← All guides

Env vars rescue

Bolt.new env vars work in preview but break on production

Bolt.newVPSSupabase

Short answer

A clean environment variable map for the production server with secrets rotated where needed.

Why this matters

The app ran fine in Bolt.new. After export, nothing works because every secret, API key, and callback URL is missing.

Walkthrough

  1. 01

    Audit every variable the app needs

    Search the codebase for `process.env` references and list each one.

    • Separate public frontend variables from server-only secrets.
    • Identify which variables must be available at build time vs runtime.
    • Note which URLs and keys still point to preview or test values.
  2. 02

    Set variables on the production server

    Load env vars from the deploy panel or server environment, not from files.

    • Add each variable to your deploy panel environment store.
    • Update all callback URLs, auth redirects, and webhook endpoints to the production domain.
    • Rotate any key that was ever visible in Bolt.new preview or a public repo.
  3. 03

    Rebuild and verify

    After setting env vars, rebuild the app and test every integration.

    • Run a clean production build with the new environment.
    • Test database connections, auth flows, payment webhooks, and email.
    • Confirm no preview URLs remain in the running app.

Where RepoAssistant fits

RepoAssistant cleans up Bolt.new environment variables during production deploy so nothing breaks on launch.