Developer tools
QA Audit CLI
Compare what the crawl found on your live site to the tests in your repo — pages and routes, Application Map buttons and forms, and unit/component files. Install free from npm; crawls and scoring stay on our servers. Commands that call the API need a paid API token.
Skip the install when you can
- Reports & exports — open your paid report at
/report/<job-id>and download the CLI bundle markdown when ready. - Security Pro — DNS verify, network scan, and exports from the dashboard.
- HTTP API — same endpoints the CLI uses; token from /account with
Authorization: Bearer …
The CLI shines for local repo compare (qa-audit bundle --job-id <job-id> --path ./your-app) and offline inventory (qa-audit repo-scan --path .). Everything else works in the browser or via curl.
Complete a paid audit
Checkout at /audit. CLI API access comes with these plans:
- Team — 30 days of access, 3,000 calls/month
- Engineering — 6 months of access, 6,000 calls/month
- Security Pro — 6 months of access, 6,000 calls/month, plus network scan API
Launch and Essential do not include CLI API access. When access expires, renew with another qualifying audit or contact support. Manage tokens on /account.
Create an API token
Sign in → /account → CLI API tokens → create a token. Copy it once — we only store a hash.
Install the CLI
Requires Node 24+. Install globally from npm (free package; API calls still need your paid token):
npm install -g @qa-audit/qa-audit-cliPackage @qa-audit/qa-audit-cli. If the package is not published yet, wait for the public release — we do not ship a public source install.
Configure
qa-audit config set --api-url https://qa-audit.com --token <your-token>
# Or environment variables:
export QA_AUDIT_API_URL=https://qa-audit.com
export QA_AUDIT_API_KEY=<your-token>Verify
qa-audit whoami
# → { "ok": true, "cliAccess": true, "kind": "user", ... }Or use curl
export QA_AUDIT_API_URL=https://qa-audit.com
export QA_AUDIT_API_KEY=<your-token>
curl -s -H "Authorization: Bearer $QA_AUDIT_API_KEY" \
"$QA_AUDIT_API_URL/api/cli/me"
curl -s -X POST \
-H "Authorization: Bearer $QA_AUDIT_API_KEY" \
-H "Content-Type: application/json" \
-d '{"url":"https://example.com","tier":"essential"}' \
"$QA_AUDIT_API_URL/api/audit"Commands
Audit a URL
qa-audit audit https://example.com --tier essential --modules seo,links --json
qa-audit audit https://example.com --pages 10 --out report.json--tier takes a plan ID: launch, essential, team, engineering, security-pro. Page budgets are clamped to your plan's limit.
Named scan wrappers
Shortcuts that map catalog-friendly names onto modules. Full attribute tables live in the docs wiki.
qa-audit scans
qa-audit scan a11y https://example.com --tier launch --json
qa-audit scan map https://example.com --tier essential --pages 10
qa-audit scan flows https://example.com --tier engineering --jsonProject YAML
qa-audit init
qa-audit run --jsonAttribute reference: /docs/qa-audit-yml.
Repo scan — local inventory (no API token)
Inventory tests on your machine: package manager, runners, frameworks, route hints, and which unit/component files look covered. Optional JSON for CI. Does not call the hosted API.
qa-audit repo-scan --path .
qa-audit repo-scan --path . --json --out inventory.jsonBundle — match tests to your crawl
Use the job id from /report/<job-id>(Team+ with command-line API access). This is Test Coverage Review: compare your paid crawl to tests in a local checkout on three axes — pages/routes (browser suites and path hints), buttons and forms (Application Map vs locators in tests — needs Essential+ map on the job), and unit/component files (local file matches, not the same as visiting a URL). Writes a qa-audit/ folder with reports — not generated tests in your repo. Team includes the compare plus AI fix suggestions; Engineering adds manual drafts for uncovered pages and key controls.
Optional: run qa-audit init in the repo for testDirs, fileCap, and exclude — loaded automatically on bundle --path. Artifact list: /docs/bundle-artifacts.
qa-audit bundle --job-id <job-id> --path ./your-app
# → ./your-app/qa-audit/report.md, coverage.csv, per-page.md, tests/*.md, bundle.json
qa-audit bundle download --job-id <job-id> --path ./your-appSecurity Pro network exports
Run DNS verify and network scan from the dashboard, then download Plain-English, raw, or JSON exports from the setup wizard.
What is not in the package
- No crawl engine, nmap, or scoring — only HTTP calls to our API
- No outbound email or operator tools
- Repo scan reads your project locally; only inventory JSON goes upstream
