Documentation
Quick start
- Create a free account and verify your email address.
- Add a project with your website's public URL (http or https).
- Confirm you have permission to test the website and run a Quick Scan.
- Review issues: each one has a simple explanation, technical details, evidence and a suggested fix.
- Click “Generate AI Fix Prompt”, choose your coding agent, and paste the prompt into it.
- After deploying the fix, click Retest. The comparison shows what was fixed, what remains and any regressions.
Verifying domain ownership
- DNS: add a TXT record containing devscan-verification=<token> on your domain (or _devscan.<domain>).
- File: serve /.devscan-verification.txt containing exactly devscan-verification=<token>.
- Meta tag: add <meta name="devscan-verification" content="<token>"> to your homepage <head>.
- Verification is required for load testing and mutating API checks.
How scores work
- Each category starts at 100. Findings subtract a severity weight (Critical 30, High 15, Medium 6, Low 2); repeated occurrences of the same problem count with diminishing weight.
- Any critical finding caps its category at 59. Performance blends findings with lab metrics (or Lighthouse); accessibility blends with the axe-core pass rate.
- The overall score is a weighted average of the categories that were actually tested. Untested categories are excluded — never counted as zero.
- Bands: 90–100 Excellent · 75–89 Good · 50–74 Needs Attention · 0–49 Poor. Scores describe automated technical checks only.
CI/CD & API
- On the Team plan, create an API key (Integrations → API keys) with the scans:write scope.
- Start a scan: POST /api/v1/projects/{project_id}/scans with header Authorization: Bearer <key> and body {"scan_type": "FULL", "authorization_confirmed": true, "idempotency_key": "<commit-sha>"}.
- Poll GET /api/v1/scans/{scan_id} until status is COMPLETED, PARTIAL or FAILED, then fail your pipeline on new critical issues.
- Outgoing webhooks (scan.completed, finding.critical, monitor.down…) are signed with HMAC-SHA256: verify the DevScan-Signature header (t=<timestamp>,v1=<hex>) against your signing secret.
Limits & fair use
- Usage resets at the start of each billing period (calendar month on Free). Quick Scans also have a daily fair-use limit.
- If you downgrade, nothing is deleted: projects beyond your new limit become read-only and extra monitors are paused.