Build with AI

How to build a UGC creator marketplace with OpenAI Codex

Own the platform instead of renting one that takes a cut. Campaigns from brands, applications and video from creators, a licence granted the moment work is approved, and a payout the creator can actually track. Describe it from your terminal and Codex writes the schema, the permissions, and the money flow as diffs you approve.

August 2026 · 45 min read · Updated September 2026

OpenAI Codex

$ Build a two-sided UGC marketplace: brands fund campaigns and review submissions, creators apply and upload video, approving a submission grants a licence and credits the creator’s wallet, and every table is locked down so neither side can read the other’s.

  • Data model written as migrations
  • Money moved server-side only
  • Ready for your review
You describe it, Codex builds it
Start here

What a UGC creator marketplace actually is

A UGC marketplace is the middle of a transaction: a brand wants video it can advertise with, a creator wants paying for making it, and your platform is what makes both sides comfortable enough to go through with it.

Strip it back and there are three loops running at once. A brand posts a campaign with a budget and a brief. Creators apply, get picked, and upload their work. The brand reviews it, asks for a change or approves it, and the moment it approves, two things have to happen together that most software treats as unrelated: the rights to that video have to move to the brand, and money has to move to the creator.

That pairing is the whole job. Everything a marketplace gets criticised for lives there: a creator paid three weeks late, a brand running an ad on footage it turns out it never licensed, an account that took the money and vanished. The screens are ordinary. What is not ordinary is holding funds you do not own, proving that a stranger is who they claim to be, and being able to answer, months later, exactly who agreed to what.

Two customers who want opposite things

Brands want the work cheap, fast, and exclusive. Creators want to be paid promptly and keep reusing their own portfolio. Your platform sets where that line falls, and it has to be visible to both sides in the same words before either commits.

The licence is the product

What a brand actually buys is permission: to run this video, on these channels, for this long, exclusively or not. If that is not a record in your database with a date on it, you have sold a file and hoped.

You are holding somebody else’s money

Between "brand funds the campaign" and "creator withdraws" sits a balance that belongs to neither of you yet. A wallet that reconciles, a payout that can be retried without paying twice, and a ledger you can read back in an argument are not nice-to-haves here.

Who runs creator programmes now

66.3%

of respondents “report running programs entirely in-house”, per Influencer Marketing Hub’s 2026 benchmark survey of 600+ marketers, the shift that ends with someone needing a platform of their own.

Influencer Marketing Hub, 2026 (Influencer Marketing Benchmark Report) · checked August 2026

What a marketplace needs

The parts every UGC marketplace is built from

It is worth knowing the pieces before you start, because a marketplace is where most people underestimate how much sits behind the screens. These six are the whole product, and every one of them is something you describe in plain words rather than build.

01

Two front doors and one account system

A brand signing up and a creator signing up want completely different forms, dashboards, and vocabulary, but they share one login system and one set of rules about who may read what. Building them as two separate apps is the mistake that doubles every later change.

02

Campaigns with a budget that runs out

A brief, a rate, a deadline, and a number of slots. The budget is the part people forget: when the last slot is filled the campaign has to stop accepting applications on its own, rather than relying on somebody noticing.

03

Uploads that survive real life

Creators upload video from a phone on hotel wifi. Files are large, connections drop, and the same clip gets submitted twice. Chunked uploads that can resume, a duplicate check, and a preview the brand can watch without downloading a gigabyte.

04

Review, revision, and a decision that sticks

Approve, decline, or ask for a change, with the reason attached, visible to both sides, and kept after the fact. A rejected submission with no recorded reason is how a dispute starts and why it cannot be settled.

05

Licences with dates on them

What the brand may do with the approved video, where, for how long, and whether anyone else may use it too. Issued the moment the work is approved, stored as a record rather than a PDF in someone’s inbox, and revocable if a payment never clears.

06

Wallets, payouts, and a ledger that balances

A balance per creator, a queue of payouts that can be retried without paying anyone twice, and a transaction history detailed enough to answer where a specific $200 went. This is the part that turns a content tool into a marketplace.

Build vs buy

Run the marketplace or pay a percentage to one

The alternatives are not four versions of the same thing. You can rent marketplace software, subscribe to a platform that also takes a cut of what you pay creators, buy credits that get spent as you work, or skip the marketplace idea entirely and just buy the videos. Here is the trade-off, side by side.

Build your own

Your own marketplace is a one-time build that keeps the margin between the brand’s budget and the creator’s fee, and with an AI coding tool writing the plumbing, that build is weeks rather than quarters.

  • Pay to build it once, then only your own infra bills and payment-processor fees: no cut of every campaign going out the door
  • You set the take rate, the payment terms, and the licence wording, instead of inheriting someone else’s
  • Brand and creator relationships are yours, in your database, reachable without an export request
  • Add a workflow your niche needs (whitelisted ad usage, a retainer, a revision limit) without waiting for a vendor roadmap
  • Your own AI on top: moderation, brief writing, duplicate detection, on whichever model you pick
  • Full ownership of the code and data: export anytime, zero lock-in

Rent a platform instead

Sharetribe · Insense · GRIN · Trend

Renting gets you running this month with none of the payment plumbing on your conscience. What it costs is a percentage, a per-transaction fee, or a credit balance, plus a product shaped by what the vendor’s other customers asked for.

