Cutable is an AI web-app builder. A Next.js workspace lets users describe an application, while a Go API plans and executes the work with OpenRouter inside isolated E2B sandboxes. Generated files are indexed in PostgreSQL and streamed to the browser over WebSockets.
This repository is a Go backend migration and Cutable rebrand of the original Likeable project. The UI was retained and modernized; the former Node/Express/Prisma/LangGraph backend was replaced with a dependency-light Go service.
- Go 1.26 HTTP and WebSocket API
- JWT authentication in secure, HttpOnly cookies
- Optional Google OAuth 2.0 sign-in with state validation and PKCE
- PostgreSQL persistence with embedded SQL migrations
- OpenRouter chat completions with function/tool calling
- Secured E2B sandbox lifecycle, filesystem, command, build, and preview support
- Two account-level demo builds followed by session-only bring-your-own-provider keys
- Next.js 16, React 19, Tailwind CSS 4, React Query, and Monaco Editor
- A reproducible
cutable-react-baseE2B template - Unit tests, live provider smoke tests, dependency audits, and GitHub Actions CI
- Go 1.26 or newer
- Node.js 22 or newer and npm
- Docker with Compose
- An OpenRouter API key with available credits
- An E2B API key with available credits
-
Create the protected environment file:
cp .env.example .env chmod 600 .env
-
Fill in
OPENROUTER_API_KEY,OPENROUTER_MODEL,E2B_API_KEY, and a randomJWT_SECRETof at least 32 characters. Do not commit.env.To enable Google sign-in, create a Google OAuth client of type Web application, add
http://localhost:3010/api/auth/google/callbackas an authorized redirect URI, then setGOOGLE_CLIENT_IDandGOOGLE_CLIENT_SECRET. Keep the client secret only in.envor a production secret manager. -
Install the two JavaScript dependency sets:
npm ci --prefix apps/frontend npm ci --prefix apps/backend
-
Start PostgreSQL:
docker compose up -d postgres
-
Start the Go API in one terminal:
npm run dev:backend
-
Start the frontend in another terminal:
npm run dev:frontend
Open http://localhost:3000. The API health endpoint is http://localhost:3010/healthz.
The Go service loads the repository-root .env automatically during local
development. Production deployments should inject environment variables from
their secret manager instead.
Cutable uses the alias in E2B_TEMPLATE_ALIAS, which defaults to
cutable-react-base.
Build or update the production template:
npm --prefix apps/backend run build-templateBuild a separate development alias:
npm --prefix apps/backend run build-template-devTemplate builds and live sandboxes consume E2B credits. Agent runs consume the OpenRouter credits associated with the configured model.
npm test
npm run lint
npm run build
npm audit --prefix apps/frontend
npm audit --prefix apps/backendThe E2B live integration test is opt-in. Supply an existing running sandbox ID; the test reconnects securely and never logs its access token:
cd apps/backend
E2B_LIVE_SANDBOX_ID=your-sandbox-id go test ./internal/provider \
-run TestE2BLiveFilesystemAndCommand -vThe architecture handbook continues from this context view into the user journey, AI execution loop, trust boundaries, deployment path, data model, and a claim-to-code verification map. Every diagram is supplied as an editable Excalidraw scene plus PNG and SVG exports.
The API does not persist E2B environment access tokens. It receives a fresh
short-lived credential whenever it creates or reconnects to a sandbox.
User-supplied OpenRouter and E2B keys are held in browser sessionStorage,
sent only with build or preview requests, and are not stored by the Go API.
See .env.example for the complete list. OPENROUTER_MODEL is
required intentionally; there is no hidden fallback model. For HTTPS
deployments set COOKIE_SECURE=true, use an HTTPS FRONTEND_ORIGIN, and use a
wss:// frontend WebSocket URL. FRONTEND_ORIGINS is a comma-separated,
exact-match allow-list for credentialed CORS and WebSocket requests; include
every production and preview hostname that should use the API. Set
GOOGLE_REDIRECT_URL to the exact
production API callback URL registered in Google Cloud.
The backend container reads an optional /run/secrets/cutable.env file before
normal environment variables. The image is published to GHCR for both AMD64
and ARM64 with immutable commit tags and digests.
apps/
backend/
cmd/server/ Go entrypoint
internal/ agent, providers, API, config, and PostgreSQL store
e2b/ E2B template definition and build scripts
migrations/ readable SQL migration copies
frontend/ Next.js application
compose.yaml local PostgreSQL
Reimplemented from the original Likeable codebase with permission. Cutable’s Go migration, provider integrations, security hardening, and rebranding are maintained in this repository.
