VKR.
Senior Software Engineer/Frontend Architecture/Delhi, India

VaibhavKumar Rai

I take frontends that have outgrown their architecture and turn them into systems a whole team can build on.

7+ years building enterprise SaaS and real-time systems. React, Next.js, TypeScript, FastAPI. Design systems, live streaming interfaces (WebSockets, SSE, WebRTC), and workflow authoring engines.

Staff role

How I think5 notes
01

I migrate piece by piece, never in a big bang

Whenever an app outgrows its stack, the hardest part is keeping product velocity alive while changing the engine underneath. I look for the cleanest seams, draw strict TypeScript contracts at the boundaries, and migrate one route or module at a time. Customers keep using the app, and the team never has to pause shipping.

02

Most UI bottlenecks come down to DOM churn

When an app stutters, my first instinct isn't to start wrapping every hook in useCallback. It's almost always because the browser is juggling too many DOM nodes. At Scrut, when 50k security events streamed over WebSockets, we buffered incoming data off-screen and virtualized the table so only visible rows hit the DOM. Keep the DOM small and the tab stays fast.

03

Design systems should live in tokens, not component forks

A good design system should save engineers time, not trap them in review discussions about margins and paddings. I anchor themes and spacing to CSS custom properties at the document root. That way, dark mode, tenant customization, and layout density happen dynamically at runtime without having to touch dozens of component files.

04

When an edge case breaks, I read the framework source

I've never liked fixing weird framework quirks with random setTimeout workarounds or superstitious code. If lifecycle hooks fire out of order or bindings break, I pull down the framework repository and step through the compiler AST. That habit is how I ended up finding and fixing bugs in Svelte core and Qwik.

05

AI agents need scoped permissions, not raw API keys

As autonomous agents become part of developer workflows, handing them master API keys with blanket write access is a huge blind spot. One malformed prompt can delete data or trigger irreversible actions. I built AgentGate because agents need a proxy layer: per-tool permissions, structured audit trails, and an immediate way to cut off access.

Experience7 roles / 2018 to now
2024 — 2026Bangalore

Scrut Automation

Senior Software Engineer

Promoted from SDE II (Jun 2024) to Senior (Apr 2025), same team

  • Led the React frontend and built backend APIs with FastAPI and PostgreSQL for security findings and vulnerability management.
  • Built a visual rule builder for compliance workflows so teams could automate security checks.
  • Streamed live security data over WebSockets and SSE, using virtualized tables to keep the UI fast.
  • Built a shared UI design system and used code splitting to cut initial load time.
  • Set up PostHog tracking and worked with PMs to make incident triage faster.
ReactTypeScriptWebSocketsSSEFastAPIPythonPostgreSQLDesign systemVirtualization
2022 — 2024Bangalore

Kami Vision

Senior Software Engineer

Kami Cloud · B2C
  • Rewrote the Vue app in React and TypeScript, with a shared design system in Storybook.
  • Added live camera feeds with WebRTC, handling video playback and automatic reconnects.
  • Used WebSockets for camera controls and SSE for real-time motion alerts.
  • Integrated Stripe subscriptions with webhook handling, multi-language support, and tests.
Internal Dashboard · B2B
  • Built a Next.js dashboard with a rule builder to set up camera alerts and workflows.
  • Wrote TypeScript transformers to turn messy API responses into clean client models.
  • Created the component library and testing setup used across internal teams.

Vue.js React

ReactWebRTCWebSocketsSSETypeScriptNext.jsStorybookStripe
2022Remote

Milky Way AI

Freelance Software Engineer

  • Built a dashboard that automates stock replenishment and gives retail operations a real-time read on inventory.
2021 — 2022Remote

Quizizz

Freelance Software Engineer

  • Worked the migration off Krafty onto Nuxt and built the complex UI components that came with it.

