How to test a Bolt app before launch
This guide is for people who built a site or app with Bolt (bolt.new) and want to know whether it holds up once strangers use it. The common failures appear after publishing: changes that never went live, a database that behaves differently for real users, sign-in that fails on the live address, a custom domain that is half connected. You will get a step-by-step plan for the published site, an honest view of what Bolt's own tools check, and what an independent, read-only test adds.
It belongs to a series on how to test an app built with AI. A similar routine for another builder is in How to test a Lovable app.
What Bolt is and where your app lives
Bolt describes itself as an AI builder for websites, apps and prototypes, with Bolt Cloud covering hosting, databases, user authentication and custom domains.
According to Bolt's help center, publishing puts the project at a live URL. Every user, Free or Pro, gets a free .bolt.host address, and Bolt assigns a random name on first publish that you can change. Bolt's own hosting is the default, but projects can also be published to Netlify instead: in that case Bolt generates a random netlify.app address on first publish. Custom domains are available to Pro users.
Two facts matter for testing:
- Changes do not go live automatically. After editing, you must click Update in the Publish menu.
- Visibility is a setting. Paid plans can make a site private, with invited viewers, and a site with a custom domain must be public. Team members can view a private site by default.
What Bolt already gives you
Fair credit first. Bolt documents several checks that you should use:
- Paid plans can run a security audit from the Publish menu, and Bolt fixes the issues it finds. On any plan, the database settings include a Security tab.
- The help center suggests asking Bolt to add debug logging, reproducing the issue in a separate browser tab and pasting the console output back into the chat.
- Its advice for reliability is to make one change at a time, test each one, keep a README and split large files.
- Bolt Database is created automatically when your app needs one, with Tables, Authentication, File Storage, Logs, Secrets and User Management in its settings. Bolt notes that unpublished projects' databases may be paused after low usage, and publishing stops that.
The documentation does not describe an automated test suite for your finished app, so the verification of the live site is left to you.
Pre-launch test plan for a Bolt app
- Publish, then open the published address in a private window. Do not test in the preview.
- Confirm nothing is pending: if you edited after publishing, click Update, then test again.
- Check the visibility (public or private) matches what you want. Open the site signed out, from another device.
- Visit every page and menu item and note blank screens, missing images or console errors. Bolt's help center says missing images are fixed by placing them in the
Publicfolder. - Test on a phone-width screen: navigation, forms, buttons.
- Create a new account and confirm the whole sign-up path, including any email.
- Sign in, sign out and use a wrong password. Check messages and where you land afterwards.
- Sign in as two different users and verify one cannot see the other's data. Open the database Security tab and read what it flags.
- Create, edit and delete one record and reload to prove it persists.
- Visit a private page while signed out; you should be turned away.
- Submit forms with empty, long and odd input; read the errors and check what was stored.
- Check the custom domain, if any: it loads over a secure connection, the bare and
wwwversions both work, and it points to the right site. - Check secrets and payment settings: no keys visible in the page, and any payment set up in test mode before real money.
- Check text and legal pages: placeholder copy, dead links, privacy page, contact address.
- Re-test after each fix, publishing with Update first.
What an independent test adds
Bolt's tools work inside your project, with the same builder that wrote the app. An independent test is separate from that builder, and complements it.
- It sees the live site as a visitor. It starts from the address you share and has no access to your project, so it finds what only shows once published.
- It does not read your code, so it judges the result and not the intention.
- It repeats. Run it after each Update and it compares with the previous run, so a regression shows as a difference.
- It gives you a verdict with evidence, which is easier to act on than a general feeling that the app works.
A clean report shows what an independent test saw. It is not proof that the app has no defects, and it does not replace your judgement.
Test your Bolt app with Avalyz
Avalyz tests a web app from the outside, in real browsers, and returns a GO, NO-GO or INCONCLUSIVE verdict with evidence.
- Free test, no sign-up: use the free test page, 3 tests a day, or start one with
https://avalyz.com/essai?url=YOUR_APP_URL. - Read-only by default: it creates and changes nothing on your app.
- Optional test account: give a test login; signing in is the sole form submitted, then signed-in pages are explored.
- A report you can paste back into Bolt: a plain-language summary, findings ranked by severity with annotated screenshots, a PDF sign-off report and a comparison with the previous run.
- Plans are on the pricing page, with a 14-day trial and no card. The badge for your README is described in the method page.
FAQ
Where is a Bolt app published?
By default on Bolt's own hosting, at a .bolt.host address. Projects can also be published to Netlify, and Pro users can use a custom domain.
I changed my app but the live site is the same. Why?
Per Bolt's help center, changes do not go live automatically. Use Update in the Publish menu.
Does Bolt test my app for me?
It offers a security audit on paid plans, a database Security tab and debugging help. It does not document a full acceptance test of the published app.
Can an outside test change my data?
Not by default. A read-only test creates nothing. Write mode is optional and needs proof or attestation that the site is yours to test.
What about other builders?
See Replit, v0 and the vibe-coded app guide.