Developer disappeared with the code? What to do, step by step
5 min read
On this page
A developer who stops replying is stressful, especially when they hold the only copy of the code. Before you worry about the code, though, make sure you control the accounts your business runs on: the domain, the hosting, the database and the payment provider. Those are what keep a live product online, and many people find they control more than they feared. Work through the steps below in order.
Step 1: Map what you control today
Make a simple list with one row per service and three columns: whose account is it, whose card pays for it, and can you log in right now. Typical rows are the domain, DNS, hosting, code repository, database, email, payments, app store accounts and any paid APIs such as maps, email sending or AI.
The domain
Look your domain up with ICANN's lookup tool (lookup.icann.org) to see which registrar holds it and when it expires. Personal details are often hidden for privacy, so the result may not show whose name it is in. If you do not have a login at that registrar, contact their support with proof that the domain is yours, such as invoices and business records. Note the expiry date: an expired domain can be lost, so renewal comes first.
Hosting and database
If the hosting or database is billed to the developer's card, it may stop when they stop paying. Platforms such as Vercel, Netlify, Supabase and Firebase allow projects to be transferred between accounts, but usually only the current owner can start the transfer. If you can log in to the account, download a database backup today, before anything else.
The code repository
On GitHub and similar services, a repository in the developer's personal account is theirs to control; you can only see it if they invited you. A repository in an organisation you own is different: you can remove their access and keep working. If you have no access, search for any copy you may already hold, such as zip files sent by email, a staging server, or files in a hosting dashboard you can log in to. The code running in a browser is compiled, so it is not a replacement for the source, though it can help a developer rebuild missing parts.
App stores and payments
If your mobile app was published under the developer's Apple or Google developer account, moving it to yours requires their cooperation through each store's app transfer process. For payments, check whose Stripe or PayPal account receives the money and remove any developer users from accounts that belong to you.
Step 2: Lock down everything you do control
Once you know what is yours, close the doors behind the developer:
- Remove their user from every account you own: code host, hosting, database, payments, email, CMS admin and analytics.
- Rotate keys: database passwords, service keys, payment API keys, email sending keys, AI API keys and OAuth client secrets.
- Turn on two-factor authentication and check the recovery email and phone number on your registrar and main email account.
- Look for things you did not set up: unknown admin users, deploy keys, SSH keys and webhooks pointing to servers you do not recognise.
Rotate in a safe order: create the new key, update the app to use it, confirm it works, then revoke the old one. That avoids taking your own product offline. Paste config files and code you have into the Secret Leak Scanner to list keys that may be exposed. The guide Developer disappeared: secure your code, domain, hosting and accounts today goes through each service in detail.
Step 3: Ask for what you need, in writing
Send one calm, factual message by email. List exactly what you need: transfer of the repository, the domain and the hosting, plus any notes or documentation. Give a reasonable date, and offer to settle any invoice that is fairly owed. Keep a copy.
Silence is not always bad faith. Illness, burnout and family emergencies are common reasons people vanish from a project, and a clear request with no accusations is often the one that gets answered. If you agree a handover, the Handover Checklist Generator gives you a list to work through together.
What you own depends on your agreement
Who owns the code is a legal question, and the answer depends on your contract and your country. In many places, the person who writes code owns the copyright unless there is a written agreement transferring it, or unless they were your employee. Gather what you have: the contract or proposal, invoices, payment records and any messages that mention ownership or handover.
Before threatening action, or before asking a new developer to build on code whose ownership is unclear, speak to a lawyer where you are based. This page is general information, not legal advice. Also avoid naming or accusing the developer in public posts; it can create legal risk for you and rarely gets the code back.
If the code cannot be recovered
You still have options. If you own the database, your data, which is often the most valuable part, is safe. The live product, your screenshots and your own knowledge of how it should work are a solid specification for rebuilding. A developer can tell you whether partial recovery or a fresh build is more realistic; finishing a half-built app explains how to weigh that up.
What a rescue developer checks first in this situation
A developer stepping in after someone vanished pays special attention to what left with that person. They will usually:
- Confirm which accounts you now control and which still need transferring.
- Check whether the code you have matches what is running in production.
- Search the git history for keys that were committed at any point.
- Look for settings that were never written down, such as environment variables, scheduled jobs and third-party configurations.
- Confirm that database backups exist and can actually be restored.
If you have a public repository, the Repo Health Check gives you and them a quick starting picture.
Post the takeover
When your accounts are secure, post the takeover for free. Describe the product, its stack, what access you have and what is missing. Being honest about the gaps lets developers plan properly. Do not include keys, passwords or the previous developer's name; once you choose someone, give access through invites. This time, agree scope, milestones and code ownership in writing, as covered in paying a developer safely. TakeoverWork connects you with people who take over projects but does not check them or handle payments.
Live matching takeovers
No matching takeovers are open right now
New projects are posted regularly. Browse every open takeover, or post your own project free.
Browse all takeoversFrequently asked questions
Can I get my domain back if the developer registered it in their own name?
Possibly, but it depends on the registrar and on what you can prove. Contact the registrar's support team with invoices, emails and business documents that show the domain was bought for you, and keep an eye on the expiry date in the meantime. If the registrar cannot help, a lawyer can advise on dispute options in your country.
Should I rotate keys even if I think the developer is honest?
Yes. Rotating keys is routine whenever someone with access leaves a project, not an accusation. It also protects you if their laptop or accounts are ever compromised.
Can a new developer work on the code I already have?
In many cases, yes, but whether you have the right to use and change that code depends on your agreement with the original developer and the law where you are. If ownership is unclear, get advice from a lawyer before a new developer builds on it.
Can I name the developer in my takeover listing?
No. TakeoverWork listings describe the situation without blaming anyone. Say that the previous developer is no longer available and what access you have, which is all a new developer needs to know.
What should my next agreement with a developer include?
A written scope, milestones, who owns the code and accounts, how access is granted and removed, and what a handover at the end must contain. Put accounts in your own name from the start and invite developers to them.
Stuck with a half-built app?
Post your project free. Developers who finish and rescue projects can send you an interest note, and you decide who to talk to. You agree scope and payment directly with them.
Free tools that help
Related guides
Developer disappeared: secure your code, domain, hosting and accounts today
A calm, ordered plan for the day your developer goes silent: protect the domain and email first, then hosting, code, data and money accounts.
ReadHow to give a developer access without sharing passwords
Use team invites and limited roles instead of shared passwords, service by service, and know exactly how to remove access and rotate keys when the work ends.
ReadPaying a developer safely: milestones, scope and written agreements
Agree scope in writing, pay per milestone against clear acceptance criteria, keep code ownership explicit and use payment methods that leave a record. Practical steps for project owners.
ReadRelated problems
Agency abandoned your project or closed mid-build? What to do next
When an agency stops work or closes, you need more than the code: accounts, designs, licences and project history. Here is how to collect them and plan the next step.
ReadHow to finish a half-built app without starting over by accident
A practical path for a stalled app: take stock of what works, decide fix or rebuild with clear reasons, define finished, prepare access and post a clear listing.
ReadSecurity issues in AI-generated apps: what to check and how to fix them
AI app builders ship working features fast, but often leave keys in the browser, tables open and API routes unprotected. Here is how to check yours.
Read