MK Studio
A client portal where briefs, source files, versions and approvals of creative work live in one verifiable trail.
- Role
- Product lead and full-stack builder
- Year
- 2026
- Stack
- TypeScript, Cloudflare Workers, Cloudflare D1, Cloudflare R2 (private), Supabase Auth (MFA), Vite, Vitest, Miniflare, Python ops tooling

The problem
Creative approvals ran over chat and shared drives: clients approved one file and downloaded another, adjustments overwrote reviewed versions, and there was no record of who approved what.
What I built
A single portal for team and clients. The client submits the brief and originals and explicitly confirms the hand-off; the team keeps private production notes separately; each version is published for review, where the client can mark a point on the artwork, request changes or approve. Approval records version, release and SHA-256, and only the exact approved bytes become downloadable.
Highlights
- Immutable review trail: adjustments create new versions and never replace reviewed bytes; approval is bound to a SHA-256 hash, and preview and download serve the same file.
- Server-side authorization per client and project on D1, Supabase used only for identity with MFA required for admins, opaque HttpOnly session cookies, exact-origin and CSRF checks on every mutation.
- Legacy archive imported with provenance: 11 projects from 8 brands, 165 versions and 3,002 piece records, with 1,817 new binaries deduplicated and zero read errors.