  • Live in days: sign up, configure, and start, with nothing to build or host
  • Payment handling, creator onboarding, and the compliance paperwork around payouts come as part of the product
  • Support, onboarding, and someone to call when a payout fails at 6pm on a Friday
  • None of the four price the same way, so comparing them is genuinely hard: per month, per month plus a percentage, per credit consumed, or per video delivered
  • Two of the four charge on top of the subscription: a per-transaction fee, or a percentage of everything you pay creators
  • You inherit the vendor’s data model, so a term your niche cares about is a term you may simply not be able to record
SharetribeBuild $39/mo (test only, no live marketplace) - live plans $99/mo (Lite), $199/mo (Pro), $299/mo (Extend), all billed yearly

The closest thing to renting what this guide builds. Those three live figures are the yearly-billing rates the page shows by default. Paying month to month costs more, and the toggle that reveals by how much did not render for us, so treat them as the floor rather than the price. Live plans include 50, 250, or 500 free transactions per month, then “additional transactions $0.19 or less per initiated transaction”. The page is candid about what sits outside the subscription: payment processing, maps, analytics, custom development, and hosting for your custom code at roughly $19/mo. Lite runs on a mysharetribe.com address, so a marketplace on its own domain starts at Pro, and changing how the marketplace itself behaves needs the top tier.

sharetribe.com · checked August 2026

Insense$500/mo (Brand, monthly) or $400/mo billed annually - Agency $800/mo, plus a 7-20% marketplace fee

The subscription is not the whole price. Every tier charges a marketplace fee against creator spend (20% on the one-month trial, 10% on Brand, 7% on Agency) and states plainly that “Creator payments are not covered and must be budgeted separately”. So the bill is a fixed monthly figure plus a percentage of the exact thing your marketplace would be earning its own margin on. The $650/mo trial rolls into Brand automatically unless cancelled 48 hours ahead.

insense.pro · checked August 2026

GRINFree (200 credits/mo) - then $200, $500, $1,000, or $1,500/mo by credit bundle

Priced by credits consumed rather than by seat, with month-to-month billing and no quote-only enterprise tier on the page. Credits reset monthly and do not roll over. Overage is capped by you rather than by them: “If you go over your monthly credits, Gia keeps running at one flat rate, the same on every paid plan. You set a hard cap, and you are never billed a dollar above it.” The free tier stops rather than bills: “Free never has overage; it simply pauses billable actions until your next cycle.” Worth re-checking before you budget: this pricing model is new, and a vendor that just rebuilt one is likely to move it again.

grin.co · checked August 2026

TrendNo subscription - credit packs from $550 (up to 6 videos) to $3,872 (up to 56)

The row that represents not building a marketplace at all. You buy credits at “$9.16 each”, spend them on finished videos, and the packs include “100% licensing & distribution rights to use on social, websites, ads, & more”. No contract and no monthly fee, but “Credits expire 12 months after purchase”, and you end up with content rather than a creator roster, a licence archive, or any relationship you can go back to. For a brand that just wants video, this is the honest answer. For anyone whose business is the platform, it is not the same product.

trend.io · checked August 2026

Rule of thumb: if the marketplace is your business (you take a margin, you own the relationships, you want your own licence terms), the rented options are a tax on the exact revenue you are trying to build, and owning the platform pays back fast. If you are a brand that simply needs a steady supply of video, buy the videos and skip all of this. The genuinely awkward middle is an agency running creator campaigns for clients on a subscription plus a percentage, because that percentage scales with the part of the business you are already doing yourself.

No dev needed

Why build with Codex

Most software looks simple from the outside, but almost all of the actual work is invisible: a database, logins, permission checks, forms that validate what people type, and dozens of screens that read and write records. Doing that by hand means knowing the whole stack cold, so weeks pass before the first feature a customer would notice actually works.

Codex closes that gap by working the way a developer would, just faster. The whole workflow becomes a simple loop:

The build loop
1

Describe

Tell Codex what you want, in plain language.

2

Build

It edits the real project files, backend and auth and UI, rather than replying in a chat.

3

Check

Run the app yourself and confirm the change works.

Repeat

Describe the next change.

Loop back to Describe

None of that loop needs a computer-science background, which is why one person can take an idea to a working app over a handful of focused sessions.

Three hard partshandled for you

The data model, authentication, and access rules are the pieces that make software like this genuinely hard to build alone. Describe them and Codex scaffolds all three, leaving mostly screens to build on top.

Any language is the interface

There’s no code to write, and no requirement to describe it in English. Ask for a new field, a renamed step, or an AI summary in whatever language you think in, and Codex implements it.

Local files it edits directly

Codex works on the project on your own disk rather than a copy somewhere else, so what it changes is exactly what you see when you run the app. Point it at the handful of files that matter and it stays fast and focused.

What it costs

Pay a developer, or do it with AI

Two numbers decide this, and only one of them is the build. One is who writes the platform, a one-time cost you can pay in money or in your own hours. The other is the per-transaction fees that start the day money begins moving through it. The first is compared below. The second is the same either way.

