Replit Agent: Building Apps From a Prompt

Replit Agent builds and publishes apps from a chat in the browser. What Agent 4 does, how its modes and task board work, what checkpoints and rollbacks restore, how publishing and the two databases work, the limits, and the security work that stays with you.

7 min read

Replit Agent is the AI agent inside Replit that turns a plain-language request into a working app, then hosts it. You describe what you want, and Agent plans the work, writes the code, sets up a database, tests the result in a real browser and publishes it to a .replit.app address or your own domain. The current generation is Agent 4, launched in March 2026, which splits work into parallel tasks on a board and adds a design canvas. Two safety nets matter most: checkpoints you can roll back to, and a production database that Agent is not allowed to touch. The limits are the usual ones for a hosted builder, plus a security review that Replit says is your job, not its own.

What Agent 4 does

Agent works in a Replit project in your browser, and one project can hold several outputs, a web app, a mobile app, slides or a data dashboard, sharing one backend. The Replit Agent overview (opens in a new tab) describes it taking action rather than only answering: it sets up the project, creates the app, checks its work and fixes problems as it goes. It can also work without an app in mind, creating files, doing research or reading connected services such as Linear, Slack, Notion or BigQuery.

  • Plan mode: Agent brainstorms and writes an ordered list of tasks without changing code or data. You approve the plan, or revise it, before building starts.
  • Tasks and the board: accepted tasks run in the background in isolated copies of your project, on a board with Drafts, Active, Ready and Done columns. Nothing reaches your main version until you review a task and choose Apply changes, or Dismiss. How many run at once depends on your plan.
  • Modes: Free Mode uses a no-cost allowance and picks models for you; Power Mode is the cost-conscious paid mode; Max Mode uses the most capable models for hard, large or production work. In Power or Max you can let Auto choose a model or pick one yourself. Economy Mode no longer exists.
  • App Testing: in Power or Max, Agent opens your app in a real browser, clicks through it like a user, and fixes what fails, leaving a video replay. It currently covers full-stack JavaScript and Streamlit apps.
  • Design Canvas: an always-available canvas for trying visual variants of your app and applying the one you like.

Coming from Agent 3? Replit’s post on what changed from Agent 3 to Agent 4 (opens in a new tab) says the fork-and-merge model for teammates was replaced by the shared task board, planning and building now happen at the same time, and the separate Design Mode became the Design Canvas.

Checkpoints and rollback

Agent saves checkpoints on its own: after finishing a feature, at major milestones, after testing, and before attempting a fix for a serious error. Replit’s page on checkpoints and rollbacks (opens in a new tab) says each one captures your project files and packages, the Agent conversation and its memory of the project, environment settings, and your database’s data and schema. You roll back from the Agent tab with Rollback to here, and you can roll forward again if you went too far, until you make new changes.

  • Code only by default: a rollback leaves the database alone unless you tick Database under the additional rollback options, and then it restores the development database only.
  • Production is separate: your live database is never rolled back this way. It has its own point-in-time restore.
  • Everything after goes: rolling back discards all later changes, code included, so read the checkpoint descriptions first.
  • Git sees it too: checkpoints appear as commits in the Git pane. Replit still recommends your own Git commits for long-term history.

Databases: development and production

Ask Agent for a database and it adds a managed PostgreSQL database, writes the schema and connects the app through an ORM. Every app then has two. Replit’s page on development and production databases (opens in a new tab) sets out the rule: Agent can create and change tables in the development database, but it is not able to modify the production database. When you publish, structural changes you made in development, such as added or dropped columns and tables, are applied to production.

That last step is where live data gets hurt. Replit lists the risky changes: removing a column the code still uses, changing a column’s type, adding a required field with no default, renaming tables or columns, and tightening constraints. For anything like that, test in a deployment preview, a temporary copy of production, before you publish, and only copy development data into production if it is safe to show real users.

Deploying

In Replit, deploying is called publishing, and the Publishing tool (opens in a new tab) gathers every choice in one pane: the address, who can open the app (Public, Password protected, Workspace only or Invite only), the production database, uptime monitoring, a security scan and a feedback widget. Under Adjust settings sit the deployment type, machine size, secrets, which sync from development automatically, and the region, which is fixed once you publish.

