Avalyz

Articles

How to test a Bolt app before launch

This guide is for people who built a site or app with Bolt (bolt.new) and want to know whether it holds up once strangers use it. The common failures appear after publishing: changes that never went live, a database that behaves differently for real users, sign-in that fails on the live address, a custom domain that is half connected. You will get a step-by-step plan for the published site, an honest view of what Bolt's own tools check, and what an independent, read-only test adds.

It belongs to a series on how to test an app built with AI. A similar routine for another builder is in How to test a Lovable app.

What Bolt is and where your app lives

Bolt describes itself as an AI builder for websites, apps and prototypes, with Bolt Cloud covering hosting, databases, user authentication and custom domains.

According to Bolt's help center, publishing puts the project at a live URL. Every user, Free or Pro, gets a free .bolt.host address, and Bolt assigns a random name on first publish that you can change. Bolt's own hosting is the default, but projects can also be published to Netlify instead: in that case Bolt generates a random netlify.app address on first publish. Custom domains are available to Pro users.

Two facts matter for testing:

What Bolt already gives you

Fair credit first. Bolt documents several checks that you should use:

The documentation does not describe an automated test suite for your finished app, so the verification of the live site is left to you.

Pre-launch test plan for a Bolt app

  1. Publish, then open the published address in a private window. Do not test in the preview.
  2. Confirm nothing is pending: if you edited after publishing, click Update, then test again.
  3. Check the visibility (public or private) matches what you want. Open the site signed out, from another device.
  4. Visit every page and menu item and note blank screens, missing images or console errors. Bolt's help center says missing images are fixed by placing them in the Public folder.
  5. Test on a phone-width screen: navigation, forms, buttons.
  6. Create a new account and confirm the whole sign-up path, including any email.
  7. Sign in, sign out and use a wrong password. Check messages and where you land afterwards.
  8. Sign in as two different users and verify one cannot see the other's data. Open the database Security tab and read what it flags.
  9. Create, edit and delete one record and reload to prove it persists.
  10. Visit a private page while signed out; you should be turned away.
  11. Submit forms with empty, long and odd input; read the errors and check what was stored.
  12. Check the custom domain, if any: it loads over a secure connection, the bare and www versions both work, and it points to the right site.
  13. Check secrets and payment settings: no keys visible in the page, and any payment set up in test mode before real money.
  14. Check text and legal pages: placeholder copy, dead links, privacy page, contact address.
  15. Re-test after each fix, publishing with Update first.

What an independent test adds

Bolt's tools work inside your project, with the same builder that wrote the app. An independent test is separate from that builder, and complements it.

A clean report shows what an independent test saw. It is not proof that the app has no defects, and it does not replace your judgement.

Test your Bolt app with Avalyz

Avalyz tests a web app from the outside, in real browsers, and returns a GO, NO-GO or INCONCLUSIVE verdict with evidence.

FAQ

Where is a Bolt app published?

By default on Bolt's own hosting, at a .bolt.host address. Projects can also be published to Netlify, and Pro users can use a custom domain.

I changed my app but the live site is the same. Why?

Per Bolt's help center, changes do not go live automatically. Use Update in the Publish menu.

Does Bolt test my app for me?

It offers a security audit on paid plans, a database Security tab and debugging help. It does not document a full acceptance test of the published app.

Can an outside test change my data?

Not by default. A read-only test creates nothing. Write mode is optional and needs proof or attestation that the site is yours to test.

What about other builders?

See Replit, v0 and the vibe-coded app guide.

Try it free See pricing

Sources

Bolt is a trademark of its owner. Avalyz is independent and not affiliated with it.