A site scaffolded from a description
Pages, sections and prompts from an industry plan, with the four legally required pages appended automatically. Copy is left empty, not invented, until an LLM key drafts it.
Needs a keyAvailable now
In build
The whole team
Nineteen specialists, each with a defined job and an honest status label.
See all nineteen“I don't need a designer. I need a page that says what I sell, and a way for someone to actually pay me for it.”
Most site builders assume you already know what "good" looks like — a template you're meant to have opinions about, a page-builder grid you're meant to already understand, a publish button with no idea what it's about to make public. A shop owner doesn't want any of that. They want to describe the business, see it as a real page, and know exactly what they're agreeing to before it goes anywhere a customer could find it.
How it works
Three steps, and the middle one is the whole point: an approval you can actually read, built from exactly what's about to happen.
Say what the business is, and Kuber scaffolds the pages, sections and per-section writing prompts from an industry plan — with the four legally required pages appended automatically. Copy is left empty rather than invented; drafting it in your voice needs an LLM key.
Change any block, reorder sections, set up cash on delivery, GST and coupon rules, then review an approval built from the exact manifest about to go public — every page, every price, every payment method, the domain. Nothing is summarised away; it is itemized.
Publishing spends that approval once. The digest is recomputed at the moment of publish and compared against what was actually granted — edit a price after approving and the deploy is refused as stale. A successful publish still lands pending-host: going actually live needs a hosting credential, and Kuber says so rather than claiming it.
A phone and a stall is the whole starting point. Kuber is built for exactly this, not for someone who already knows what a design system is.
Before it goes public
The approval you grant is itemized — pages, prices, payment methods, the domain — and hashed. That digest is recomputed at the instant of publish and compared to the one you approved. Approve, then edit, then publish is refused, because the approval no longer describes what would actually go live.
Take the order anyway
A value floor and ceiling, pin-code allow and block lists, and optional phone verification, all evaluated locally at checkout with a stated reason when an order falls outside a rule. Marking the cash as actually collected is a real order-status move now that an orders table exists, refusing a second mark on an already-settled order.
The tax split
GSTIN shape, state code and check digit are validated locally, and the tax is split so the two halves add up exactly to what's charged — including the odd paisa a straight 50/50 split would otherwise drop. Now that orders exist, a numbered tax invoice generates once per order, idempotently, refusing outright rather than guessing if any line's HSN/rate is undeclared. E-invoice IRP registration still needs a GSP account.
Run a promotion
Percentage or flat codes with minimums, caps, a validity window, and total and per-customer limits. The limit check and the increment happen in one database statement, so a race between two shoppers can't both slip through — and a repeated order reference replays the original discount rather than granting a second one.
What it does
Each label is derived from the backend's own capability module — not written on this page.
Pages, sections and prompts from an industry plan, with the four legally required pages appended automatically. Copy is left empty, not invented, until an LLM key drafts it.
Needs a keyCreate, edit and reorder blocks freely, and every content change now snapshots a pre-image first, so an accidental deletion has an undo. Media upload is a presigned direct-to-bucket transfer, the same pattern Socie's media library uses, gated on an object-storage credential.
Needs a keyPages from a blueprint library, header and footer ordering, and hide rather than delete. A required legal page cannot be deleted at all.
Works todayRendered through the same renderer the publish uses. A mobile-only override never touches the desktop layout.
Works todayNo score and no ranking claim returned. A sitemap is generated from the pages actually visible, and can submit through Khoji's own Google Search Console connection — a workspace completes that OAuth once and both agents use it, since Search Console is a property of the domain, not of which agent asks.
Needs a keyRenders every page and records the deployment against a spent approval. There is no hosting target yet — publishing does not mean public until a CDN credential is connected.
Needs a keyA, CNAME and TXT records with explicit do-not-touch-MX warnings. Kuber holds no registrar credential and writes no DNS itself. Propagation checking needs a resolver.
Needs a keyImport reports errors per row instead of failing the whole batch, refuses duplicate SKUs and javascript: URLs. A size or colour variant now has its own stock, reserved atomically at order time so two simultaneous checkouts for the last unit can't both succeed.
Works todayValue floor and ceiling, pin-code lists and optional phone verification, evaluated at checkout with a stated reason. Marking cash as actually collected is a real order-status move, refusing a second mark on an already-settled order.
Works todayCard numbers, CVVs, VPAs and anything named like a secret are refused before the approval is even read. Taking real payment needs the gateway's own key and webhook secret.
Needs a keyGSTIN and state code validated locally, CGST/SGST split so the halves always add to the tax charged. A numbered invoice generates idempotently per order, refusing outright rather than guessing if a line's HSN or rate is undeclared. E-invoice IRP registration still needs a GSP (GST Suvidha Provider) account.
Needs a keyPercentage and flat codes with minimums, caps and limits, redemption checked and incremented in one statement so a race can't beat the cap.
Works todayValidated field kinds, a mandatory privacy line, honeypot and timing heuristics. Spam is filed rather than deleted, and a clean submission can email a named address. The public embed a visitor's browser would call still needs the site to be hosted.
