Your Bolt app looks finished in the browser and falls over with real users. Here's what to do.
Sample before and after: an API key in the browser, illustrative
Before
- Browser code
- API key pasted in
- Payment or AI API
- Anyone viewing the source can use the key
After
- Browser code
- Your server holds the key
- Payment or AI API
- The key never reaches the browser
Is your Bolt app showing these symptoms?
- Logging out and changing the address bar still shows pages that should need an account
- Data disappears on refresh, or lives in the browser rather than in a database
- An API key for an AI model, a payment provider or another service sits in a front-end file
- You deployed from the editor and aren't sure which version is live or how to undo it
- Asking Bolt for a backend feature rewrites parts of the app you didn't ask it to touch
- A developer said it needs a proper backend and you don't know what that means for cost
Why do Bolt apps break after launch?
Bolt runs a full development environment in the browser and turns a prompt into a working app you can publish in a few clicks. For getting an idea in front of people, that is exactly right. The backend is where builds differ. Some Bolt apps connect to a hosted database and sign-in service; some keep their state in the browser; some call third-party APIs straight from the page, with a key pasted in to make it work. All three look the same in a demo.
The gap shows when strangers arrive. Checks that only run in the browser can be skipped by anyone who opens developer tools. A key in client code can be copied and billed to your account. Without a data layer that enforces ownership, one user's records are one changed ID away from another's. And because deploying straight from the editor skips separate environments and review, a bad prompt reaches production as easily as a good one. This is not a failing of Bolt. A prototype tool is built to get you to a working screen, and it did.
How do we fix a Bolt app?
- Two-day triage ($349, two working days): a senior engineer reads the code Bolt generated and how it is deployed, then returns the five risks most likely to hurt you first, an indicative fix range, and a recommendation on whether to fix, harden fully or, rarely, rebuild.
- Stabilisation sprint (from $2,500, one to two weeks) or production hardening (from $6,000, three to five weeks): keys moved into server-side functions, sign-in enforced on the server, a real database with per-user access rules, migrations and tested backups, tests around sign-up and payment, and CI with one-step rollback. If you need a fixed quote first, the Production Readiness Audit ($1,500, five working days) gives you one.
- Move the project off the builder when that is the right call: we put the code in a standard repository, on hosting and a database you control, without a rebuild. Scope and price come from the triage or audit.
- Optional managed AI engineering from $1,500 a month, three-month minimum, so someone keeps owning reliability after launch.
Questions about fixing a Bolt app
My Bolt app doesn't have a backend at all. Can you still help?
Yes, and it is a common starting point. The triage tells you what the backend needs to do, what can stay as it is, and what adding it would cost. Usually the interface Bolt built is kept and the missing layer is built underneath it.
Is a key in my front-end code a problem if nobody has used it?
Yes. Anything shipped to the browser can be read by anyone who loads the page. We rotate the exposed keys, move the calls that need them behind a server, and check the provider logs for use you did not make.
Can I keep using Bolt after you have fixed it?
For interface work, yes. We agree which parts are safe to regenerate and which are now maintained by hand, and the tests in CI catch it if a new prompt breaks sign-up or payments.
What do you need from me to start?
The project's code, exported to a repository or shared from Bolt, plus where it is hosted and which services it calls. We never ask for your personal passwords, and access is removed at handover.
What happens to the triage fee if I go ahead?
Half of it is credited against a sprint that starts within 30 days.
Tell us what's breaking, or what's slow.
We take on a limited number of engagements at a time and reply to every message, including the ones we're not the right fit for.