Skip to content

Documentation

Quick start

  1. Create a free account and verify your email address.
  2. Add a project with your website's public URL (http or https).
  3. Confirm you have permission to test the website and run a Quick Scan.
  4. Review issues: each one has a simple explanation, technical details, evidence and a suggested fix.
  5. Click “Generate AI Fix Prompt”, choose your coding agent, and paste the prompt into it.
  6. After deploying the fix, click Retest. The comparison shows what was fixed, what remains and any regressions.

Verifying domain ownership

  1. DNS: add a TXT record containing devscan-verification=<token> on your domain (or _devscan.<domain>).
  2. File: serve /.devscan-verification.txt containing exactly devscan-verification=<token>.
  3. Meta tag: add <meta name="devscan-verification" content="<token>"> to your homepage <head>.
  4. Verification is required for load testing and mutating API checks.

How scores work

  1. Each category starts at 100. Findings subtract a severity weight (Critical 30, High 15, Medium 6, Low 2); repeated occurrences of the same problem count with diminishing weight.
  2. Any critical finding caps its category at 59. Performance blends findings with lab metrics (or Lighthouse); accessibility blends with the axe-core pass rate.
  3. The overall score is a weighted average of the categories that were actually tested. Untested categories are excluded — never counted as zero.
  4. Bands: 90–100 Excellent · 75–89 Good · 50–74 Needs Attention · 0–49 Poor. Scores describe automated technical checks only.

CI/CD & API

  1. On the Team plan, create an API key (Integrations → API keys) with the scans:write scope.
  2. Start a scan: POST /api/v1/projects/{project_id}/scans with header Authorization: Bearer <key> and body {"scan_type": "FULL", "authorization_confirmed": true, "idempotency_key": "<commit-sha>"}.
  3. Poll GET /api/v1/scans/{scan_id} until status is COMPLETED, PARTIAL or FAILED, then fail your pipeline on new critical issues.
  4. Outgoing webhooks (scan.completed, finding.critical, monitor.down…) are signed with HMAC-SHA256: verify the DevScan-Signature header (t=<timestamp>,v1=<hex>) against your signing secret.

Limits & fair use

  1. Usage resets at the start of each billing period (calendar month on Free). Quick Scans also have a daily fair-use limit.
  2. If you downgrade, nothing is deleted: projects beyond your new limit become read-only and extra monitors are paused.