Skip to content
TakeoverWork
Problem

Developer disappeared with the code? What to do, step by step

5 min read

On this page
  1. Step 1: Map what you control today
  2. Step 2: Lock down everything you do control
  3. Step 3: Ask for what you need, in writing
  4. What you own depends on your agreement
  5. If the code cannot be recovered
  6. What a rescue developer checks first in this situation
  7. Post the takeover

A developer who stops replying is stressful, especially when they hold the only copy of the code. Before you worry about the code, though, make sure you control the accounts your business runs on: the domain, the hosting, the database and the payment provider. Those are what keep a live product online, and many people find they control more than they feared. Work through the steps below in order.

Step 1: Map what you control today

Make a simple list with one row per service and three columns: whose account is it, whose card pays for it, and can you log in right now. Typical rows are the domain, DNS, hosting, code repository, database, email, payments, app store accounts and any paid APIs such as maps, email sending or AI.

The domain

Look your domain up with ICANN's lookup tool (lookup.icann.org) to see which registrar holds it and when it expires. Personal details are often hidden for privacy, so the result may not show whose name it is in. If you do not have a login at that registrar, contact their support with proof that the domain is yours, such as invoices and business records. Note the expiry date: an expired domain can be lost, so renewal comes first.

Hosting and database

If the hosting or database is billed to the developer's card, it may stop when they stop paying. Platforms such as Vercel, Netlify, Supabase and Firebase allow projects to be transferred between accounts, but usually only the current owner can start the transfer. If you can log in to the account, download a database backup today, before anything else.

The code repository

On GitHub and similar services, a repository in the developer's personal account is theirs to control; you can only see it if they invited you. A repository in an organisation you own is different: you can remove their access and keep working. If you have no access, search for any copy you may already hold, such as zip files sent by email, a staging server, or files in a hosting dashboard you can log in to. The code running in a browser is compiled, so it is not a replacement for the source, though it can help a developer rebuild missing parts.

App stores and payments

If your mobile app was published under the developer's Apple or Google developer account, moving it to yours requires their cooperation through each store's app transfer process. For payments, check whose Stripe or PayPal account receives the money and remove any developer users from accounts that belong to you.

Step 2: Lock down everything you do control

Once you know what is yours, close the doors behind the developer:

  • Remove their user from every account you own: code host, hosting, database, payments, email, CMS admin and analytics.
  • Rotate keys: database passwords, service keys, payment API keys, email sending keys, AI API keys and OAuth client secrets.
  • Turn on two-factor authentication and check the recovery email and phone number on your registrar and main email account.
  • Look for things you did not set up: unknown admin users, deploy keys, SSH keys and webhooks pointing to servers you do not recognise.

Rotate in a safe order: create the new key, update the app to use it, confirm it works, then revoke the old one. That avoids taking your own product offline. Paste config files and code you have into the Secret Leak Scanner to list keys that may be exposed. The guide Developer disappeared: secure your code, domain, hosting and accounts today goes through each service in detail.

Step 3: Ask for what you need, in writing

Send one calm, factual message by email. List exactly what you need: transfer of the repository, the domain and the hosting, plus any notes or documentation. Give a reasonable date, and offer to settle any invoice that is fairly owed. Keep a copy.

Silence is not always bad faith. Illness, burnout and family emergencies are common reasons people vanish from a project, and a clear request with no accusations is often the one that gets answered. If you agree a handover, the Handover Checklist Generator gives you a list to work through together.

What you own depends on your agreement

Who owns the code is a legal question, and the answer depends on your contract and your country. In many places, the person who writes code owns the copyright unless there is a written agreement transferring it, or unless they were your employee. Gather what you have: the contract or proposal, invoices, payment records and any messages that mention ownership or handover.

Before threatening action, or before asking a new developer to build on code whose ownership is unclear, speak to a lawyer where you are based. This page is general information, not legal advice. Also avoid naming or accusing the developer in public posts; it can create legal risk for you and rarely gets the code back.

If the code cannot be recovered

You still have options. If you own the database, your data, which is often the most valuable part, is safe. The live product, your screenshots and your own knowledge of how it should work are a solid specification for rebuilding. A developer can tell you whether partial recovery or a fresh build is more realistic; finishing a half-built app explains how to weigh that up.

What a rescue developer checks first in this situation

A developer stepping in after someone vanished pays special attention to what left with that person. They will usually:

  1. Confirm which accounts you now control and which still need transferring.
  2. Check whether the code you have matches what is running in production.
  3. Search the git history for keys that were committed at any point.
  4. Look for settings that were never written down, such as environment variables, scheduled jobs and third-party configurations.
  5. Confirm that database backups exist and can actually be restored.

If you have a public repository, the Repo Health Check gives you and them a quick starting picture.

Post the takeover

When your accounts are secure, post the takeover for free. Describe the product, its stack, what access you have and what is missing. Being honest about the gaps lets developers plan properly. Do not include keys, passwords or the previous developer's name; once you choose someone, give access through invites. This time, agree scope, milestones and code ownership in writing, as covered in paying a developer safely. TakeoverWork connects you with people who take over projects but does not check them or handle payments.

Live matching takeovers

No matching takeovers are open right now

New projects are posted regularly. Browse every open takeover, or post your own project free.

Browse all takeovers

Frequently asked questions

Can I get my domain back if the developer registered it in their own name?

Possibly, but it depends on the registrar and on what you can prove. Contact the registrar's support team with invoices, emails and business documents that show the domain was bought for you, and keep an eye on the expiry date in the meantime. If the registrar cannot help, a lawyer can advise on dispute options in your country.

Should I rotate keys even if I think the developer is honest?

Yes. Rotating keys is routine whenever someone with access leaves a project, not an accusation. It also protects you if their laptop or accounts are ever compromised.

Can a new developer work on the code I already have?

In many cases, yes, but whether you have the right to use and change that code depends on your agreement with the original developer and the law where you are. If ownership is unclear, get advice from a lawyer before a new developer builds on it.

Can I name the developer in my takeover listing?

No. TakeoverWork listings describe the situation without blaming anyone. Say that the previous developer is no longer available and what access you have, which is all a new developer needs to know.

What should my next agreement with a developer include?

A written scope, milestones, who owns the code and accounts, how access is granted and removed, and what a handover at the end must contain. Put accounts in your own name from the start and invite developers to them.

Stuck with a half-built app?

Post your project free. Developers who finish and rescue projects can send you an interest note, and you decide who to talk to. You agree scope and payment directly with them.

Free tools that help

Related guides

Related problems