Google's own documentation uses the words "vibe code" for AI Studio's Build mode. It also says what happens to your API key when you deploy, and who can see your code when you share. Here's what it builds, and the checks Google's pages leave to you.
People do search for "google vibe coding," and it's a fair question, because Google's tools do this and Google says so in its own documentation. Everything here comes from Google's pages, read on 3 October 2026, and where those pages are silent, this page says so.
What Build mode makes
Google's Build docs open by saying the page describes how to use AI Studio "to quickly build (or 'vibe code') and deploy apps." They add that AI Studio "supports building web apps with full-stack runtimes and native Android apps with Kotlin and Jetpack Compose — all through natural language prompting."
For a web app, that means a React front end by default and, on the server side, "a Node.js runtime that allows for secure API calls, database connections, and npm package usage." You can open the Code tab to see what was generated, keep chatting to change it, sync it to GitHub, or download a ZIP. When you're ready, the docs say to deploy to Cloud Run.
Where Google Antigravity fits
Antigravity is the other Google name you'll see. Google's Developers Blog introduced it on 20 November 2025 as "a development platform that combines a familiar, AI-powered coding experience with a new agent-first interface," which makes it a developer tool, closer in spirit to a coding agent than to a prompt-to-app builder. The two are connected: the AI Studio docs say "The Antigravity Agent is the main AI functionality within Google Antigravity and now the core components of the agent harness is powering the Build mode experience in Google AI Studio." For the difference between builders and codebase tools generally, see Lovable vs Cursor vs Claude Code.
Two lines to read before you share or deploy
Your key powers everyone's calls. Google documents that your Gemini API key is handled as a server-side secret: "Your API key is stored as a server-side secret and is never included in client-side code." That's the right design. The catch is in how deployment works: "When you deploy to Cloud Run from AI Studio, your API key is included securely in the server-side environment. The deployed app will use your API key for all users' Gemini API calls." So visitors can't see your key, but their usage is billed against it. Google says so for sharing too: "API calls count toward your usage limits. If you use paid models, costs may apply," and that AI Studio "will give you a heads-up during setup and before you share if your app could incur costs." The habit this points to is the one in rate limits: decide how much one visitor can use before a stranger or a script does it for you.
Shared users can see your code. Google's FAQ: "By default your app is private." And then: "Users you share your app with can see its code and fork it for their own purposes." So treat anything in the code as readable by whoever you share it with. Google's pages say keys belong in the Secrets panel rather than in code; that's the same rule as keeping secrets out of the browser.
The database check Google's pages don't describe
Build mode can set up a database for you. The full-stack docs say "The Antigravity Agent can provision and set up" a Firestore database and Firebase Authentication, and that if you ask it to "add a database to my app," it "will handle the necessary configuration and code generation for you."
What the pages we read don't say is which access rules it applies to that database. That matters because a database's access rules are what stop one user reading another's data, the same job Row Level Security does in Supabase. Firebase's own docs show an example rule set that gives "read/write access to all users under any conditions," with the warning: "NEVER use this rule set in production; it allows anyone to overwrite your entire database." We're not saying AI Studio sets rules like that, because the pages don't say. We're saying you should open your project's Firestore rules and read them before you share, and ask the agent to explain them if you can't. The full pre-launch list is in the six checks.
What you'll need to get started
Google's own codelab, which builds a small "Snake & Beats" game in Build mode, lists what you need: a Cloud project "with billing enabled," a Gemini API key, a Gmail account and a GitHub account. The docs also note that "Pricing for Google Cloud Run may apply based on usage." None of that is hidden, but it's worth knowing the path from "try a prompt" to "deployed app" involves a billing-enabled Cloud project. The wider map is in everything to check before real people use your app.
Quick answers
Is Google AI Studio vibe coding?
Google's own docs describe Build mode as how to quickly build (or "vibe code") and deploy apps from natural-language prompts. It generates full-stack web apps and native Android apps.
Is my Gemini API key exposed in an AI Studio app?
Google says no: the key is stored as a server-side secret and never included in client-side code. The related thing to know is that a deployed app uses your key for all users' calls, so their usage counts against your limits and costs.
Can people see my app's code if I share it?
Per Google's FAQ, apps are private by default, and users you share an app with can see its code and fork it. Keep secrets in the Secrets panel, not in the code.
What is the difference between AI Studio and Antigravity?
Per Google, Antigravity is a development platform with an AI-powered editor and an agent-first interface, aimed at developers. AI Studio's Build mode is a prompt-to-app experience, and Google's docs say the Antigravity agent harness powers it.
This page has no affiliate links or sponsored placements. All tool descriptions come from Google's own documentation, codelab, developer blog and Firebase docs, read on 3 October 2026; we haven't built an app in AI Studio ourselves, so nothing here describes how it feels to use.