Hire a developer

Custom build, from scratch
Developer
~$16k-$65k
Supabase (backend)
Free tier · $25/mo (Pro plan)*
Hosting
$0 free tier
Build time
~325 hrs of their work

~$16k-$65k to build, then from $25/mo after launch

The spread comes from who you hire, not from how much there is to do: our ~325-hour estimate priced across the bands in the rate survey below. It puts North American contractors at $45-$75/hr and senior US developers at $100-$150+/hr, and notes agencies adding 20-40% on top, which works out at roughly $50/hr for the cheapest credible option and around $200/hr for an agency putting a senior on it. Every hour of that is spent before a single brand has posted a campaign. What continues afterwards is small by comparison: the database, the host, and the per-transaction fees your payment provider charges.

Build it with Codex

From scratch, with Codex
Codex
~$20/month (Plus) to ~$200/month (Pro)
Backend (Supabase)
Free tier · $25/month (Pro plan)*
Hosting
$0 on a free tier
Your time
~155 hrs

~$20-$200/month while you build, then whichever plan you keep using

Codex itself is free to install. The cost sits in the ChatGPT plan behind it, or in API usage if you sign in with a key instead. Plus, around $20/month, covers a template import or a short build. A from-scratch build that runs for weeks usually needs Pro’s top usage-multiplier tier instead, which lands around $100 to $200 a month. The fee doesn’t shrink when you start from a template the way a per-hour developer bill would: the template changes how many of the hours in the estimator above you actually spend, not which ChatGPT plan you’re paying for.

* Read the storage line before you pick a plan, because this template stores video. The free Supabase tier includes 1 GB of file storage, 500 MB of database, and 5 GB of egress, and pauses a project after 1 week of inactivity. A handful of creator uploads and you are out. Pro, from $25/mo, moves that to 100 GB of storage and 250 GB of egress with daily backups kept for 7 days, and charges $0.0213 per GB of storage and $0.09 per GB of egress beyond it. Payouts and identity checks are billed per use by whoever you route them through, and are the two lines that grow with the marketplace rather than sitting flat.

Both columns end with the platform belonging to you, and with the hundredth brand costing no more to serve than the first. The only thing that differs is whose hours go into it: a developer you pay up front, or your own, spent describing what you want and reading back what arrives.

Prices and rates from supabase.com, developex.com and learn.chatgpt.com, checked August 2026.

Plan first

Decide before you build

These six are business decisions rather than technical ones, and every one of them is cheap now and expensive once campaigns are running under the old answer. Write your answers down before the first prompt.

01

How you make money

A percentage of each campaign, a flat listing fee from brands, a subscription from either side, or a mix. It decides whether money passes through your platform at all: a take rate means you hold funds and pay them out, a listing fee means brands pay creators directly. The second is dramatically less to build.

02

What a licence actually grants

Write the default terms in plain sentences first: which channels, how long, whether the brand gets exclusivity, whether the creator may keep it in a portfolio, and what happens if a payment is reversed. Each is a column, and adding them later reopens campaigns already agreed under vaguer terms.

03

When money is released

On approval, on a timer after approval, or on a schedule you run twice a month. This is the most-argued-about part of any creator platform, so pick a rule you can state on the sign-up page. It also decides whether you need a holding balance or just a payout queue.

04

Who you check, and when

Verifying identity costs money per check and adds friction exactly when a creator is deciding whether you are worth the trouble. The common answer is to check nobody at sign-up and require it before the first withdrawal. The two flows differ, so pick one now.

05

How a disagreement ends

A brand rejects a submission the creator thinks is fine. Who decides, on what evidence, within how long, and is the outcome all-or-nothing or a partial payment? Marketplaces that leave this to email end up inventing it per case, which is slower and less defensible.

06

What you keep, and for how long

Rejected videos, expired licences, verification documents, and the accounts of creators who leave. Verification data especially is the kind to hold for as short a time as your obligations allow. Pick a retention period per category and build the deletion.

Approaches

Comparing your build options

The starting point decides how much of the estimate disappears into plumbing rather than into the parts a brand logs in to use. Below is one marketplace built three ways: entirely by hand, on a UI kit that leaves everything behind the screens to you, or with Codex working task by task on the real source.

~325 hrsBuilding by hand

Three products in a trench coat (a brand side, a creator side, and the admin console that referees them) plus the parts a marketplace cannot skip: holding money, proving who someone is, storing video, and recording who owns what once it is delivered.

~240 hrsGeneric UI starter kit

Dashboards, tables, and an upload widget, none of which know what a campaign is. Nothing in a starter kit tracks a licence, splits a payout, or stops a creator reading another creator’s earnings, and those are the parts that take the time.

~155 hrsBuilt with Codex

Hand Codex one task at a time and it edits the real files (migrations, policies, payout functions) from the terminal, an editor extension, or a cloud run you check back on later. The same task list, worked as diffs you approve.

Interactive calculator

Estimate your exact build timeframe

Not every marketplace needs all of this on day one. Plenty launch with campaigns, uploads, and manual bank transfers, then add wallets and identity checks once real money is moving. Untick what you are deferring and the estimate follows.

What your creator marketplace needs

Your estimate

155 hrs

start to finish

Based on the 7 of 7 features you’ve selected, plus ~39h of groundwork. Toggle any on the left to watch the number move, and open the groundwork row to untick what you have already, such as a database that is already running or going live if you are only building a mock-up for now.

A rough estimate, not a quote. Real time depends on how much you customize and how clean your data is.

