AI tools can generate code quickly, but shipping a working app still depends on one old-school engineering skill: breaking the project into clear parts, defining system boundaries, and configuring each layer correctly.
The Principle I Keep Relearning
When people talk about building with AI assistants like Codex, the conversation often focuses on prompts. In practice, the bigger factor is architecture: what should run where, which service is responsible for what, how layers communicate, and which credentials and security checks belong in each environment.
This project was a perfect example. The code was not the hard part. The hard part was decomposition: deciding how to split data collection, pricing, frontend rendering, API handling, anti-abuse protection, and email delivery into a flow that is simple, safe, and maintainable.
Key takeaway: AI accelerates implementation, but clarity of system design determines whether the app is robust or fragile.
Why I Built This
I needed to catalog and sell my LEGO collection. Doing this manually would take too long: finding each set, collecting photos and descriptions, checking market prices, and publishing everything in a clean format.
So I asked Codex to help me build an application that could automate most of that workflow:
- Identify sets from my collection context and map them to correct catalog entries.
- Fetch images and descriptions for each set using the set number.
- Pull market prices from popular sources.
- Generate my listing price as market price reduced by a few percent.
- Publish sets on a simple sales page where buyers can send inquiries.

How the App Works
The frontend is a PHP page that displays my LEGO sets with images, metadata, and calculated asking prices. A buyer can pick a set and open a contact form directly from that item card.
Since I only needed one simple display page, I went with PHP on free hosting rather than spinning up another Vercel app — keeping things lightweight on the frontend side. The API logic stays on Vercel, where deployment is straightforward, while PHP handles the server-side rendering, which also makes the page easier to crawl by search engines and AI.
Behind the scenes, the contact form sends a JSON request to a serverless API endpoint. The endpoint validates the request, verifies anti-bot protection, and sends an email notification to me. Price data can be refreshed automatically or on demand, depending on how often I want to sync with the market.

Security Across Multiple Layers
Because this app uses multiple services, abuse prevention matters. We introduced protection at several points:
- Cloudflare Turnstile to filter bot traffic.
- CORS restrictions so only allowed origins can call the API.
- Server-side input validation before processing or sending email.
- Credentials and keys stored in environment variables, not hardcoded in backend code.
The system is hosted on free-tier services, which is completely sufficient for this project size. For a personal catalog and direct buyer inquiries, this stack provides enough performance with low operational cost.

What This Project Taught Me About AI Development
AI can write features fast, but only if I provide a clear model of the system first: inputs, outputs, trust boundaries, deployment targets, and configuration responsibilities. Once those constraints are explicit, tools like Codex become genuinely productive.
If those constraints are missing, even good generated code can become expensive to debug. In other words: prompt quality matters, but project decomposition matters more.

