Running into an error while publishing or deploying your project? See Publish issues.
GitHub sync issues
In your own projects, Bolt syncs to GitHub every time you make a change. If collaborators edit your project, their changes sync the next time you open the project. If your changes don’t sync to GitHub as expected, reauthorizing the GitHub app can help refresh the connection and get your sync working again. To reauthorize your GitHub connection:- On the Bolt homepage, below the chatbox, click the GitHub option.
- In the Import a repository dialog, click Configure the GitHub App. The Install Bolt.new (by StackBlitz) page opens.
- Select your GitHub account. The Install & Authorize Bolt.new (by StackBlitz) page opens.
- Click Install & Authorize, then follow the on-screen instructions to enter your credentials. When GitHub finishes verifying your credentials, you’re returned to Bolt, and your connection is refreshed.
GitHub authentication issues
Sometimes, GitHub authentication conflicts can occur if you’ve connected the same GitHub account to more than one Bolt account. This usually happens when:- You originally signed up for Bolt using your GitHub account.
- Later, you created a new Bolt account and tried to connect that same GitHub account through the GitHub integration.
1
Create a new login method for your original Bolt account
-
In your first Bolt account (the one you signed up for using GitHub), reset your password using the email address associated with your GitHub account.
This adds an email and password login option to that account.
- Log out once the reset is complete.
2
Remove GitHub authentication from the old account
- Log back in to the original account using your new email and password credentials.
- Click Settings in the left menu.
- Click the Credentials tab.
- Under GitHub, click Delete to remove GitHub as an authentication method.
3
Connect the GitHub integration to your new account
- Log in to your new Bolt account (the one you want to use going forward).
- Go through the usual steps to connect the GitHub integration.
Expo or EAS CLI login fails in the Bolt terminal
If you experience this problem, you might first see this message in the Expo Go app on your phone, rather than an error from Bolt itself:- In your Bolt project, click the code icon (
</>) in the top center of your screen to switch to Code view. - In the bottom panel, click Terminal.
- Type
npx expo loginornpx eas-cli login, then press ENTER.
expo loginfails withError: socket hang up.eas-cli loginopens a browser screen asking you to allow eas-cli to access your Expo account. After you approve it, the browser showsThis site can't be reached, localhost refused to connect.
1
Create a personal access token
- Go to expo.dev/settings/access-tokens and log in with your Expo account.
- Create a new personal access token and copy it.
2
Add the token to your Bolt project
Add the token to your project as
EXPO_TOKEN, either in your project’s .env file, or as a secret:- Click the database icon in the top center of your screen.
- Click Secrets.
- In Name, enter
EXPO_TOKEN. In Value, paste your token. - Click Create secret.
3
Run your command again
Run the
npx expo login or npx eas-cli login command again. With EXPO_TOKEN set, it completes automatically, and you won’t need to log in through the browser again for this project.EXPO_TOKEN and still see a login error, confirm you copied the full token and that the secret name is exactly EXPO_TOKEN.
These steps fix your login access only for the project where you added the secret. If other Expo projects run into this issue, you’ll need to add the token again for each one.
Supabase row-level security rules aren’t working
If your Supabase row-level security (RLS) rules aren’t behaving as expected (such as returning no data, exposing too much data, or causing authorization errors), it’s often due to a misconfigured policy or a mismatch between your schema and the rule conditions. You can resolve this by resetting your RLS configuration and reapplying the correct rule through Bolt. To do so, follow these steps:- In the chatbox, prompt Bolt to remove all existing row-level security rules from the affected Supabase table. This clears out any incorrect or conflicting policies.
- Once the rules are removed, prompt Bolt to add back the relevant row-level security rule. Be specific about the intended behavior (for example, “only allow users to view rows where user_id matches their authenticated ID”).
- After the new rule is applied, test your queries or endpoints again to confirm the policy is now enforced correctly.
Server functions
Server functions connect your project to external services, like OpenAI, Notion, Stripe, or GitHub, and to your database. Each type of connection can run into its own issues:- CORS errors happen when a web browser tries to call a server function from a domain your CORS configuration doesn’t allow.
- Authorization header or JWT issues happen when external services like Stripe or GitHub send webhook requests without a JSON Web Token (JWT). When this happens, ask Bolt to turn off JWT verification for that function and add another way to validate the request.
- Missing secrets happen when a server function tries to connect to an external API, like OpenAI, without the credential it needs.
CORS (cross-origin resource sharing) errors
If your server function isn’t working, it may be due to a CORS error. To check this:-
Open Chrome DevTools: press
Command + Option + Jon Mac,Control + Shift + Jon Windows or Linux. - Check the Network tab. Look for errors related to CORS.
-
Next, check whether the CORS headers in your server function’s file are set correctly. Here are the CORS headers for a chatbot built with Bolt using OpenAI:
Missing secrets
If your project expects a secret you haven’t created yet, you’ll see the following message:These steps work whether you have a Bolt database or have connected or claimed a Supabase database to use with Bolt.If you do manage your database in Supabase, you can also add secrets in the Supabase dashboard under Edge Functions > Secrets. Making the change in either place updates the same secrets.
1
Open the Secrets settings
- In your Bolt project, click the database icon at the top center of the screen.
- Click Secrets.
2
Add the secret
- In Name, enter the name that your server function uses for the secret.
- In Value, enter the secret key or password.
- Click Create secret.
OPENAI_API_KEY in Name, then paste your OpenAI API key in Value.3
Continue your work
The secret is available to your server function right away. You don’t need to redeploy it. If Bolt pauses and asks you to add the secret, tell Bolt you’ve added it so it can continue or test your project.
In shared projects, only the project Owner or a Co-owner can view or add secrets.
Webhooks: authorization headers and JWT
When a third-party service (such as GitHub, Slack, or Stripe) triggers a webhook in your project, the request comes from outside your app’s authentication system, so it won’t include a valid JSON Web Token (JWT). By default, server functions expect authenticated requests. If JWT verification is still turned on, your webhook calls from external services will fail with an authorization error. To fix this:- In the chatbox, ask Bolt to turn off JWT verification for the server function that receives the webhook.
This allows the function to accept incoming requests from third-party services that don’t use your app’s authentication.
- Add your own checks inside the server function to confirm each request is legitimate. For example:
- Validate a secret or signature header provided by the third-party service.
- Confirm the request source matches the expected domain or IP range.
Branding doesn’t show on the Google OAuth consent screen
If your app name or logo isn’t appearing on the Google sign-in screen, the issue is usually in your Google Cloud Console branding configuration rather than in Bolt. To check, sign in to Google Cloud Console and go to Google Auth Platform > Branding. The most common causes are:- Your branding hasn’t been verified. Google requires verification before your app name and logo appear on the consent screen. If you haven’t submitted for verification yet, click Verify branding.
- Your branding hasn’t been published. Verification and publishing are separate steps. After verification is complete, click Publish branding to make your changes live.
- Your Google OAuth app is in Testing mode. Even with verified and published branding, your app name and logo won’t appear if your publishing status is set to Testing. To fix this, go to Google Auth Platform > Audience and publish your app.