Setting up your workspace

Let’s set up the tools you need

Before step 01, four things go on your computer. It takes about 15 minutes in total, and none of it is coding. Three are ordinary installers, and the fourth is a ChatGPT plan with Codex access switched on. After that, you build by describing what you want in plain language.

1

OpenAI Codex

Cost: Free to install · needs a paid plan to build with

Your main AI assistant. The app itself costs nothing and installs with a single command from OpenAI, then runs in your Terminal. What it costs to use is the next card: every request spends the usage allowance on your ChatGPT plan, and the free plan’s allowance is small enough that a build of this size stops early. Codex is also built into an extension for popular code editors and into the ChatGPT desktop app, which can hand a longer task off to Codex cloud to keep running in an isolated environment while you do something else.

Install Codex CLI
2

ChatGPT plan

Cost: ~$20/month (Plus) or from ~$100/month (Pro)

Codex is technically included on the free ChatGPT plan too, but Free’s usage is the tightest of any tier. OpenAI doesn’t publish Free’s own cap, only that every paid tier gets a larger multiple of it, so treat Free as a way to try Codex rather than to build with it. ChatGPT Plus, around $20/month, is the realistic starting point, and a long, from-scratch build tends to need the top ChatGPT Pro tier, priced by usage multiplier at roughly $100 to $200/month. Codex can also run on pay-as-you-go API billing instead of a ChatGPT plan, if you’d rather pay per token than hold a subscription.

Compare ChatGPT plans
3

Node.js engine

Cost: Free

The engine that runs your app on your own computer. You never have to learn how it works: download the version marked LTS (the most stable one), install it, and forget about it.

Download Node.js (LTS)
4

Supabase (database)

Cost: Free to start

Where your project keeps its data. Install it, then sign in once by running supabase login. Words like migrations and row-level security turn up later in the guide, and Codex writes those parts for you.

Install Supabase CLI

Nothing here is worth memorizing. These four just need to exist on your machine. From step 01 on, you say what you want and Codex runs the commands.

Step by step

Build your marketplace core, one Codex task at a time

Nothing here asks you to write code. You describe a task and Codex writes the files and runs the commands. The order is deliberate: the project, then the shared data model, then the permission model, then the screens, then the money that depends on all of it. Give Codex one task, read the diff, then start the next.

  1. 01

    Write AGENTS.md before anything is scaffolded

    Codex reads AGENTS.md at the start of every task, so writing it first means your vocabulary is loaded before there is any code to be inconsistent with. A marketplace has two sets of nouns, which makes this worth more here than usual.

    PromptSet up the project
    Start by writing an AGENTS.md at the project root: the stack is React 18, Vite, TypeScript, Tailwind, and the Supabase JS client, and this project is a two-sided UGC marketplace. Fix the vocabulary in it (brands, campaigns, applications, submissions, licences, wallets, payouts) and note the rule that money only ever moves in server-side functions, never from the browser. You load that file automatically at the start of every later task, so nothing in it needs repeating by hand. Then scaffold the project itself: a typed Supabase client under src/lib reading VITE_SUPABASE_URL and the publishable key (the sb_publishable_… key that replaced the older anon key) from .env, with .env confirmed present in .gitignore. Start the dev server once to prove it boots before you stop.

    Putting the money rule in AGENTS.md rather than in one prompt is what keeps task five from cheerfully writing a balance update straight from a component.

  2. 02

    Get the campaign, submission, and ledger shapes right in one task

    Have Codex write the migrations for both sides and the money at once, and ask to see the SQL before it runs. A wallet retrofitted later is the expensive version of this.

    PromptDesign the marketplace data model
    Write the Supabase migrations for the core of a two-sided UGC marketplace. Brands are the buying side, creator_profiles the selling side, each keyed to an account. Campaigns carry a title, brief, deliverable format, rate per accepted submission, slot count, deadline, and a status through draft, active, paused, completed, cancelled, with the funded budget tracked separately from the rate. Applications join a creator to a campaign and carry their own status. Submissions join an application to an uploaded file and move through draft, submitted, under review, approved, rejected, revision requested. Licences are written on approval and record the channels, the term, whether it is exclusive, and when it was granted. For the money: creator_wallets holds a balance per creator and transactions holds every credit and debit as its own row, so a balance is the sum of its history rather than a figure anybody overwrites. Print the SQL for me before it runs, and regenerate the TypeScript types once it is applied.

    Ask for the ledger in this task, not a later one. Adding transactions after the fact means backfilling history for balances that were only ever a number.

  3. 03

    Narrow permissions, then build the two sign-up paths

    This task touches authentication, which is exactly the kind of change worth scoping Codex down for rather than leaving the wider settings you would use for routine edits.

    PromptAdd auth and the three roles
    This task touches authentication, so narrow your permissions to just this one rather than keeping whatever you had set for routine edits. Wire in Supabase Auth for email-and-password sign-up, login, logout, a persisted session, a profiles row per account, and a useUser hook. Then the role model: an app_role enum of 'creator', 'brand_manager', and 'admin', with a user_roles table linking a user_id to a role, kept in its own table rather than on the account, since anything stored on the account is editable by the person it belongs to, plus a SECURITY DEFINER function has_role(_user_id uuid, _role app_role) that reads it without recursing. Then fork onboarding: a creator completes a creator profile, a brand creates or joins a brand record, and each lands on their own dashboard. One migration, and walk me through the diff before it runs.

