"A key was found" — the publish stopped
The scan found something that looks like an API key, token, private key or database password in a file that was about to be uploaded. The message names the file and the line and offers a sentence to paste into your AI. The fix is to move the secret out of the code — into an environment setting on the host, or out of the project altogether — and publish again. The scan looks at exactly the files the publish would send, built output included, so a key that only exists after a build is caught too.
"Only you can open it"
Netlify put the new site behind team access, which it does on some accounts. The app shows the one button that makes the site public. On a plan where Netlify refuses that, the app says so and links to the setting on netlify.com.
"The site was deleted"
The site is not in your hosting account any more — deleted on the dashboard, or on an account you are no longer signed in to. Publish again and the app makes a new site; the folder is untouched. If you deleted it by mistake and the host offers to restore it, link the restored site with Choose existing site.
"Netlify is not accepting the app any more"
The token was revoked, or the authorization was removed on netlify.com. Press Connect again. The app only ever signs you out on positive evidence that the credential is dead — never on a timeout or a network error — so this message means the host said so.
The build failed
The message on screen is one sentence; the whole output is in the project's log, on the Logs tab, and in the project's history, which keeps the last twenty publishes and failed runs. A missing Node.js or npm is its own message, with the install the app can run for you.
Docker is not running, or not installed
WordPress and PHP need Docker Desktop. "Docker is closed" offers to start it; "You need Docker" links to the download on a Mac and installs it on Windows. On Windows, a machine that has never had WSL needs one restart after the install.
A site that "took too long to start" is cleaned up so the next Start begins fresh; a database backup that "could not be imported" usually means the .sql file is not a complete dump — try another, or start without one.
The local name does not open
- Nothing answers. The app is not running, or the site is stopped. The name only works while the app runs.
- "Not secure", or a certificate warning. The computer has not trusted the app's root certificate yet, or the browser keeps a store of its own: Firefox does, and shows a warning on every local name. Chrome, Safari and Edge use the computer's trust. On a Mac, removing and re-adding the name repeats the trust dialog.
- The name opens with a port after it,
my-shop.test:8080. Another program holds port 80 or 443 on this computer. The row under the name says so; stop that program and start the site again. - It opens on the wrong site. Two projects cannot share a name; the app refuses the second. A name another tool put into the hosts file is honoured as it is.
"Windows protected your PC"
The Windows build is not yet signed, which is why the download page sends it by email rather than linking it. The warning is Windows saying the publisher is unknown: More info → Run anyway installs it. The app updates itself from then on.
The AI tool says it is not connected
On the AI page, Inside your AI asks each tool whether it has the app's server. "Needs Node.js" means the server has nothing to run under — install Node.js from the Publishing page. For Claude Code, claude mcp get vibecodeanddeploy in a terminal shows what it knows; a server registered by a repository's own .mcp.json counts for that folder only, so connect from the app for every folder.
Where the log is
Settings → Log, with a search box, a filter and a Copy button sized for the feedback form. Every project has its own log on its Logs tab. Nothing in either log names your files' contents, credentials or account details.