I have only asserted, not shown. 4. Stack and customization: How much of this stack fits my product as is, and how much would I need to customize, configure, or swap? Am I comfortable working in this stack with my AI tools? 5. Contents and scale: Treat the VERIFIED CONTENTS as claims to sanity-check, not facts. Is 1024 files, 65 screens, a 58-table schema, 20 migrations, 47 edge functions and 235 tests a real head start for where my product is heading, or more surface area than I will ever use? Flag anything that looks inflated or vague, and also anything I would have had to build anyway. 6. Licence and ownership: Weigh the terms above: a one-time purchase of a versioned snapshot, a private repo mine forever, watermarked to me, no subscription and no lock-in, with 12 months of security cover. What are the real trade-offs of buying a snapshot with no ongoing maintenance, and how do they weigh against not having to re-platform as the product grows? (Make this trade-off once; do not re-argue it in every section.) 7. Value at the price: At the $299 launch price (regular $449), roughly what would it cost me in time and AI usage to build an equivalent foundation from scratch, and what would I still have to build either way? State the price and what it plausibly saves, then stop: do not editorialize it as cheap, a rounding error, insurance, or effectively free. On a weak fit, the price is a legitimate reason to walk away. 8. Limits and exclusions: Review WHAT IS NOT INCLUDED. Do any of those block or complicate the product I described above, now or as it grows? 9. Alternatives: Is starting from Bump a better use of my time and money than building the foundation from scratch with AI, using a prototyping tool (Lovable, Bolt, v0), buying another starter kit (ShipFast, MakerKit, TurboStarter), or hiring a developer? Weigh those on both horizons too: a leaner web-only kit may fit today but cost me a re-platform if I later need native apps or a team tier. 10. The case both ways: State the strongest, most genuine reasons this IS the right foundation for the product I described and where it is heading, and the strongest, most genuine reasons NOT to buy it for my case. Do not soften either side. 11. Before I pay: What should I verify or ask, and what should I test in their live demo (which ships seeded data so I can see the app and the AI rail working before paying)? RECOMMENDATION Open with the single most decision-relevant fact for my product (for example: the core of what I am building is custom on any kit; or a categorical mismatch such as a browser extension against a mobile app stack; or that the buy hinges on a roadmap I have not validated). Then give a clear verdict: buy, do not buy, or it depends (and on what). Weigh both horizons, shipping the first version and scaling if it works, and treat asserted-but-unvalidated growth cautiously. Keep it to a few sentences, and name the single factor that most moves the decision either way.
FAQ
Questions, answered.
What exactly do I get?
A GitHub repo you own: your product on web, iOS and Android from one codebase, plus the admin surface, the marketing site, auth with MFA, Stripe and in-app purchase billing, transactional email, push notifications, AI chat rails, an optional MCP server that starts disabled, the growth stack (Lemlist cold outreach, a Reddit copilot, AI quote decks), the docs, and the AI-agent pack that makes Claude Code and Codex good at the codebase.
Do I need to be a developer?
No. You bring the idea and the AI tools you already use. Bump handles the foundation: the auth, the payments, the database, the parts that are easy to get wrong. You're not starting from a blank screen, and you're not lost in someone else's architecture. It's not no-code, and we won't pretend it is: you'll work in real code with your AI, on rails that keep you from getting stuck.
Is this just a website template?
No. A template is a coat of paint. This is the whole structure underneath: your product on web and both app stores, the admin surface, the marketing site, and a production backend, all wired to real payments, auth, email and AI.
What makes this "AI-native"?
Three layers, all shipped. You build with AI: the agent pack and rules files make Claude Code and Codex genuinely good at the codebase, and setup is a conversation. Your product ships AI: the chat and voice rail with usage caps is ready for your own prompts and tools. And the business runs on AI: admin workflows plus the go-to-market copilots draft the work while you stay the approver. That's the company Koora is being built as, and this is its engine.
What do I actually own?
Everything. It's your code, your accounts, your product. Bump has no hosting, no sandbox, no per-seat fees: the repo lands in your GitHub account and every service runs on accounts you own.
Why not just vibe code it from scratch?
Starting from a blank screen with AI feels fast until you hit the parts AI gets wrong: auth, payments, security, deployment. That's where projects stall or quietly ship a data leak. Bump gives you those foundations already built and hardened, so you spend your tokens and your time on your actual product.
How is this different from Lovable, Bolt or v0?
They're brilliant for spinning up a prototype fast. But you're building inside their sandbox, and the moment you need real payments, native mobile apps, or a production backend you control, you hit a wall. Bump is real code you own from day one. Use Lovable to sketch the idea. Use Bump to build the business.
How is this different from other starter kits?
They're good, and they're built by engineers for engineers. The marketing assumes you speak fluent developer, and most stop at a web app. Bump ships your product on web, iOS and Android with a real admin surface and the go-to-market playbooks, built for founders who vibe code. Same head start, aimed at a different person.
Why not hire a developer or an agency?
A technical cofounder or an agency costs equity or tens of thousands of dollars, and you wait weeks to see anything. Bump is a one-time cost and you're building the same day. It won't replace a great engineer forever, but it gets you from idea to launchable without needing one to start.
How hard is setup?
Type /setup. Your AI does the walking; you do the account sign-ups. There's a manual guide if you'd rather drive. And if you get stuck: the docs first, then the community, then email us.
Will it stay updated?
You buy the version as it stands, and it's yours forever. Bump's job is to bump you ahead at the start, not to keep your product up to date: within days the codebase is yours and diverging. For 12 months, security issues found in your version are covered: an advisory with a ready-to-paste prompt so your AI patches your codebase, plus the code fix if you'd rather pull it.
What does it cost to run?
Near zero at zero users. The stack sits on vendor free tiers (Supabase, Vercel, Resend, PostHog, Sentry), so costs start when usage does. The docs list what each vendor charges and when you'd start paying.
Do I need a Mac?
No. EAS builds your iOS app in the cloud, so you can ship to both app stores from any machine.
Are all four surfaces native apps?
Three of the four are: the consumer app, the business workspace, and the admin console all run on iOS, Android and web from one Expo codebase. The fourth, the marketing site, is a Next.js web app in the same repo, sharing the same design tokens. The business workspace and admin console use web-first layouts (a sidebar on wide screens, a tab bar on phones) and work on native. On native, customer subscription billing goes through the web by default; if you would rather sell inside the native app, that falls under Apple and Google's in-app purchase rules, and the kit already ships those rails (store billing with server-side receipt validation) on the consumer side, so it is a documented extension, not a limitation.
What if one of the tools isn't right for me?
Swap it. It's your repo. The integrations are our production picks, not requirements; the docs show what each one does so you can replace or delete it.
Can I build more than one product?
Yes, unlimited products. The one thing you can't do is resell or redistribute the kit itself.
Why are you selling your own rails?
Because it funds the mission. We're bootstrapping Koora, our care-sector startup, and Bump turns the foundation we already built into fuel for it. You get the months back; we fund a startup working to uplift the quality of care. No VC, no catch: every sale bumps both of us ahead.
What about refunds?
Because you receive the full source code minutes after purchase, there are no change-of-mind refunds. But if the kit isn't as described or you can't get it running, email support@bump.build and we'll make it right or refund you. Your license ends if a refund is issued, and nothing here limits rights you have under mandatory consumer protection laws where you live (for buyers in Australia, the Australian Consumer Law).
Skip the slow start. Start bumped ahead.
Get Bump today, and spend your first month, and your tokens, building your product instead of your plumbing. Build with AI, ship AI in your product, and run the business with AI: one repo, all three.