    Two sign-up paths, one account system. Building them as two separate apps is the decision that doubles every change you make afterwards.

  4. 04

    Read this diff properly: it is the one holding two sides apart

    Row-level security across every table, matching rules on the uploaded video, and a client that cannot touch a balance at all. Of every diff in this build, this is the one to actually read rather than approve on trust.

    PromptAdd row-level security and storage rules
    Turn on row-level security across brands, creator_profiles, campaigns, applications, submissions, licences, creator_wallets, and transactions. An admin reaches every row. A brand manager reaches their own brand, its campaigns, and the applications and submissions attached to them. A creator reaches only their own profile, applications, submissions, wallet, and transactions, and can read an active campaign without seeing who else applied to it. Give every insert and update its own WITH CHECK clause. Then close the money path from the client side entirely: creator_wallets and transactions get select and insert policies at most, with no client-side update or delete, because a balance may only change inside a server-side function. Carry the same thinking into Storage: the submissions bucket must not be public, and a file must be readable only by the creator who uploaded it, the brand whose campaign it belongs to, and an admin. Once it is applied, walk me through proving all of it: one creator querying another's transactions should come back empty, and a submission URL from an unrelated campaign should refuse to download.

    Table policies, storage policies, and the client's write access to the ledger are three separate things. It is entirely possible to get two right and leave the third open.

  5. 05

    Point Codex at the screens, a few files at a time

    The campaign board, the upload, and the review screen are what both sides judge this on. Codex only needs the files each screen touches, not the whole project.

    PromptBuild the screens
    Now the screens, on top of what is already there. For creators: a board of active campaigns showing the rate and how many slots are left, a campaign page with an apply action, and an upload that sends large video in chunks so a dropped connection resumes instead of restarting, with honest progress while it does. For brands: a form to create and edit a campaign, an applications view for shortlisting and accepting, and a review screen that plays the submission and offers approve, decline, or request a revision with a written reason that both sides keep. Data access stays in typed hooks rather than spread through the components, and no screen should ever surface one creator's application to another.
  6. 06
    Destination

    Make approval move the licence and the money together

    The last piece is the one that makes this a marketplace rather than a file drop. It is also a long, well-scoped task, a reasonable one to hand to a cloud run, provided you read the diff before it merges.

    PromptAdd licences, payouts, and test
    Add the rights and money layer as server-side functions only. Approving a submission must, in one database transaction, grant a licence against that campaign's terms and credit the creator's wallet with the campaign rate. Neither half may land without the other. Add a withdrawal request that queues a payout, and a payout function that is safe to call twice, so a retried request cannot pay anyone a second time. Give the admin side a finance view of what is owed, what has been paid, and what is stuck. Then run the app and take it end to end yourself (post and fund a campaign as a brand, apply and upload as a creator from a second account, request a revision, approve the next attempt, check the licence row and the wallet both moved, and request a withdrawal), then fix whatever does not hold up.
Authentication & security

Keeping two sides apart, and the money straight

A marketplace holds three sensitive things at once: personal data about people who do not work for you, files somebody else owns the rights to, and balances that are not yours. Here is how each stays protected, in simple terms.

Proven logins for both sides

Sign-in comes from a system that has already been attacked for years and held, so you are not writing password handling yourself. Brands and creators use the same one. What differs is the profile behind the account and which half of the product it opens.

Three roles, and the rule each one bends

The template ships three roles: creator, brand manager, and admin. The interesting cases are the ones between them: a brand manager reads submissions to their own campaigns and nobody else’s, a creator reads their own earnings and never another creator’s, and an admin reaching into either of those leaves a trace.

Earnings are the data people forget to protect

It is obvious that a creator must not read another creator’s bank details. It is less obvious, and just as important, that they must not be able to total up another creator’s earnings from a campaign they can both see. Rate agreements between a brand and one creator are private to that pair.

Row-level security across every table

The template ships 180 row-level security policies, more than any other template here, because almost every table has three different right answers depending on who is asking. The database enforces that itself on every read and write, so a screen that forgets to filter still cannot show a brand another brand’s campaign.

Uploaded video needs the same rules as the rows

A submitted video is a file in storage, not a database row. Locking the submissions table down carefully while leaving the bucket readable by anyone holding a link is the version of this that looks finished and is not. Here the file is the actual thing of value, since a leaked link is an unlicensed copy.

Money moves on the server, always

Nothing about a balance, a payout, or a licence grant may be decided by code running in someone’s browser. Those belong in server-side functions the browser can only ask, never instruct. Each one should be safe to call twice, because networks retry and a payout that runs a second time has really paid twice.

Keys, and which ones are allowed out

Only a “publishable” key reaches the app, and it is designed to be seen. The database’s service key, your payment provider’s secret, the identity-check provider, the mail sender, and whichever AI model you use all stay on the server. A marketplace collects more of these than most apps, which is a good reason to route them through one place rather than five.

A ledger with no backup is a ledger you cannot defend

Nothing on the free tier is backed up, so a bad migration during the build takes everything with it. From $25/mo, Supabase Pro keeps a daily backup with 7 days of history behind it. Have that running before the first real balance exists, because “we think you were owed about $400” is not an answer anyone accepts.

