Case Study · Live Product
Social Autopilot
One post, every platform. Social Autopilot lets a person or small team write a single post and publish or schedule it across seven social networks — with multiple accounts per platform, recurring schedules, a content calendar and team workspaces.
The problem
Anyone who posts to more than one network repeats the same work: open each app, re-upload the same video, paste the same caption, and try to remember to post at the right time. Existing schedulers are expensive, lock you into their platform, and rarely support multiple accounts on the same network — which agencies and creators actually need.
The approach
I built a focused, self-hostable product around one clear workflow, then made the unglamorous parts solid enough to trust:
- Write once, publish everywhere — one composer, one caption, per-network previews and caption limits.
- Multiple accounts per platform — connect several accounts on the same network and choose exactly which one each post targets.
- Scheduling & recurring posts — publish now, schedule for later, or repeat daily/weekly; each occurrence is queued automatically.
- Reliability — every platform publishes independently and is claimed atomically, so one failure never blocks the rest and nothing double-posts.
- Content calendar & media library — plan the week and reuse media you already uploaded.
- Drafts, templates & CSV import — save drafts (with local autosave), reuse captions, and bulk-create posts from a spreadsheet.
- Team workspaces — invite teammates who share the owner's accounts and posts without sharing passwords.
How it’s built
A FastAPI service renders the app and exposes a JSON API; PostgreSQL (Supabase) stores users, posts, connections and publishing history; OAuth tokens are encrypted at rest. A scheduler and a database-backed heartbeat both drive the same publishing engine, so jobs survive restarts and run correctly with multiple instances. Object storage holds media, and the whole thing deploys to Vercel.
PostgreSQL & object storage sit behind FastAPI; OAuth tokens are encrypted.
Trust & operations
Because it touches people's social accounts, security and transparency mattered: encrypted tokens, hashed passwords, CSRF protection, two-factor authentication, a session manager, a public status page and daily database backups. The public status page below reports service health in real time.
Documentation & onboarding
A built-in help center and an SEO-ready landing page make the product usable without a manual, and the dashboard guides new users through setup with a progress checklist.
Outcome
- Live, production deployment serving real pages and APIs.
- 360+ automated tests guarding the publishing pipeline, auth and workspaces.
- Seven integrations with independent, retryable publishing.
- A codebase I could refactor (multi-account, workspaces, recurring posts) without breaking — because the tests were there.
What I’d do next
Provider app reviews to unlock public posting on the approval-gated networks, a payment provider for subscriptions, per-post analytics, and a read-only team role.