# FAQ

> Straight answers to the questions people ask before and after they scaffold their first BSV app.

> Agents: search these docs with the `search_docs` tool on the MCP server at https://createbsvapp.vercel.app/mcp, or read everything at https://createbsvapp.vercel.app/llms-full.txt.

**TL;DR:** it's free to run, users need a BRC-100 wallet, and the generated code is yours to read and change. Before real users arrive, work through the [deploy](https://createbsvapp.vercel.app/docs/deploy#production-checklist) and [security](https://createbsvapp.vercel.app/docs/security#before-you-launch) checklists.

## Does it cost money to run?

Not for authentication. Wallet login and signed requests are signatures, not transactions, so no coins move and nothing touches the blockchain. New projects target testnet by default. Costs only start when *your* app creates [transactions](https://createbsvapp.vercel.app/docs/bsv-primer#signatures-vs-transactions).

## Do my users need a wallet?

Yes, any [BRC-100](https://createbsvapp.vercel.app/docs/glossary#brc-100) wallet. We recommend [BSV Browser](https://browser.bsvb.tech/), free on macOS, Windows, iOS and Android. Desktop users connect directly, and phone users scan a QR code.

## Is it production-ready?

The generated code is built with production in mind: production config refuses to start without HTTPS and a stable server key, proofs are single-use and expire, and the API client is locked down. Whether *your app* is ready depends on what you add. In particular:

- apply the [1.1.2 build fix](https://createbsvapp.vercel.app/docs/troubleshooting#client-build-fails)
- move the nonce store to [Redis or your database](https://createbsvapp.vercel.app/docs/security#replay-protection-across-instances) before running more than one instance
- add rate limits and authorization, and remove the demo routes

The [security model](https://createbsvapp.vercel.app/docs/security) lists exactly what is and isn't guaranteed.

## Why signatures instead of passwords or sessions?

A signature proves who sent a request without a shared secret that can leak, be phished or be reused. Signed requests are stateless: no session store, nothing to steal from a cookie jar. If you want "stay logged in", issue your own session after [wallet login](https://createbsvapp.vercel.app/docs/capabilities#turning-login-into-a-session).

## Why generate code instead of shipping a library?

So you can read, change and own the code that decides who's logged in. See [Why create-bsv-app](https://createbsvapp.vercel.app/docs/why#the-positions-we-take).

## Can I use Next.js, Vue, Fastify or Hono?

The generated *starters* are Vite + React and Express. The *helpers* are plain TypeScript: `verifySignedRequest` runs in any Node server, and the React hooks run in any React app. Use [add mode](https://createbsvapp.vercel.app/docs/add-to-existing#frameworks-other-than-vite-and-express) and treat the wiring snippets as a guide.

## Can I add this to an app I already have?

Yes, with add mode: `npx create-bsv-app@latest add --capabilities wallet-connect,wallet-login --yes`. See [Add to an existing project](https://createbsvapp.vercel.app/docs/add-to-existing).

## Does it work without a server?

Partly. A frontend-only app (the `react` starter) can connect a desktop wallet. Phone pairing, login and signed requests need a server to verify proofs and host the relay.

## Where is user data stored?

Nowhere, until you decide. The scaffold has no database: the only "user record" is the identity key in a verified proof. Store whatever you need, keyed by it.

## Where do I get testnet coins?

From the [BSV Faucet](https://bsvfaucet.com/), run by the BSV Association: sign in, paste a testnet address from your wallet, and request up to 10 million satoshis every 24 hours. You only need coins once your app creates [transactions](https://createbsvapp.vercel.app/docs/bsv-primer#your-first-payment); login and signed requests are free.

## How do I go to mainnet?

Pass `--network main` when scaffolding, or set `BSV_NETWORK` and `VITE_BSV_NETWORK` to `main`. Signatures work the same on every network. See [Networks](https://createbsvapp.vercel.app/docs/environment#networks).

## How do I get the latest helper files after a CLI update?

Commit first, then run `npx create-bsv-app@latest add --capabilities <ids> --force --yes` and review the diff. `--force` overwrites the helper files.

## Is @bsv/app still supported?

No. It's deprecated and forwards to create-bsv-app. See [Migrate from @bsv/app](https://createbsvapp.vercel.app/docs/migrate-from-bsv-app).

## Can my AI agent use this?

Yes. Use `--file` or `--yes`, read the generated `AGENTS.md`, and connect the docs over [MCP](https://createbsvapp.vercel.app/docs/agents#connect-the-docs-over-mcp).