Krafty Nuxt

Vue.jsNuxt
2019 — 2021Remote

Klinify

Software Engineer

  • Cut dashboard load time by 45% with memoization, API optimizations and code splitting.
  • Built a configurable design system carrying per-clinic branding, themes and layouts, with SSR and SSG for dynamic content.
  • Wrote backend Flask APIs and CouchDB map-reduce transformations to handle clinic workflows and patient records.
ReactFlaskCouchDBPythonSSR / SSGDesign systemi18n
2019Bangalore

Appknox

Software Engineer

  • Built the Ember.js interface for running and managing application security scans, so customers could run several scans in parallel instead of one at a time. Throughput went up, turnaround came down.
  • 25 pull requests merged into appknox/irene, their open source frontend.
Ember.jsAppSecAPIsOpen source
2018 — 2019Bangalore

Squadcast

Software Developer Intern

  • Built a bidirectional sync between Slack and Squadcast chat (Node.js and WebSockets) so incident updates landed in real time on both sides.
  • Wrote Enzyme tests across the frontend, shipped backend serverless Kubeless microservices, and stood up an Artifactory registry for private npm packages.
ReactNode.jsWebSocketsKubelessEnzymeArtifactory
Built on my own timegithub.com/RaiVaibhav

AgentGate

Permission control for AI agents over MCP. It sits between an agent and a server like GitHub, Stripe or Slack, enforces per-tool permissions, scans responses for security problems, logs every decision, and revokes access instantly. The agent never gets the real API key, only a gateway URL.

Give an agent a GitHub token today and it gets everything that token allows. There's no way to say “read repos, never delete them.” This is my answer to that.

TypeScriptMCPAI SecurityAccess ControlAudit Log

Bandhu

A companion-first mental health check-in app for India. The idea is that it should feel like texting a friend, not opening a treatment tool. Built with FastAPI, Postgres/pgvector, React 19, Vite, Tailwind v4 and shadcn/ui, with NVIDIA NIM and Langfuse for tracing.

It's a prototype and I say so in the README. Anything safety-critical—crisis-language detection and clinical suggestions—sits behind an eval pipeline that tests retrieval and prompt outputs before it ships. The engineering docs cover the pipeline design, vector schema, and eval test cases.

React 19FastAPIpgvectorRAGLLM evalsLangfuseTailwind v4

The real app, running here. Try it.

Open source

Svelte & Qwik core

5 pull requests merged into Svelte and one into Qwik: element bindings, a contenteditable regression, beforeUpdate firing twice, onDestroy ordering, each-block bindings with spread syntax. Small fixes, but they meant reading someone else's compiler until the bug made sense.

SvelteQwikCompilers
2017 — 2018

coala, GSoC and Code-in

Google Summer of Code 2018. Wrote a Python tool that drops you straight into an analyzer's code and steps through it with a debugger interface like pdb, so debugging an analyzer got about as easy as writing one.

Google Code-in mentor, two terms, with coala, the open source static analysis org. Also 2 merged fixes into man-group/pytest-plugins and an ESLint plugin of my own for nested-if detection.

PythonStatic analysisMentoring
Toolkit
Frontend
React.js, Next.js, Vue.js, TypeScript, JavaScript, HTML5, CSS3, Tailwind CSS
Real-time & streaming
WebSockets, Server-Sent Events (SSE), WebRTC, live stream buffering, event-driven state
State & data
Zustand, Redux, React Query, REST APIs
Testing
Jest, Cypress, Storybook, Enzyme
Architecture
Enterprise workflow & rule authoring engines, design systems, micro frontends, Nx monorepo, virtualization, SSR/SSG, legacy migrations
Backend
FastAPI, Python, Node.js, PostgreSQL, pgvector, Flask, CouchDB, Swagger
RAG & evals
RAG pipelines, LLM evals, Langfuse, semantic search, prompt engineering, MCP
Tools & ops
Git, CI/CD, Webpack, Vite, Docker, AWS, PostHog, Grafana
Languages
English (full professional), Hindi (full professional)
Education, certificates & current
2015 — 2019
B.Tech, Computer Science and Engineering. Shri Mata Vaishno Devi University, Jammu & Kashmir
Certificates
DeepLearning.AI: Neural Networks and Deep Learning · DeepLearning.AI: Machine Learning · Google: Foundations of Project Management · Google: Project Initiation
Right now
Going deep on agentic AI and RAG, which is where AgentGate and Bandhu came from. What I actually want to know is what these systems need from a frontend, because that answer is still being worked out.
Off the clock
Runner, paragliding pilot, licensed skydiver. I keep a CSS-only art gallery on CodePen, because I'd rather battle CSS than DS Algo.