  • Autoscale: the default, adding servers under load and scaling to zero when idle.
  • Reserved VM: one always-on machine, for bots, background workers and APIs that must stay connected.
  • Scheduled: runs a command on a cron schedule and stops, with no public URL.
  • Static: files only with no backend, and not compatible with apps Agent builds, because those are full-stack.

Published apps do not change when you keep editing; publish again to push updates. Mobile apps follow their own path through Replit’s Launch feature to App Store Connect and TestFlight.

Limits to plan around

  • Free Mode is for getting started: App Testing is off and scheduled routines do not run there.
  • App Testing covers full-stack JavaScript and Streamlit web apps, not every framework Agent can write.
  • Rollback is not backup for live data: plan production restores and risky migrations separately.
  • Region is fixed after publishing; changing it means remixing the app.
  • Moving a project: downloading a zip or copying a project leaves out secrets, the database and deployment settings, which you set up again. GitHub sync runs through the Git pane.
  • Agent writes the code, and you still own it: Replit’s model puts code review, licensing and business logic on you.

Security basics

Replit runs a security scan before every publish, and a setting can block publishing when it finds critical vulnerabilities; the Project Security Center adds deeper scans, up to a black-box test of the running app. Its shared responsibility model (opens in a new tab) is clear about the split. Replit is responsible for the Agent harness, the platform and edge protection. You are responsible for reviewing Agent’s output and the dependencies it adds, approving sensitive actions such as deploys and secret changes, not feeding Agent untrusted content without checking it, vetting any MCP servers and skills you install yourself, and who can log in to your published app and what each user can see.

In practice: keep keys in Secrets, never in code; test with two accounts that one user cannot read another’s data; and read the scan results rather than only clearing them. The wider checklist for AI-built apps is in vibe coding security, and the risk of connecting untrusted tools is in MCP security risks.

Replit Agent or Bolt?

Both build and host apps from a browser chat. Bolt runs the development environment inside your tab and supports JavaScript backends only; Replit runs projects on its own servers, and Agent can work outside JavaScript, for example with Streamlit in Python. Replit leans further into operations, with parallel background tasks, browser-based self-testing, separate development and production databases, and several deployment types. Bolt keeps the setup lighter. The full picture of Bolt is in Bolt.new: what it builds and where it stops, and moving a builder project to a coding agent is covered in Lovable, Bolt and v0 vs Claude Code.

One list of work beyond the project

Agent 4’s task board is useful, and it lives inside one Replit project, for Agent’s own tasks. Work that crosses tools, or involves people who never open Replit, needs a list of its own. fenbs is a board where people and AI assistants are members: each feature, enhancement or bug has a note, a plan and a test status, in To Do, Next Up, In Progress and Completed, and History records who changed what. Replit Agent can add a custom MCP server by URL and walks you through its OAuth sign-in, so a fenbs board at https://fenbs.ai/api/mcp can be connected the same way you would connect Linear or Notion, with the scopes you choose. fenbs has no due dates, sprints or epics; it holds the work and who did it.

Related

Sister post: Bolt.new. Where builders fit: vibe coding vs low-code and what vibe coding is. Before you connect any tool: MCP security best practices. Connecting a board: the MCP docs.

Questions people ask.

What is Replit Agent 4?

The current generation of Replit Agent, launched in March 2026. It plans and builds in parallel background tasks shown on a board, adds a Design Canvas for visual variants, and replaced Agent 3’s fork-and-merge collaboration with a shared task board.

Can Replit Agent change my production database?

No. Replit says Agent can create and modify tables in the development database but cannot modify the production database. Structural changes you made in development are applied to production when you publish, so review risky migrations first.

Does a Replit rollback restore my data?

Only if you choose to. Rollbacks restore code and project state by default; tick the Database option to also restore the development database. The production database is restored separately with a point-in-time restore.

Is Replit Agent free?

Replit plans include a Free Mode allowance for everyday Agent work, with limits that depend on your plan. Power Mode, Max Mode and App Testing use paid credits. Check Replit’s pricing pages for current terms.

Start with one thing.

There is nothing to set up first. Write one line and you’ve started.