PromptCheck who can see what
Review the access rules (row-level security policies) on every table. For each one, tell me in simple terms who can view, add, edit, and delete records, confirm that people can only reach their own data while the right roles can reach more, and flag anything left open that shouldn’t be.

Paste this before launch so Codex checks nobody can see data they shouldn’t.

The one rule that matters: no secret key (database, payments, identity, mail, or AI) ever goes into the app or a public repo. If one does get out, treat it as compromised and rotate it the same day.

Workflow rules

What speeds the build, and what slows it

Speeds the build

  • An AGENTS.md file at your project root: Codex reads it automatically before every task, so you never have to remind it
  • Setting Codex’s permissions once for the session, instead of approving every small edit by hand
  • Handing a long, well-scoped task to Codex cloud, so it keeps working in an isolated environment while you do something else
  • Reviewing a diff in the IDE extension, next to the code it touched, before you keep it

Slows the build

  • Leaving permissions wide open for a sensitive change instead of narrowing them for that one task
  • Skipping the AGENTS.md file, so Codex starts each new task without your conventions loaded
  • Handing Codex cloud a vague, open-ended task, where you can’t steer it mid-run the way you can in a live terminal session
  • Merging a cloud task’s changes back in without reading the diff first
Version control

Git: what it is, and why you need it

Before you build anything, meet the one tool that makes building safe. You need no coding background for it: Git remembers every version of your project, so you can try things, break things, and get back to a working state in seconds.

What Git actually is

Git is a quiet recorder that runs alongside your project. Each time you save your work it keeps a full snapshot, so the entire history of your project lives on your computer, not just whatever the files look like right now.

Why you need it

Codex asks before it edits files or runs commands, unless you widen its permissions for the session. Once you do, Git is what makes that safe: there’s always a working version to return to, so you can hand it a bigger task without the fear of losing what already works.

A commit is a save point

Each commit is a snapshot with a short note, like “added the home page”. Make one after every working step and you can jump back to any of them later.

GitHub’s beginner guide to Git

Undo anything, safely

If a change breaks something, you roll back to the last good commit instead of unpicking it by hand. It’s the safety net that keeps a Codex session low-risk even once you’ve widened its permissions.

GitHub is also where Codex can start from

Git lives on your computer. GitHub is a free, private cloud copy of the same project. Keep it private, and never commit secret keys or passwords. Once your project is pushed there, Codex cloud can pick up a task straight from a GitHub issue or repo, without you opening a terminal at all.

Create a free GitHub account

You rarely type git commands

There’s little to memorize. Ask Codex to “commit this” or “undo the last change” and it runs the git steps for you, inside whatever permission boundary you’ve set. Prefer clicking to typing? The Codex extension for your editor shows each change next to the code it touched before you keep it, and GitHub Desktop gives you plain buttons for saving and rolling back.

Get Codex
Going live

Where to put the app once it works

The thing you actually deploy is small: a folder of plain files that almost any host will serve. The records, the accounts, and the uploaded video all live in Supabase instead (covered below), which is why the free-tier column here matters far less than the one further down.

HostBest forNotesFree tier
VercelOne-click deploysPoint it at the repository and it publishes itself, with a standard Vite project needing no configuration at all. Read the licence before you settle, though: Hobby is for personal, non-commercial use, and a platform that takes a cut of campaigns is commercial under any reading of that, which puts you on Pro at $20/user/mo.Pro from $20/user/mo (Hobby is non-commercial)
NetlifyDrag-and-drop or GitConnect the repository, or drag the built folder onto the page and be done. The shortest path between “it works locally” and a link you can send a brand this afternoon.Free tier
Cloudflare PagesCheapest at scaleSet it up once and every visitor is served from wherever Cloudflare is closest to them. Worth more attention here than on most projects, because a marketplace playing video previews back moves an order of magnitude more bandwidth than a dashboard does.Generous free tier
GitHub PagesFree Git-based hostingServes the site straight out of your GitHub project once one routing setting is in place. The catch: serving from a private repository is a paid GitHub feature, and code that decides who gets paid what does not belong in a public one, so count this as free only if you are genuinely happy to publish the source.Free from a public repo only
Firebase HostingTeams already on GoogleOne configuration step, and after that each release is a single command. Chiefly a fit when Google is already the tooling your team knows and adding a new vendor would need explaining.Free Spark tier
AWS Amplify HostingTeams already on AWSSet up from the AWS console with a single rewrite rule so deep links resolve. Mainly a fit when AWS is already the account your billing goes through.Free tier (build + hosting)
SurgePublish from the terminalA single command puts the built folder online, with no repository involved anywhere. Useful for putting a half-finished campaign board in front of a friendly brand for an opinion.Free - unlimited publishing
DigitalOcean App PlatformDigitalOcean usersHand it the project and it handles the build and the serving, next to whatever else you already have running in that account.Free - 3 static sites, 1 GB/mo transfer

All of them will serve this app, and the front end is the cheap half whichever you pick. What is worth checking before you commit: whether the plan you are on allows commercial use at all, since Vercel’s Hobby tier says plainly that it does not, and what happens to your bill once creators are uploading video and brands are streaming it back.

Database & backend

Keep your data in Supabase

Postgres for the records, auth for both sides, storage for uploaded video, and edge functions for anything touching money or a key. Whichever host serves the frontend above, all four run here.

