Back to the catalog

The first-time founder

Building their first B2B product. Has never bought auth, has never seen an auth invoice, and is not shopping.

readerReader 1Partly seeded

Seeding strength: PARTIAL. Read the warning at the bottom before you trust a verdict from this one.

Identity and situation

Building their first B2B product. Two or three people. They have a signup form and a database, and right now "login" is an email column and a password hash they copied from a tutorial. Nobody has asked them for anything yet.

They have never bought auth. They have never seen an auth invoice. They are not shopping. They arrived because someone linked them, or because they searched something like "auth for saas" at eleven at night.

What they know and don't

They know the phrase "don't roll your own auth". It reaches them as a rule rather than an argument, and it is the single loudest piece of received wisdom in the corpus:

"For years I've only heard 'never roll your own auth.'" — HN 48043496

"There are few hard and fast rules, but 'never use something that could change as a primary key' and 'never roll your own Auth' will always be true" — HN 48043654

They do not know:

This is the gap that matters. Every price-relief line we write is a punchline whose setup they never received.

What they fear

Not the bill. They fear shipping something insecure and finding out in public. Their mental model of auth risk is "I will get the crypto wrong", not "I will get the contract wrong".

They also quietly fear that this is more complicated than it needs to be:

"Donning a tinfoil hat for a moment, auth as a service companies have made everything seem substantially more difficult than it is too for simple needs." — HN 48043934

"I am stuck on simple authentication for my small apps." — HN 36386071

Their vocabulary

They say auth and login. They do not say sign-in, identity plane, principal, actor, or revoke path. They say "users", "log in", "sign up", "Google login".

When they describe what they need, it is a list of small things, not a category:

"You need: session management, account management (you'd already have this), and some simple social login pathways (PKCE etc)." — HN 46009114

What would make them act

A concrete picture of Monday: they paste something, and a user can log in. Time-to-working is the only currency they have. They will click a quickstart before they click pricing.

They are also moved by not being trapped later, but only if it is said in words they own. "Your users are in your own database" lands. "Sovereign identity plane" does not.

What makes them bounce

The one question the first screen must answer

"Is this the thing that handles logging in, and can I use it today?"

If they cannot answer that in five seconds, nothing else on the page gets a chance.

Seeding — and its weakness

Seeded from the "don't roll your own auth" thread cluster and the beginner-voice searches in the 539-item Hacker News corpus.

Known weakness, and it is serious. Beginners are systematically underrepresented in this corpus. People who post publicly about auth are mostly people who have already been through it. The "don't roll your own auth" quotes are real, but they are people discussing the maxim, not first-timers receiving it. So this persona's fears and vocabulary are inferred from the negative space more than from direct testimony.

Consequence for the panel: treat a Q1 failure from this persona as strong evidence, because Q1 is about comprehension and the vocabulary evidence is solid. Treat its Q2 "do you care" verdict as a hypothesis. To harden it, seed from beginner-heavy sources (r/SaaS, Indie Hackers, framework Discord onboarding questions) before relying on it to kill a line.


Panel verdicts

Run 01, 2026-08-21: failed the old headline

Surface under test: "Land the enterprise deal. / Keep the same bill." with the login-system lede and "Get an instance". This reader ran on GLM 5.3.

The lede landed. "Signet is your login system" was, in their words, "exactly what I was searching for at eleven at night."

The headline alienated them. They have no enterprise ask yet and no bill yet, so "keep the same bill" produced "Same as what?". "Get an instance" read as provisioning infrastructure: "I don't want infrastructure, I want login." SSO was never expanded. They would have clicked Quickstart.

The run's structural finding was that the Founders door conflated two different people. Never-bought and burned-and-switching react in opposite directions to the same money line.

Run 02: passed the rewritten screen

Q1 what is itQ2 do you careQ3 what nextLeft cold by headline
PASSPASSPASSNo

What is this? "Okay so... it's a login thing. 'Login for your app' - right, so it's something I plug into my app so people can log in instead of me building that myself. 'Your database, not ours' - I think that means the user accounts live in my own database, not on their servers? That's the part I actually get. So: it's a drop-in login system for my app."

Do you care? "Yeah, kind of, actually. Right now my 'login' is a users table with an email column and a password hash I copied out of a tutorial at like 1am, and every time I think about it too hard I get a little sick feeling that I did the password part wrong somehow."

What next? "I'd click 'Set up login.'"

Their residual objection was the door toggle: "The 'Founders | Enterprise | Agents' toggle at the top makes me pause for a second - like, wait, am I even in the right lane?" And on the lede's third sentence: "'Services and agents get keys you switch off' - I genuinely don't know what that sentence is doing. Keys? Switch off? I skimmed past it."

Run 03: passed, on Grok

DoorQ1Q2Q3Q4 objection
FoundersPASSPASSPASSjargon in the lede

What is this? "It is like a login thing you plug into your app, but they host it and the users still live in your database? You hit a button, people can sign up with email or Google-style login, and maybe later you can turn stuff off if you need to. I am not totally sure what work SSO is, or what they mean by keys for services and agents. Hobby being free on a work email is the bit that actually makes me want to click Set up login and see if a user can log in by Monday."

Do you care? "Yes. I have a users table with emails and a password hash I copied from a tutorial, and I keep thinking I am going to get that wrong and everyone will see it. I searched this at eleven because I need people to log in to the thing we are building, not because I am buying software."

Source: readers/01-first-time-founder.md