LovableBoltCursorDeployment
Lovable, Bolt or Cursor app works in preview but breaks when deployed
6 min read · Updated 27 September 2026
It runs perfectly in Lovable, Bolt or your local preview, then you publish it and logins fail, data won't load or pages show 404. The preview environment quietly provides things your live site doesn't have yet. Start by opening the live site, pressing F12 and reading the Console and Network tabs: the real error is usually right there.
The 6 usual causes
- Missing environment variables. Keys that existed in the editor aren't set on your host (Vercel, Netlify and so on). Add them there, then redeploy.
- Your new domain isn't authorised for login. Firebase: add it under Authentication → Settings → Authorised domains. Supabase: set Site URL and Redirect URLs under Authentication → URL Configuration. Google sign-in also needs the domain in its OAuth settings.
- API keys are restricted to the old domain. Google Maps and similar keys often only allow the preview URL, so add your real domain to the allowed list.
- Page refresh gives a 404. Single-page apps need every route rewritten to index.html. On Vercel that means a rewrite in vercel.json, and on Netlify a _redirects file.
- CORS errors. Your API or backend only accepts requests from the preview address, so allow your production domain.
- Database security blocks real users. Supabase Row Level Security or Firestore rules that were open during building are now locked, or the other way round (dangerously open).
// vercel.json for a Vite/React single-page app: fixes 404 on refresh
{
"rewrites": [{ "source": "/(.*)", "destination": "/index.html" }]
}When you ask the AI to fix it, paste the exact error message from the Console. "It doesn't work" makes AI tools guess, and that's how working code gets rewritten.
Still stuck?
Share your screen and we'll fix it together, live. A$99 / hour, agreed price, no surprises.
