Docs
Verify ownership
Before a full audit or any run behind login, WitnessQA checks that you own the site. This stops anyone from pointing the agent at a site that is not theirs. It takes one change to your site and one click.
When it is needed
| Run | Verification |
|---|---|
| Free partial audit (public flows) | Not needed |
| Full audit | Required |
| Any run that logs in | Required |
| Issue verification from GitHub or Jira | Required |
Each environment is verified on its own. Verifying staging.acme.app does not verify acme.app.
Verify in three steps
-
Open the environment and copy your token
Open Environments, pick the environment and click Verify ownership. Each environment has its own token.
The environment list. Click Verify ownership on the one to verify. -
Add the token to your site
Pick the method that is easiest for you. They all work the same way. Details for each one are below.
Four methods. Copy the one you want and deploy it to the environment. -
Click Verify
After you deploy, click Verify. WitnessQA checks right away. Keep the token in place: it is checked again before each full audit, and runs pause if it is gone.
Verified. Full audits and logged-in runs are now unlocked for this environment.
Methods
JS snippet
Like an analytics tag. Good when you can edit the page template but not the server. Add it to every page or just the home page.
<script async src="https://witnessqa.com/v.js" data-site="wqv_8f2c1e9a4b7d"></script> Meta tag
Add it inside <head> of the home page. It must be in the HTML the server sends, not added later by JavaScript.
<meta name="witnessqa-verification" content="wqv_8f2c1e9a4b7d" /> DNS TXT record
Best when you cannot change the site. DNS changes can take up to an hour to show up.
Type TXT
Name _witnessqa.staging.acme.app
Value witnessqa-verification=wqv_8f2c1e9a4b7d File in the site root
Upload a plain text file that contains only the token.
https://staging.acme.app/witnessqa-verification.txt
wqv_8f2c1e9a4b7d Protected staging
If your staging is behind a login wall, give WitnessQA a way through. The agent sends it on every request to that environment only.
Vercel Deployment Protection
In Vercel, open Project Settings → Deployment Protection and create a Protection Bypass for Automation
secret. Paste it in WitnessQA. The agent sends it in the x-vercel-protection-bypass header.
Basic auth
Pick Basic auth and enter the username and password. They are stored encrypted and never shown again.
Troubleshooting
- Meta tag not found. View the page source, not the inspector. If the tag is not in the source, it is added by JavaScript. Use the snippet instead.
- DNS record not found. Wait up to an hour, then try again. Check that the name includes the full host.
- File not found. Open the file URL in a private window. It must return the token with status 200, not a redirect to login.
- Blocked by protection. Add the bypass secret or basic auth first, then verify.