Needs a keyPrices are re-read from the catalogue on every step, never trusted from the client, and a checkout session freezes the coupon, GST split and COD eligibility it computed so the order records exactly what a shopper agreed to. A cash-on-delivery checkout is genuinely complete end to end with no credential; paying by gateway needs one connected first.
Needs a keyCancelling needs a reason and restocks every tracked variant. Shipment updates and the tracking history are written by the seller and emailed to the customer at each stage. What's genuinely absent is automatic courier polling — no courier is chosen and no courier API is called, so every event today is entered by hand.
Needs a keyStaff hours, slot listing, booking, reschedule and cancel all run locally end to end. Double-booking is refused by a database constraint, not a read-then-write, so two simultaneous requests for one slot always resolve to exactly one appointment. An email reminder sends when the customer left an address; a WhatsApp reminder or a Google Calendar sync are not wired up yet.
Needs a keyA share link to the site's own product grid works today against real data — slug, click count, first and last click — with no Meta credential involved. A synced native WhatsApp/Instagram catalogue message needs the WhatsApp Business API or the Meta Commerce API; every sync attempt is logged rather than failing silently either way.
Needs a keyPage views and cart-funnel events are Kuber's own rows — no third-party analytics script runs on a Kuber page. Overview aggregates traffic, checkout starts and completed-order revenue, grouped by currency and never summed across one, exportable as CSV or JSON.
Works todayWhat Kuber will never do
Five things Kuber refuses outright, each enforced in code — not a setting an owner could accidentally switch off.
Every page, section, price, payment method and domain about to go public is itemized and hashed. That digest is recomputed at the moment of publish and compared to the one actually approved — edit a price after approving, and the deploy is refused as stale.
A deployment row cannot be written without a granted, unexpired, unspent approval. One grant covers exactly one action — an owner who approved one publish has not approved every future one.
Copy is checked against a guard that refuses prices, percentages, ratings and customer counts nobody entered — plus four classes Kuber adds itself: certifications, delivery promises, stock counts and review volumes. A thin brief gets an honest, plainer page, not a confident invented one.
A privacy policy, terms, a refund/cancellation policy and a reachable contact page are required, not optional polish — the Consumer Protection (E-Commerce) Rules 2020 and the DPDP Act 2023 require them, and a required legal page cannot be deleted at all.
Connecting a payment gateway stores only a provider name and a public merchant reference. Anything shaped like a card number, a CVV, a VPA or a secret is refused before the approval is even read — this schema has nowhere to put it.
Still needed
A publish renders every page and records the deployment, but lands pending-host: it needs a hosting or CDN target credential before anyone outside this account can see it. Connecting your own domain needs a resolver for propagation checking and an ACME account for TLS. A form's public embed — the endpoint a visitor's browser actually calls — waits on that same hosting step, since nothing here is reachable without it.
Connecting a gateway is approval-gated and stores only a provider name and a public merchant reference — a card number, CVV, VPA or secret is refused before the approval is even read. Taking real payment needs the gateway's own key and webhook secret, which this schema is built to hold and currently does not.
Site scaffolding and block editing both work with no credential; what needs one is drafting copy in your own voice (an LLM key) and uploading an image or file (an object-storage credential). Until then, copy stays empty rather than invented, and media upload is unavailable rather than silently failing.
An SEO audit, meta editing and a generated sitemap all work locally; submitting that sitemap to Search Console needs the same Google OAuth connection Khoji uses. A numbered GST invoice generates today; registering it with the government's e-invoice portal needs a GSP (GST Suvidha Provider) account this deployment hasn't connected.
Shipment tracking, appointment reminders and catalogue sharing all record real state today; what's missing on each is the outside connection that would make it automatic — a courier's tracking API (a partner still needs choosing), a WhatsApp number for a booking reminder, and the WhatsApp Business or Meta Commerce API for a native catalogue message.
Before you switch
Tell us what you sell and how you take orders today, and we'll tell you plainly what Kuber can carry now — and what still needs a hosting or gateway credential.
Questions
No. The approval is hashed against the exact manifest you saw — every price, every page, every payment method. That digest is recomputed the moment you actually publish and compared to what you approved; if anything changed in between, the publish is refused as stale and asks you to review and approve again.
No, never. A deployment cannot be written without a granted, unexpired, unspent approval — an explicit, itemized confirmation immediately before the action. Even a successful publish lands pending-host rather than live: going actually public needs a hosting credential connected separately.
No. A guard checks generated copy for exactly this — prices, percentages, ratings and customer counts nobody supplied, plus certifications, delivery promises, stock counts and review volumes. A thin business description gets honest, plainer copy back, not a confident invented claim.
No. A required legal page cannot be deleted at all, and a site cannot be marked ready to publish while one is missing, hidden or left empty. This isn't a nag — it's the Consumer Protection (E-Commerce) Rules 2020 and the DPDP Act 2023 requiring exactly this information from a seller and anyone collecting personal data.
No. Connecting a gateway stores only a provider name and a public merchant reference — the schema has no field for a secret. Anything shaped like a card number, a CVV, a VPA or a key is refused before the connection request is even read.
Yes, by cash on delivery — a real cart, a checkout that re-reads prices from the catalogue rather than trusting the client, and an order record complete end to end with no credential. Paying by gateway is refused with a clear error until a payment gateway is connected; that's the one piece still waiting on a credential.