ServiceBest forNotesFree tier
SupabaseData, auth, video, functionsPostgres database, authentication, file storage for submissions, and edge functions for payouts, licence grants, and moderation. Create a free project and your AI coding tool connects the app to it, then watch the storage line, because 1 GB does not go far in video.Free tier, then usage-based
AI workflows

Where AI genuinely helps a marketplace

Once the core runs, each of the four below is one more prompt. They share one server-side function rather than each wiring up its own, which is also what keeps your key out of the browser.

A first pass over everything uploaded

Every submission gets looked at before a human sees it, flagging the obvious problems: the wrong product, no product at all, unusable audio, something that should never have been uploaded. It sorts the queue rather than making the decision.

PromptA first pass over everything uploaded
Add a server-side function that runs on every new submission, sends the video’s frames and transcript to your ai function, and returns a moderation verdict with a confidence score and a short reason. Store it against the submission, sort the review queue by it, and never auto-reject on it alone. Anything flagged goes to a person with the reason attached.

Turning a rough brief into a usable one

Brands write briefs badly, and a vague brief guarantees submissions nobody can approve. This drafts a structured version from whatever they typed, which they then edit.

PromptTurning a rough brief into a usable one
Add a “Improve this brief” action on the campaign form that sends the brand’s draft to your ai function and returns a structured brief (what to show, what to say, what to avoid, deliverable format and length, and the usage rights being asked for), presented as an editable draft the brand confirms rather than something saved automatically.

Matching creators to a campaign

Ranks the creators who applied against what the brief actually asks for, using their past accepted work on your platform, so a brand with 80 applications has somewhere sensible to start.

PromptMatching creators to a campaign
Add a “Suggest a shortlist” action on the applications view that sends the campaign brief and each applicant’s profile and past accepted submissions to your ai function, and returns a ranked shortlist with one line of reasoning per creator. Show it as a suggested order the brand can ignore, and never hide unranked applicants.

Feedback a creator can actually act on

Turns a brand’s two-word rejection into specific, revisable notes. Fewer disputes start when the reason for a decline is concrete rather than “not what we wanted”.

PromptFeedback a creator can actually act on
When a brand requests a revision, add an action that sends the brief, the submission, and the brand’s note to your ai function and returns a clearer version of that feedback: specific, tied to the brief, and phrased as changes to make. Show it to the brand for approval before it reaches the creator, and keep both versions on the record.

Each prompt above should pick whichever model tier fits the job: a fast, lower-cost model for high-volume work, and a stronger reasoning model for anything that weighs tradeoffs against each other. Codex’s model names change faster than this page does, so check OpenAI’s current model line-up (linked in the references below) before you build, rather than copying a name you saw once. Keep all of it behind that same ai function, so one key and one rule set covers every feature you add.

Ready-made option

Get a head start with our template

All of the above is written for someone starting with nothing, which you do not have to be. This same marketplace already exists as working code, and starting there turns most of that estimate into one afternoon spent setting a take rate and rewriting the licence terms in your own words.

UGC Marketplace

The exact creator marketplace this guide builds, packaged so you can open it, point it at your own backend, and make it yours from there. A marketplace that connects brands with creators and handles the messy parts in between. Brands post campaigns and review what comes in, creators apply and upload, and the platform takes care of licensing, payouts, identity checks, and disputes.

React 18ViteTypeScriptTailwind CSSSupabase
Out of the box

The key benefits of starting with a template

The parts nobody enjoys building are already done and running: the three-sided permission model, wallets and payouts, licence records, chunked video upload, moderation, and the admin console over all of it. That leaves your time for the terms and the take rate that make it your marketplace.

Building the core from scratch

~155 hrs

Opening the template, already built

~1 hr

~154 hrs of building you skip

The two figures measure deliberately different things. ~155 hrs is what it costs to build the core yourself. ~1 hr is how long it takes to open the finished one and aim it at your own database. Everything after that (your niche, your licence wording, your payout rule) costs the same from either starting point, so neither column claims it.

All three sides working from day one

Open a functional platform, not an empty folder. Brand onboarding, campaign creation, creator applications, uploads, review, licences, wallets, and a full admin console are ready to use.

Pre-configured access rules

Three roles and 180 row-level security policies work out of the box, so a brand reaches its own campaigns, a creator reaches their own earnings, and neither can see anything belonging to the other side.

The awkward machinery already built

Chunked uploads that resume, duplicate detection on submitted files, a payout queue with retries, licence records with an audit trail, and a moderation pipeline. Each one is a week you are not spending.

Clean structure your AI can safely customize

Typed end to end, grouped by feature, and commented where it matters. That pays off every time you ask for a change afterwards: a tool with an obvious pattern to copy produces work that fits, rather than a second way of doing the same thing.

Customer story

From founders who build on our templates

As an agency we live or die by clean handoffs. The code is structured well enough that we restyle, wire in the client’s data, and ship - no untangling someone else’s mess.
Matt GrahamMatt GrahamFounder & CEO, RapidDev
Got questions?

Common questions

No. Say what you need in ordinary language and your AI coding tool writes all of it: the tables, the rules about who may read which row, the rules covering uploaded video, and the server-side functions that move money and grant licences. Your part is creating a free Supabase project for it to point at, so that everything it writes lands somewhere you own rather than somewhere you rent.

