Docs

Verify ownership

Before a full audit or any run behind login, WitnessQA checks that you own the site. This stops anyone from pointing the agent at a site that is not theirs. It takes one change to your site and one click.

When it is needed

RunVerification
Free partial audit (public flows)Not needed
Full auditRequired
Any run that logs inRequired
Issue verification from GitHub or JiraRequired

Each environment is verified on its own. Verifying staging.acme.app does not verify acme.app.

Verify in three steps

  1. Open the environment and copy your token

    Open Environments, pick the environment and click Verify ownership. Each environment has its own token.

    The environment list. Click Verify ownership on the one to verify.
  2. Add the token to your site

    Pick the method that is easiest for you. They all work the same way. Details for each one are below.

    Four methods. Copy the one you want and deploy it to the environment.
  3. Click Verify

    After you deploy, click Verify. WitnessQA checks right away. Keep the token in place: it is checked again before each full audit, and runs pause if it is gone.

    Verified. Full audits and logged-in runs are now unlocked for this environment.

Methods

JS snippet

Like an analytics tag. Good when you can edit the page template but not the server. Add it to every page or just the home page.

<script async src="https://witnessqa.com/v.js" data-site="wqv_8f2c1e9a4b7d"></script>

Meta tag

Add it inside <head> of the home page. It must be in the HTML the server sends, not added later by JavaScript.

<meta name="witnessqa-verification" content="wqv_8f2c1e9a4b7d" />

DNS TXT record

Best when you cannot change the site. DNS changes can take up to an hour to show up.

Type   TXT
Name   _witnessqa.staging.acme.app
Value  witnessqa-verification=wqv_8f2c1e9a4b7d

File in the site root

Upload a plain text file that contains only the token.

https://staging.acme.app/witnessqa-verification.txt

wqv_8f2c1e9a4b7d

Protected staging

If your staging is behind a login wall, give WitnessQA a way through. The agent sends it on every request to that environment only.

Vercel Deployment Protection

In Vercel, open Project Settings → Deployment Protection and create a Protection Bypass for Automation secret. Paste it in WitnessQA. The agent sends it in the x-vercel-protection-bypass header.

Paste the Vercel bypass secret.

Basic auth

Pick Basic auth and enter the username and password. They are stored encrypted and never shown again.

Enter the basic auth username and password.

Troubleshooting

  • Meta tag not found. View the page source, not the inspector. If the tag is not in the source, it is added by JavaScript. Use the snippet instead.
  • DNS record not found. Wait up to an hour, then try again. Check that the name includes the full host.
  • File not found. Open the file URL in a private window. It must return the token with status 200, not a redirect to login.
  • Blocked by protection. Add the bypass secret or basic auth first, then verify.