How to tell if a website was built with Bolt

Bolt.new publishes to its own hosting and marks it in the response headers. Here is every Bolt fingerprint we know, and how to check for them.

To tell if a website was built with Bolt, check three places: the address, the response headers and the badge. Bolt.new, the AI app builder from StackBlitz, builds full web apps from a prompt and publishes them with one click. That publishing step leaves the clearest fingerprints.

This guide lists each Bolt fingerprint we use in Kitsuvo's detector, how strong it is, and how to look for it yourself.

Bolt's hosting domains

Projects published from Bolt without a custom domain live on:

  • *.bolt.host: published Bolt sites
  • *.bolt.new: Bolt-run previews and hosting

An address on either is the strongest single sign. Some older Bolt projects were deployed to Netlify, so you may also meet them on *.netlify.app. Netlify hosts a great many hand-built sites, though, so that address alone says little.

Bolt's hosting adds a response header to every page:

x-powered-by: Bolt.new

To see it, open the developer tools (F12, or Option+Command+I on a Mac), choose the Network tab, reload the page, click the first request and scroll to Response Headers.

This is the most useful Bolt check on a custom domain. The address tells you nothing there, but if the site is still served by Bolt's hosting, the header gives it away.

The Made with Bolt badge

Bolt adds a small badge to sites on its free plan. Look in the page source (Ctrl+U) for:

  • bolt.new/badge.js: the badge's script
  • The text Made with Bolt, Built with Bolt or Made in Bolt
  • A link containing bolt.new/?rid, Bolt's referral link

Each of these names Bolt outright. A site owner can remove the badge, so its absence means little.

Generator tags and template leftovers

Some Bolt projects keep a <meta name="generator"> tag naming Bolt. Many start from a Vite and React template, so an untouched tab title of Vite + React + TS or the Vite lightning-bolt favicon is common. Those two are template defaults, not Bolt fingerprints: they say someone started from Vite, which plenty of developers do by hand.

The stack: weak on its own

Bolt usually generates React with Tailwind CSS, often with shadcn/ui components and lucide icons, and frequently connects Supabase for data and sign-in. Lovable and v0 produce almost the same stack. Treat it as support for a fingerprint, never as the reason to name Bolt. Our builder fingerprint guide compares them side by side.

A quick check in the console

Open the developer tools, go to Console, and paste this. It reads the page and its own response headers, and changes nothing:

fetch(location.href, { method: 'HEAD' }).then(r => ({
  header: r.headers.get('x-powered-by'),
  badge: !!document.querySelector('script[src*="bolt.new"], a[href*="bolt.new"]'),
}))

A header of Bolt.new or a badge of true points to Bolt. Only paste code you understand into a console, and never because a page told you to.

Worked example: a class-booking site on its own domain

Here is the method applied to a made-up site, kilnroom-classes.example, a pottery studio's booking page that a friend sent you. The address is a custom domain, so it tells you nothing about the builder. Work through the rest in order.

Step 1, the source. Pressing Ctrl+U shows a short document:

<title>Vite + React + TS</title>
<link rel="icon" type="image/svg+xml" href="/vite.svg" />
<script type="module" crossorigin src="/assets/index-Bq3x9.js"></script>
<div id="root"></div>

The untouched Vite title and favicon say the site started from a Vite template and nobody finished the metadata. That is a hint, not a fingerprint: it fits Bolt, Lovable and a developer working by hand equally well.

Step 2, the headers. In the Network tab, the first request shows:

content-type: text/html; charset=utf-8
x-powered-by: Bolt.new

Now there is a fingerprint. The site is served by Bolt's hosting even though it has its own domain.

Step 3, the finished page. Searching the Elements panel for bolt finds the badge in the corner of the page:

<a href="https://bolt.new/?rid=k3x9..." target="_blank">Made with Bolt</a>

The verdict. Two independent Bolt fingerprints (the header and the badge) plus template leftovers. A fair reading is Likely AI-built, builder Bolt, and Kitsuvo would list exactly those three pieces of evidence. None of it says the studio is untrustworthy. It says how the page was made.

A false alarm, worked through

Now a second made-up site: ana-portfolio.netlify.app, a designer's portfolio. It also has the title Vite + React + TS, uses Tailwind CSS and shadcn/ui class names such as text-muted-foreground, and sits on Netlify, where some older Bolt projects were deployed.

It looks a lot like the first example, but check what is missing: no x-powered-by: Bolt.new header, no badge, no bolt.new links, no bolt.host address. Every sign it has is shared with ordinary hand-built sites.

The fair reading is Possibly vibe coded at most, with no builder named. Calling it a Bolt site would be a guess, and if the designer wrote it by hand, an unfair one. This is the most common mistake people make with AI-built detection: treating the shared look as a fingerprint.

Checking for Bolt automatically

Kitsuvo is our no-AI web browser for Mac and Windows. It reads the hosting, the headers and the page source of every site as it loads. When it finds Bolt's fingerprints, it shows the builder's name and a score in the address bar, with the matched evidence one click away. It runs on your computer and is free.

For the other builders, see Lovable, v0 and Base44.

Questions people ask

What is bolt.host?

It is the domain Bolt.new uses to host projects its users publish. A site on something.bolt.host was published from Bolt. Like any hosting, most sites there are ordinary projects; be careful only if one claims to be a well-known brand and asks you to sign in or pay.

Who makes Bolt.new?

Bolt.new is made by StackBlitz, a company known for running development environments in the browser.

Can a Bolt site hide that it was made with Bolt?

Yes. If the owner removes the badge and hosts the code elsewhere, the header and domain disappear too. What remains is the shared React and Tailwind stack, which is not enough to name Bolt.