How MoatRadar Was Vibe-Coded with Claude: Stack & Pricing
October 7, 2026 · 1238 words
| TL;DR | |
|---|---|
| What it is | An AI tool that suggests stocks, startups or crypto ideas filtered through famous investors' frameworks |
| Builder | Non-developer; the first app the founder ever shipped |
| AI tool | Claude (the exact Claude product is not disclosed) |
| Stack | Node.js server with no framework, vanilla JavaScript frontend, GPT-4o, live price data, Stripe, Google OAuth, Railway |
| Time to launch | A few days |
| Revenue | Not disclosed (pricing only: credit packs from €5, €1 per search) |
| Source | Show HN, March 4, 2026 |

A person who had never shipped an app built a paid AI product in a few days. It takes card payments through Stripe, signs users in with Google, and charges €1 per search.
That product is MoatRadar. Its revenue is not disclosed, so this teardown looks at how it was built and how it charges. It also covers what the simple stack means for security.
The one point of this post: pay-per-use credits are the easiest honest pricing for an AI wrapper, but they make your payment code the most important code you have.
The problem it solves
Investors often borrow a famous investor's lens. What would Warren Buffett look for? What would Peter Lynch buy?
MoatRadar turns that into a button. You pick an investor framework and an asset class: stocks, startups or crypto. The app returns a list of ideas, each explained through that investor's principles.
At launch, the Show HN post named investors like Buffett, Lynch, Soros and Damodaran, with ten ideas per search. Today the homepage claims 80+ investor frameworks and 40,000+ stocks on 70+ exchanges. It also says a search returns up to 20 ideas in about 30 seconds.
How it was built
The founder was direct about their background:
"I'm a non-developer and this is the first app I've ever shipped in my life." — chodelka on Hacker News
The founder built it over a few days with Claude and, in their words, a lot of vibe coding. Here is the stack in plain terms:
- Node.js with no framework. Node runs JavaScript on a server. Most tutorials add a framework like Express or Next.js. MoatRadar skipped that, so the AI wrote the raw server code.
- Vanilla JavaScript frontend. "Vanilla" means plain JavaScript in the browser, with no React or similar library.
- GPT-4o does the research and writes the explanations.
- Live price data keeps the numbers current.
- Stripe handles payments. Google OAuth is the "Sign in with Google" button.
- Railway hosts it. Railway is a platform that runs your server without you managing machines.
Notice what this means. The product is built with Claude, but it runs on OpenAI's GPT-4o. That's common. The model that writes your code doesn't have to be the model inside your product.
The founder also asked HN readers where the architecture was fragile. That's a smart question for a first app. The post got no comments, so no answer came from there.
How it makes money

MoatRadar sells credits. One search costs one credit, which works out to about €1.
| Pack | Price | Credits |
|---|---|---|
| Free, no account | €0 | 2 searches |
| Free, Google sign-up | €0 | 3 credits |
| Starter | €5 | 6 (5 + 1 free) |
| Popular | €10 | 13 |
| Pro | €100 | 150 |
There is also a 30-day money-back guarantee, described as "no questions asked."
Why credits instead of a subscription? Every search costs the founder real money in GPT-4o calls. With credits, each search the user pays for covers its own cost. There's no risk of a €9 subscriber running 500 searches. It also fits the use case. Most people won't need fresh investment ideas every day.
The bonus credits on bigger packs are a classic nudge. The €10 pack gives 13 credits for the price of 10. The €100 pack gives 150.
First users
The founder hasn't shared user or sales numbers. The Show HN link carried a promo code that gave HN readers 10 free credits. The homepage shows no user counts.
The free ladder is the interesting part. Two searches work without an account. Signing in with Google adds three more credits. That lets people try the product before they hit any payment screen.
What to copy
- Charge per use when each use costs you money. Credits map your AI bill to your revenue.
- Let people try before they sign up. Two anonymous searches lower the barrier to zero.
- Offer a refund guarantee. For an unknown app, a 30-day refund makes the first €5 easier to spend.
- Ask where your code is fragile. Then get a real answer from someone who reads code.
If you vibe-code this
An AI wrapper with Stripe credits and a hand-written Node server has classic weak spots. These are checks for the app type, not claims about MoatRadar.
- Verify Stripe webhooks, and grant credits only once. A webhook is Stripe calling your server to say "payment done." Without a signature check, anyone can send a fake one. See Stripe webhook security.
- Deduct credits on the server before calling the AI. Never trust a credit count sent by the browser.
- Rate-limit anonymous searches. Free searches without an account attract scripts. See API rate limiting.
- Keep the OpenAI key on the server only. See environment variable security.
- Add what a framework would add for you. Plain Node has no security headers by default. See security headers and CSP and secure authentication.
Here is a Stripe webhook in plain Node with no framework. The key detail is reading the raw body before any JSON parsing:
import Stripe from "stripe";
const stripe = new Stripe(process.env.STRIPE_SECRET_KEY);
export async function handleStripeWebhook(req, res) {
const chunks = [];
for await (const chunk of req) chunks.push(chunk);
let event;
try {
event = stripe.webhooks.constructEvent(
Buffer.concat(chunks), // raw bytes, not parsed JSON
req.headers["stripe-signature"],
process.env.STRIPE_WEBHOOK_SECRET
);
} catch {
res.writeHead(400);
return res.end("Invalid signature");
}
if (event.type === "checkout.session.completed") {
// Your helper: store event.id with a unique constraint,
// so a retried webhook never adds credits twice.
await grantCreditsOnce(event.id, event.data.object);
}
res.writeHead(200);
res.end();
}
Selling AI credits from a vibe-coded app? Email me at [email protected] and I'll audit your payment and credit logic.
Key takeaway
MoatRadar shows how small a paid AI product can be: one plain server, one model, one payment provider, and a credit pack. The pricing is well matched to the costs. The part worth the most care is the part a first-time builder can't easily read: the payment and credit code.
More case studies: Vibe-coded apps making money · Security basics: Vibe coding security guide
Sources
- chodelka, "Show HN: MoatRadar – AI investment research through Warren Buffett's principles," Hacker News, March 4, 2026: https://news.ycombinator.com/item?id=47255448
- MoatRadar homepage and pricing (checked September 2026): https://www.moatradar.com/