"It asks me to log in." "It's blank." The link isn't broken — it was never built to leave the tool. What each AI tool actually hands you, and what opens.
You built the thing. It works in the preview. You grabbed the share link your AI tool offered, sent it to a client — and the reply came back: "it's asking me to log in," or "the page is blank," or "this expired?"
The build is fine. The problem is the link — and specifically, who the link was designed for.
Every prompt-to-app tool gives you a way to "share." But that share is built for the path of least resistance inside the tool — keep the reader on the platform, signed into the account that has access, with the session still warm. That's great while you're the one looking. The moment the audience is a client, a teammate in another company, or a friend on their phone, the assumptions break one by one.
It's worth seeing the failure tool by tool, because each one fails differently — and the fix is the same shape every time.
Lovable and v0 — the only "real" link is a public one. The in-editor preview is tied to your session and your account; the version you can actually hand out is a publish or a deploy, which puts the build on the open, indexable web. So your two options are "they can't open it" or "the whole internet can." For showing a draft to one person before it's ready, neither is right. (Share a Lovable app privately and share a v0 build without deploying are the in-between.)
Bolt — the preview dies with the session. A bolt.new preview link runs inside the StackBlitz environment that built it. Close the project, and the person you sent it to is looking at a blank page or an error. The link was never a stable address; it was a window into your live session, and the session closed. (A bolt.new link that stays is the export hosted on its own.)
Gemini Canvas — the org wall, and the wall behind it. On a work or school Google account, conversation sharing is often switched off by an admin you'll never meet; Google's own help page says exactly that, and points you back at the administrator. The part people don't see coming is that switching it on doesn't solve the delivery problem either — Google is explicit that a shared Gemini link can be read by anyone holding it, including people you never sent it to, and that recipients can reshare it onward. So the two available states are no link at all or a link for everyone. There is no per-recipient setting in between, and plenty of recipients have no Google account anyway.
Neither behaviour is a mistake. Locking sharing down is what an admin is for, and a conversation you deliberately publish should be readable by whoever opens it. The two sensible designs just don't leave a door for the case in the middle: one named client, outside your org, who should see this and nobody else. (Share a Gemini Canvas as a link anyone can open routes around it.)
Claude and ChatGPT artifacts — the platform account. An artifact share link tends to bring the reader back onto the platform: an account prompt, a sign-in, the construction site instead of the finished room. For a polished hand-off, that's friction the recipient didn't ask for.
Different walls, one pattern underneath: the share link assumes the reader lives where you built the thing. Most of the time, they don't.
The fix isn't a better account setting. It's giving the build an address that doesn't depend on a login or a session at all.
That means three things, together:
.html file (CSS and JavaScript inlined) or a zipped folder. Once it's a file, it's no longer tied to the tool that made it.That last distinction is the whole game: the link should open for the people you chose, and stay closed to everyone else — without making any of them log in.
Drop the exported HTML or ZIP and get a private link that opens in any browser — no account for you to make the link, none for them to open it. Up to 3 MB on the anonymous tier; the link self-destructs after 7 days.
Worth being straight about scope. This pattern is for the self-contained build — the front end, the prototype, the page or tool that runs entirely in the visitor's browser. If your app signs users in, writes to a database, or runs server-side code, it isn't a file and it can't be one. That's a real deploy, and Vercel and Netlify are built for exactly that — they host the full app with its server side intact. Lovable, v0, Bolt, and Replit all publish to a live URL for the same reason.
The "host the export as a private link" pattern covers the step before that deploy — and the very common case of a build that never needs a backend at all. When the recipient just needs to open the thing and see it work, a private link is the lightest tool that does the job.
The recipient's experience is the test that matters. They click; it opens; it works; they didn't have to log into anything. Whatever you built it in — Lovable, v0, Bolt, Gemini, Claude — the move is the same: export the build, put it on a link that isn't tied to your account or your session, and send that. If you're still deciding where that link should live, the free places to host a single HTML file are compared side by side, split by whether the page is meant to be found or meant for specific people. And if you want their reaction back, turn on Review and they can pin feedback to the exact spot on the page — still with no account to create.
You built an app in Bolt, v0, Replit, Lovable, or Claude and it works — but it only works on your machine, and the deploy pipeline is a bigger commitment than the question you're trying to answer. What fits the in-between moment: a live link in seconds, and you decide who opens it.
The iteration loop with Claude / Cursor / Lovable produces a new version every round. Channels that let each round travel cleanly — without exposing the chat, the previous version, or the next reviewer to noise.
You shared the AI-built page — then what? The real work is the loop: build, show, react, fold the reaction back into the next prompt. Why hosting is only step one, and what actually closes the loop.
miinideck turns a single HTML file into an unguessable link with optional password and expiry. Default-private, never indexed.