Case study Swapify
A marketplace where founders trade tools instead of buying them
Founders sit on SaaS coupons, credits, and licence tokens they will never use, while paying full price for the tools someone else is sitting on. Swapify is the exchange for that. which means the hard part is not the listing page, it is releasing a credential to a stranger safely.
Services Full-stack product engineering
Category SaaS · digital marketplace
Client MagicMakers Lab
Stack Next.js 15 · React 19 · NestJS · PostgreSQL · TypeORM
Swapify
The problem
A swap is only as good as the trust behind it.
Peer-to-peer exchange of something as sensitive as a licence key needs more than a form and good intentions.
✓Coupon and licence data is sensitive by default ✓No trust model between two strangers mid-swap ✓A swap has a lifecycle, not a single transaction ✓Public, authenticated, and admin surfaces all need different rules ✓Schema drift between environments breaks marketplaces quietly
What we had to get right
✓Credentials encrypted before they ever touch the database ✓Decryption only for the counterparty, only on a confirmed swap ✓A full request → accept or decline → fulfilment flow with state ✓Reviewable, revertible migrations so environments never drift
Our approach
Encryption module first, marketplace second
A dedicated crypto service in the shared layer encrypts coupon and licence data before storage, and the swap lifecycle decides when. and to whom , it is ever revealed.
✓Public storefront for discovering swappable coupons and licences ✓Authenticated dashboard for managing listings and swaps ✓Administrative surface with its own permissions ✓Full swap lifecycle from request through fulfilment ✓Encryption at the shared layer, not per feature ✓Google sign-in as a first-class path alongside email
Core capabilities
What it does now
A complete marketplace product: three distinct surfaces, one lifecycle.
✓Listing, discovery, and swap requests ✓Encrypted credential storage and conditional release ✓Swap state tracking with accept, decline, and fulfilment ✓Role-separated admin tooling ✓Reproducible environments through reviewed migrations ✓Documented API behind every dashboard interaction