HNHacker News
TopNewBestAskShowJobs

rishabhpoddar

125 karma · joined March 9, 2017

Founder & Ex-CTO at SuperTokens.com
submissionscomments
rishabhpoddar··on Ask HN: What's a prompt you've written that you're genuinely proud of?
There is never "one" prompt per say.. it's usually a workflow or something with the right set of information in the context and right set of tools.

One thing I'm proud of is that at my work (the product is a child facing toy / bot), i created an agent loop that tests our AI layer with adversarial questions (that it should block) based on trending non child friendly topics. This was done manually before, and so my agent loop saves a lot of time

rishabhpoddar··on Midjourney Medical
I really wasn't expecting a hardware device from midjourney! Incredible!!
rishabhpoddar··on Ask HN: What's your biggest LLM cost multiplier?
- Tool calling: This is unavoidable, but I try structure the tools such that the total tool calling for an input is minimised.

- Using UUIDs in the prompt (which can happen if you serialise a data structure that contains UUIDs into a prompt): Just don't use UUIDs, or if you must, then map them onto unique numbers (in memory) before adding them to a prompt

- Putting everything in one LLM chat history: Use sub agents with their own chat history, and discard it after sub agent finishes.

- Structure your system prompt to maximize input cache tokens: You can do this by putting all the variable parts of the system prompt towards the end if it, if possible.

rishabhpoddar··on Ask HN: Easiest way to run Claude Code on my MacBook using my iPhone, remotely?
Thanks! Will check these out.
rishabhpoddar··on Show HN: 1Code – Open-source Cursor-like UI for Claude Code
Hmm. But the value of using claude code for me is that it runs on my local machine. I have setup several skills / commands / workflows that rely on the content on my machine. So i guess using it on a remote sandbox won't help me.
rishabhpoddar··on Raising money fucked me up
> When one does not raise money you get questions like "how do we know you will be here in 6 months, how are you funded?". I doubt people will tell you directly "oh, we have seen you are funded we decided to give you a chance".

The thing is, we did raise money, and we still go the same questions, and we replied saying these are the VCs that have funded us, and we still lost those kinds of deals. The deals we won, were mainly cause we solved some burning pain point of that specific user, who really didn't care about our funding status.

> You can raise money to execute (a part of) a larger plans. There are various fields that have barriers to entry in terms of regulation and/or compliance. This can still be couple of FTE + costs before you can sign any deal.

Agreed. But for most startups, people raise cause they need more money to survive.

> This highly depends on the type of business. If you are for example in B2B you can't tell your customer "sorry I can meet only after 19:00 because of my other job" not to mention how you can be perceived.

Agreed. It's not ideal, however if you are solving a big enough pain point for the user, I'm willing to bet they won't mind it.

> make sure the startup has external feedback that you listen to. All founders are quite stubborn - which is good and necessary - and is hard to convince them they need to adjust/pivot/rethink things. Investors can do that, but best is to have some previous experience with the field, otherwise they can be just noise.

Yup, I agree here as well. But, the best external feedback is not from your investors, but from your (potential) customers!!

rishabhpoddar··on Raising money fucked me up
Im a former YC founder, I recommend to NOT raise external money from anyone, unless there is literally no other choice.

Raising money has been marketed as success by VCs and they have done a great job of it. Remember, that in reality, raising money is sign that your business is not doing well.. not the other way around.

Furthermore, a lot of people hope that raising money will help them get distribution and customers' trust. Thats NOT true. We raised a decent amount of money from YC and other VCs, and despite that, the thing that helped us most for distribution was content SEO and posting on reddit + no customer ever told us that they were using our product cause we raised $X from these VCs..

People also expect that well known VCs will help you magically solve issues in your company. That's not true either.. VCs may seem very smart, but when it comes to the details of solving issues about your company, they literally can't help, cause they don't know as much as you do about your business.

