Type a sentence. Get a real Next.js site — rendered in your browser, exportable as a ZIP, deployable to Vercel. No sign-up, no subscription, your own API keys.
Most AI site builders charge $20–100/mo to run a model call that costs a fifth of a cent — and you never own the code. ForgeAI is the open-source version: the keys are yours, the generated project is yours, and the whole thing runs on your machine.
- Anyone who needs a landing page now — studio, café, portfolio — and wants a real project, not a locked-in editor.
- Developers — skip the boilerplate: you get a typed, validated Next.js codebase you can extend.
- The curious — the whole pipeline is ~40 small files and readable. It makes a decent reference for how a BYOK AI generator is put together.
Not one big "generate everything" call — a pipeline where every stage is observable and interruptible:
flowchart LR
P[Your sentence] --> I[Intent: sections,<br/>pages, palette, DB?]
I --> C[Per-section generation<br/>provider fallback chain]
C --> V[Validate: esbuild +<br/>pattern rules]
V -->|fail| R[Retry with<br/>exact errors]
R --> C
V -->|pass| A[Assemble<br/>Next.js project]
A --> PV[Local preview:<br/>server bundle → iframe]
A --> Z[ZIP export]
A --> D[Vercel → live URL]
PV -->|click a section| E[Edit panel →<br/>regenerate just it]
- Intent — the prompt becomes structured JSON: which sections, which pages, palette, whether forms need a database. This is what drives the file map later — a prompt asking for a gallery, pricing and contact produces a site with exactly those sections.
- Per-section generation — every component is a separate paid call through your provider chain (OpenRouter → Gemini → HuggingFace, free tiers included). One provider 401s or times out → the next picks up; nothing is lost.
- Validation — generated code is esbuild-compiled and pattern-scanned: no
eval, nodangerouslySetInnerHTML, only allow-listed imports,<img>can't point at local files that don't exist, forms need names. Failures auto-retry with the exact error fed back — and a second failure marks just that section, the rest still assembles. - Assembly — a real Next.js App Router project: typed layout, compiled Tailwind, per-page routes, sitemap/robots, and
FormHandler+ Supabase migration when the intent says a database is needed. - Local preview —
/api/previewbundles the whole file map server-side into a sandboxedsrcdociframe. You see the actual rendered site before anything is deployed; clicking a section opens an editor that regenerates only that component and swaps it back in. - Take it home — ZIP export (
output:'export',serve outand it runs), or Vercel deploy to a live URL. Projects persist locally (IndexedDB) — reopen, rename, duplicate, redeploy.
If the stream dies mid-way, the error screen offers "Retry N failed sections" — it regenerates just those and reassembles, instead of burning the whole run.
- Everything produces a deployable Next.js site. The mode chips (mini-app, SaaS, game…) shape sections and tone — they don't change the stack.
- No image generation — generated sites use CSS/gradients/icons, not fake
<img src="/x.jpg">. - Grow features (analytics, email, A/B) are roadmap, not shipped. The vision doc says so.
- Quality is prompt-dependent: the same prompt won't render the same site twice, and a one-word prompt gets a generic result.
npm install
npm run dev:allOpen localhost:3000 → Settings → paste one AI key (free options) → type a prompt → Generate.
ECONNREFUSED on generate → the API isn't up; dev:all starts both processes (frontend :3000 + API :3001).
| Command | Does |
|---|---|
npm run dev:all |
frontend + API |
npm run validate |
lint + typecheck + security + unit + build |
npm run e2e |
Playwright (spins both servers itself) |
npx tsx scripts/pw-drive.ts |
headed AI-driven browser session — watch it walk the whole flow |
npx tsx scripts/smoke-assemble.ts |
assemble a project with zero AI keys |
Nowhere near us. Keys live in your browser's IndexedDB and are forwarded per-request as an auth header — the server never stores them. Self-hosters can use .env instead. Safety rails on top: prod-gated rate limiting, MAX_GENERATION_COST_USD spend cap per generation (default $0.25, configurable), zip-slip/traversal validation on every file map, CSP without unsafe-eval, sandboxed preview iframe.
Next.js 16 · React 18 · Hono API · Zustand · Tailwind · esbuild · JSZip · Vitest + Playwright. 13 production deps, all earned.
Freshly audited: 113 issues found and fixed — fake analytics removed, traversal holes closed, the preview made real instead of a mock. Example output lives in generated proj/yoga-studio/ — a genuinely generated site that next builds clean.
Shaped by the audit, in rough priority order:
- Clarifying questions before generate — intent is one-shot today; a Q&A round would lift output quality more than any model swap.
- Plugin registry — providers/deployers are arrays in
src/plugins/; a real registry would let people drop in their own without touching core. - Grow layer — SEO checkups, form-submission inbox, scheduled sitemap refresh. Only honest features — nothing that fakes analytics.
- Image generation — generated sites currently can't ship real images; a free image provider would change that.
- Multi-file project history sync — history is IndexedDB-local; optional export/import would make projects portable.
- Voice / messaging input — nice-to-have, last.
Not on the list by design: hosted SaaS, user accounts, telemetry, paywalls. The point of the project is that none of that is needed.
architecture (mermaid + sequences) · templates · gallery · free keys · vision · contributing · changelog · security
MIT — do what you want with it.