Reshuk Sapkota
← Writing

Why MakeMeSafe matters for solo developers

4 min read

Google OAuth shouldn't take an hour

Every authentication guide quietly assumes there is someone else on your team. Someone who already owns the Cloud project, who knows which of the four consent screens is the real one, who set the redirect URIs up last year and wrote them down somewhere.

If you are building alone, that person is also you. And you are supposed to be building the product.

MakeMeSafe is for that situation. Here is what it changes, and why each change matters more when there is nobody to hand the console to.


1. The hard part was never OAuth

OAuth 2.0 is a well-documented protocol. You can read the whole flow in an afternoon and it will make sense: redirect the user, get a code back, exchange it for a token, done.

The hard part is everything wrapped around it. Creating a Cloud project you never wanted. Enabling an API you will never call directly. Filling in a consent screen for an app that has no users yet. Choosing scopes before you know what you need. Adding yourself as a "test user" of your own software.

None of that is authentication. It is paperwork that happens to stand between you and authentication.

The console path versus the MakeMeSafe path

MakeMeSafe collapses the paperwork into three fields: what the app is called, where to send users back, and which sign-in methods you want. Out comes a Client ID and a Client Secret. The protocol on the other side is the same OAuth you already know — nothing proprietary, nothing to unlearn.


2. An hour is cheap. This hour is not.

Saving an hour sounds minor. If MakeMeSafe saved you an hour in month three of a project, it would barely be worth writing about.

It saves it in the first hour — and the first hour of a side project is not like other hours. It is the one where the idea is still exciting, the tab is still open, and nothing has gone wrong yet. It is also the hour with the highest chance of being the last one.

What you hit first What usually happens next
A blank editor You build something
A consent screen You go and make tea
An approval queue You open the project again "next week"

Nobody abandons a project because OAuth was conceptually hard. They abandon it because the first evening produced nothing they could look at. Getting to a working login on day one is not a convenience — it is the difference between a repo and a habit.


3. Five ways in, one thing to integrate

Five sign-in methods behind one integration

Google, GitHub, Facebook, email, or a magic link. You tick the ones you want.

The reason this matters to a solo developer is not the list — it is that the list does not multiply your work. Each provider you add the normal way is another developer account, another set of app review rules, another redirect URI to keep in sync across local, preview and production. Three providers is three times the surface area for something to silently break on a Friday.

Behind MakeMeSafe it stays one integration. Adding GitHub next month is a checkbox, not an afternoon.

And it works against whatever you are actually building in — React, Next.js, Flutter, Android, iOS. The credentials do not care about your framework.


4. Credentials you can rotate without a redeploy

The uncomfortable truth about a solo project is that the secret is usually in more places than you remember. A .env.local, a hosting dashboard, a CI variable, and — if it has been a long week — a chat message to yourself.

MakeMeSafe treats credentials as something that rotates. They are encrypted, scoped to your account, and replaceable when you need them replaced. That turns the worst-case moment from a rebuild of your auth setup into a copy and a paste.

If you have ever thought "I should rotate that key, but I do not remember everywhere it lives" — that thought is the feature working out what to be.


5. What this actually buys you

Not an hour. A different shape of evening.

The version of a weekend project that dies is the one where Friday night is spent on infrastructure, Saturday on remembering what you were building, and Sunday on nothing. The version that ships has a working login by the time the tea is cold, and spends the rest of the weekend on the part only you can build.

Auth is table stakes. Nobody has ever downloaded an app because its OAuth implementation was thoughtful. It has to be there, it has to be safe, and then it has to get out of the way.

That is the whole argument: spend your first hour on the part of your product that is actually yours.

Try MakeMeSafe — free to start, no credit card, no Cloud Console.

New writing, in your inbox.

An email when I publish something new. No digest, no newsletter series, and one click to leave.

Prefer a reader? RSS.