Another reason people want to raise money is cause they can't afford to quit their jobs and rely on their startups. In this case, well, do not quit your job.. work on your startup as side project until it's already generating 1.5-2x your annual salary, in a stable way. Remember this way, you dont have a deadline for your startup based on your runway, which is GREAT not only from your startup's survival point of view, but also from a mental health point of view.

I would also like to talk about hiring. A lot of people just assume that raising money is needed cause that way they can hire people and grow faster. This is again, not true.. usually, hiring people means you are actually going to slow things down unless you know EXACTLY what you want to hire for, which is rare for a startup. Even if you find a great person for the job, they will take at least a few months to be full productive, and if your startup is not growing like crazy (which is true for most startups), the person will likely leave (cause they are good and will find a better company) = wasted time.

I would like to say that money you raise for your company is NOT your personal money. You can't just spend it on buying stuff for yourself. In fact, even taking a decent salary from that money is looked down upon, unless your startup is doing really well already.

Finally, VCs play a numbers game. They invest in 100s of companies hoping one of them will give out a massive return and cover the losses for everyone else + make a huge profit. You are, statistically, in the ones that won't make it, and you will be written off.. at this point, you will have an entity, owing a large part of your company who literally doesn't care about you.

All of the being said, here are the reasons of why you SHOULD raise money: - Your business model only works at scale. - Your initial investment costs are very high: This is usually never true for software companies. - You are trying to impress your partner and / or friends in the short term and give them the illusion that you are successful already (lol).

rishabhpoddar··on Ask HN: Is it still worth pursuing a software startup?
It is. Big companies (or really anyone) usually don't have the time to copy an idea unless it becomes too big already. And if your idea becomes too big, it was worth pursuing it.
rishabhpoddar··on Show HN: 1Code – Open-source Cursor-like UI for Claude Code
I didn't quite understand what "Unlimited web & macOS apps access" means in the paid tier. Could you elaborate?
rishabhpoddar··on Unified API for AI Agents to Communicate Across Channels – Feedback Needed
Thanks. Would love to hear any big pain points you may have when building AI agents!
rishabhpoddar··on Unified API for AI Agents to Communicate Across Channels – Feedback Needed
I'm building an API that lets developers enable their AI agents to communicate with users across multiple channels (email, Slack, SMS, WhatsApp, etc.) through a single integration.

Why? Developers spend significant time integrating and managing different communication platforms. This API simplifies the process while offering users more flexibility in how they interact with agents.

Key Features:

- Unified communication across multiple channels via one API.

- OAuth token management: Simplifies login flows and token handling for developers.

- Centralized user control: Users can monitor and revoke tokens in one place.

- Analytics for developers: Insights into agent usage and performance.

- Consent management: Tools to ensure user consent for actions.

I'd love to hear from developers working on AI agents: Is this a problem you're facing? What would make this solution indispensable for you?

rishabhpoddar··on Show HN: Comprehensive authentication library for TypeScript
Do checkout supertokens.com - open source auth. We have tons of features and also full TS support.
rishabhpoddar··on Ask HN: Help with transpiling TypeScript to Golang and Python using LLMs
Okay! Super cool! I will check it out and reach out if needed. You are right in that i can't fully rely on LLMs. We will of course have several tests + line by line code review done for the generated code.
rishabhpoddar··on Supertokens: Open-Source Alternative to Auth0 / Firebase Auth / AWS Cognito
Right. Makes sense. I think what we had originally intended to communicate is the ease of customisability, in which case, we feel that Keycloak's UI customisation is more difficult to do.
rishabhpoddar··on Supertokens: Open-Source Alternative to Auth0 / Firebase Auth / AWS Cognito
Fair enough. We are in the process of adding this feature.
rishabhpoddar··on Supertokens: Open-Source Alternative to Auth0 / Firebase Auth / AWS Cognito
We don't have SDKs for these yet, but you can always spin up a node process with our node SDK and use that as the auth server for your Elixir app. The node process would create a session and issue JWTs to the frontend which can be sent to the Elixir backend for API auth.
rishabhpoddar··on Supertokens: Open-Source Alternative to Auth0 / Firebase Auth / AWS Cognito
We provide a docker container which manages running the SuperTokens core (the java part) for you. You can easily run several of these behind a load balancer and scale to millions of MAU. We have several users who have done this with no java knowledge whatsoever.
rishabhpoddar··on Show HN: Open Source Authentication and Authorization
Thanks for letting us know about the broken link :)
rishabhpoddar··on Show HN: Open Source Authentication and Authorization
The reason it says Partial is cause we don't have 2FA with TOPT at the moment. This feature, along with FIDO / webAuthN are in our dev pipeline.

