Vercel Support Request — INC-001
- Status:
draft_not_submitted - Prepared for: founder manual submission
- Plan observed: Hobby
- Incident date: 2026-07-17
Draft request
We are requesting clarification about an unexpected Deployment Protection result during a short-lived Preview test.
Before deployment, the project-level UI appeared to show Vercel Authentication enabled with Standard Protection selected. The project appeared to have no Git integration, custom domain, Shareable Link, Deployment Protection Exception, automation bypass, or Production deployment.
One Preview deployment was created with Vercel CLI 56.3.1 without --prod or --public. The CLI reported the deployment as Preview.
In a fresh signed-out private browser session, ordinary browser navigation loaded the application rather than presenting a Vercel login gate. We immediately deleted the deployment and project. The former URL subsequently ceased serving the application.
We retained no URL, project identifier, deployment identifier, organization or account identifier, credential, cookie, bypass value, or screenshot in source control.
Please provide written clarification on these questions:
- Should Vercel Authentication with Standard Protection on Hobby protect the deployment-specific URL class produced by a CLI Preview?
- Do team-wide Deployment Protection defaults apply identically to projects created through the CLI?
- Can protection configuration or enforcement have a propagation interval after project creation or Save?
- Is there any known UI/backend state mismatch that could display protection as enabled while a new Preview remains publicly reachable?
- Which non-sensitive diagnostics should we capture during a future controlled reproduction to prove project scope class, protection persistence, deployment classification, tested URL class, bypass absence, and redirect behavior?
Please confirm the expected safe configuration and evidence before we consider any redeployment.
Submission boundary
This document is a draft only. The founder must review and submit it manually. No support case reference, URL, platform identifier, credential, access material, or private account data belongs in the repository.