You handle the record of it. A payment provider handles the movement. Your platform tracks what each campaign has funded, what each creator has earned, and what has been paid out, then asks a provider such as Stripe to make the transfer. That provider takes on the regulated parts (card processing, bank details, payout compliance) and charges per use rather than per month. Stripe’s Connect pricing publishes $2 per monthly active account and 0.25% + 25¢ per payout sent.

Before money leaves your platform, in practice yes, both because your payment provider will require it and because it is the cheapest fraud control you will ever add. It is a per-check cost rather than a build: Stripe Identity publishes $1.50 per document-and-selfie verification and 50¢ per ID number lookup, with the first 50 verifications free. Most marketplaces ask for it at first withdrawal rather than at sign-up, so it lands after someone has a reason to bother.

More than the free tier holds, sooner than you expect. Supabase’s free plan includes 1 GB of file storage and 5 GB of egress a month, which a handful of creator uploads will use. The Pro plan at $25/mo includes 100 GB of storage and 250 GB of egress, then charges $0.0213 per GB and $0.09 per GB beyond that. Plan for the egress as much as the storage: every brand watching a submission back is bandwidth.

Yes, and there are four worth having. Most marketplaces start with an automated first look at every upload, then add brief improvement, creator shortlisting, and clearer revision feedback. All four run through one small server-side function. Choose the model tier that suits each job, and the provider key stays on the server rather than anywhere the app can reach it.

No, and the guide is written so it cannot. Every AI feature here sorts, drafts, or summarises for a person who then decides. Nothing rejects a submission or releases a payment on its own. Keep the decision, and the record of who made it, with a human, because that record is what settles a dispute later.

The database, on every single query. Row-level security means each row carries the rule about who may read it, so a creator asking for the wallet table gets their own rows and nothing else, even if a screen forgets to filter. The same applies between brands: a campaign belongs to one brand, and the others cannot see it exists.

Whatever your licence terms say, which is exactly why they are a decision to make before you build rather than wording to add later. The template records a licence per approved submission (what the brand may do, for how long, and whether anyone else may use it too) along with when it was granted. That record is the thing you point at if either side later disagrees.

Nothing here is proprietary, so nothing can lock you in. Underneath it is plain PostgreSQL: a standard dump hands you every campaign, submission, licence, and transaction in a form any Postgres host will accept, and the uploaded files come out of storage the same way. Worth knowing for a second reason on this template: a creator asking you to delete their data is far easier to answer when you can see exactly where all of it sits.

Yes, and on this template it is worth doing early. Every host listed here connects a custom domain with free HTTPS in a few clicks, and a platform asking two strangers to trust it with a payment has a harder time of that from a subdomain belonging to somebody else.

No, though you will type the occasional command: installing Codex, starting the app, applying a database change. The setup section above lists what you need, with a link for each, and once it’s on your machine Codex runs most of those commands for you.

A regular ChatGPT chat can sketch ideas and write snippets, but it isn’t working on your actual project. Codex reads and edits the real files on your computer. The app you get out of it is one you can run and publish, not a preview.

On a ChatGPT plan, Codex’s usage resets on a rolling window rather than billing per token, so a heavy day of building can bump into a limit. You either wait for it to reset, move up a plan, or switch to pay-as-you-go API billing for the rest of the session. Nothing you’ve already built is lost either way, so the work only pauses.

References

Sources checked August 2026
  1. 01Influencer Marketing Benchmark Report 2026 (in-house programme share). influencermarketinghub.com
  2. 02Pricing, Sharetribe. sharetribe.com
  3. 03Pricing, Insense. insense.pro
  4. 04Pricing, GRIN. grin.co
  5. 05Pricing, Trend. trend.io
  6. 06Connect pricing (active accounts, payout fees), Stripe. stripe.com
  7. 07Identity verification pricing, Stripe. stripe.com
  8. 08Pricing (Pro plan, storage, egress, backups), Supabase. supabase.com
  9. 09Pricing (transactional email), Resend. resend.com
  10. 10Web developer hourly rates 2026 (freelance and agency benchmarks). developex.com
  11. 11Row Level Security, Supabase docs. supabase.com
  12. 12Storage access control, Supabase docs. supabase.com
  13. 13Pricing (plans, usage limits), ChatGPT docs. learn.chatgpt.com
  14. 14Codex CLI, ChatGPT docs. learn.chatgpt.com
  15. 15API pricing (models), OpenAI for developers. developers.openai.com
  16. 16IDE extension, ChatGPT docs. learn.chatgpt.com
  17. 17ChatGPT desktop app, ChatGPT docs. learn.chatgpt.com
  18. 18Codex cloud, ChatGPT docs. learn.chatgpt.com
  19. 19AGENTS.md, ChatGPT docs. learn.chatgpt.com

This guide is general information, and not legal, tax, or financial advice. Holding funds on behalf of others, verifying identity, licensing content, and paying creators across borders are regulated differently depending on where you and your users are, so take proper advice before you take a payment. Third-party prices, plan limits, and market rates are quoted from the sources above and were last checked on the date shown. Vendors change them without notice, so confirm before you budget. Build hours and the cost estimates derived from them are our own estimates, not quotes. Codex, ChatGPT, and the OpenAI API are products of OpenAI. Verify current capabilities and pricing before relying on them.