> If I was self-hosting the open source version at auth.mydomain.com would I be able to export the data, load it into your cloud offering and point the domain to your service for a hiccup free transition for site users? What about the reverse?

Yes you can - both ways.

rishabhpoddar··on Show HN: Open Source Authentication and Authorization
There are other differences too:

- Our architecture is different: We provide a frontend SDK with react components that are embedded in your own website - giving you more control and a better dev experience. The frontend doesn't talk to SuperTokens directly, but instead proxies requests via your backend API layer (using our backend SDK). This makes it much easier for you to customise the backend auth logic (you can reuse your API code and also are not forced to use Java), and also enables us to handle your app's session management out of the box.

- For use cases that don't need OAuth (for example if you have a single website), we don't require you to use the protocol. This makes it simpler to setup auth, especially for people not familiar with OAuth and its various flows already.

- There are other feature differences - some features that we have that they don't and vice versa. But this is just a function of time investment on either side.

rishabhpoddar··on What language to use to build webapp or OSS project?
Another big factor is the availability of hiring talent. But I guess this already comes under the popularity point.
rishabhpoddar··on Okta to Acquire Auth0 for $6.5B
For example, if you require email / password auth without SSO, then we do not use open ID connect or any of the oauth flows - because those are not needed in a simple setup.
rishabhpoddar··on Sick of spending time on Auth, we built an open source 'Stripe for Auth'
One important point is that we do not follow the OAuth 2.0 protocol since for simple email password login without SSO, we do not need to provide OAuth.

So the login part, is a simple API call with the email / password. On success, a session is created, and the flow for that is provided here (in a diagram): https://supertokens.io/docs/emailpassword/common-customizati...

rishabhpoddar··on Sick of spending time on Auth, we built an open source 'Stripe for Auth'
Yes. It was using HMAC. But I would still assume that RSA would be much faster than a db lookup (in a distributed system)?
rishabhpoddar··on Sick of spending time on Auth, we built an open source 'Stripe for Auth'
This is a debatable topic. We wrote a blog post about this as well: https://supertokens.io/blog/are-you-using-jwts-for-user-sess...
rishabhpoddar··on Sick of spending time on Auth, we built an open source 'Stripe for Auth'
Thanks for the encouragement :) We will be happy to help when you get started.
rishabhpoddar··on Sick of spending time on Auth, we built an open source 'Stripe for Auth'
Oh! Thanks for the heads up! I have created an issue about this on our github, referencing this comment.
rishabhpoddar··on Sick of spending time on Auth, we built an open source 'Stripe for Auth'
Thanks for the comment and disclosure :)

We do intend to be a full featured solution. Though, since we are relatively new, we only provide email and password.

That being said, our approach is modular in nature so that users get only what they want.

rishabhpoddar··on Sick of spending time on Auth, we built an open source 'Stripe for Auth'
Thank you! Really appreciate your kind words :) Have a great day
rishabhpoddar··on Sick of spending time on Auth, we built an open source 'Stripe for Auth'
So the core is written in Java. The core is a http microservice that contains the main auth logic + interacts with the database.

The backend API queries the core for sign in / sign up / sessions etc... This can be in any framework, and we decided to choose NodeJS first. Here, the user does not have to interact with Java at all.. just simply use our NodeJS SDK that internally calls the core's APIs

← PreviousPage 2 of 4Next →