Developer tools

QA Audit CLI

Compare what the crawl found on your live site to the tests in your repo — pages and routes, Application Map buttons and forms, and unit/component files. Install free from npm; crawls and scoring stay on our servers. Commands that call the API need a paid API token.

00

Skip the install when you can

  • Reports & exports — open your paid report at /report/<job-id> and download the CLI bundle markdown when ready.
  • Security Pro — DNS verify, network scan, and exports from the dashboard.
  • HTTP API — same endpoints the CLI uses; token from /account with Authorization: Bearer …

The CLI shines for local repo compare (qa-audit bundle --job-id <job-id> --path ./your-app) and offline inventory (qa-audit repo-scan --path .). Everything else works in the browser or via curl.

01

Complete a paid audit

Checkout at /audit. CLI API access comes with these plans:

  • Team — 30 days of access, 3,000 calls/month
  • Engineering — 6 months of access, 6,000 calls/month
  • Security Pro — 6 months of access, 6,000 calls/month, plus network scan API

Launch and Essential do not include CLI API access. When access expires, renew with another qualifying audit or contact support. Manage tokens on /account.

02

Create an API token

Sign in → /account → CLI API tokens → create a token. Copy it once — we only store a hash.

03

Install the CLI

Requires Node 24+. Install globally from npm (free package; API calls still need your paid token):

install
npm install -g @qa-audit/qa-audit-cli

Package @qa-audit/qa-audit-cli. If the package is not published yet, wait for the public release — we do not ship a public source install.

04

Configure

config
qa-audit config set --api-url https://qa-audit.com --token <your-token>

# Or environment variables:
export QA_AUDIT_API_URL=https://qa-audit.com
export QA_AUDIT_API_KEY=<your-token>
05

Verify

whoami
qa-audit whoami
# → { "ok": true, "cliAccess": true, "kind": "user", ... }
06

Or use curl

curl
export QA_AUDIT_API_URL=https://qa-audit.com
export QA_AUDIT_API_KEY=<your-token>

curl -s -H "Authorization: Bearer $QA_AUDIT_API_KEY" \
  "$QA_AUDIT_API_URL/api/cli/me"

curl -s -X POST \
  -H "Authorization: Bearer $QA_AUDIT_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"url":"https://example.com","tier":"essential"}' \
  "$QA_AUDIT_API_URL/api/audit"
07

Commands

Audit a URL

audit
qa-audit audit https://example.com --tier essential --modules seo,links --json
qa-audit audit https://example.com --pages 10 --out report.json

--tier takes a plan ID: launch, essential, team, engineering, security-pro. Page budgets are clamped to your plan's limit.

Named scan wrappers

Shortcuts that map catalog-friendly names onto modules. Full attribute tables live in the docs wiki.

scan
qa-audit scans
qa-audit scan a11y https://example.com --tier launch --json
qa-audit scan map https://example.com --tier essential --pages 10
qa-audit scan flows https://example.com --tier engineering --json

Project YAML

qa-audit.yml
qa-audit init
qa-audit run --json

Attribute reference: /docs/qa-audit-yml.

Repo scan — local inventory (no API token)

Inventory tests on your machine: package manager, runners, frameworks, route hints, and which unit/component files look covered. Optional JSON for CI. Does not call the hosted API.

repo-scan
qa-audit repo-scan --path .
qa-audit repo-scan --path . --json --out inventory.json

Bundle — match tests to your crawl

Use the job id from /report/<job-id>(Team+ with command-line API access). This is Test Coverage Review: compare your paid crawl to tests in a local checkout on three axes — pages/routes (browser suites and path hints), buttons and forms (Application Map vs locators in tests — needs Essential+ map on the job), and unit/component files (local file matches, not the same as visiting a URL). Writes a qa-audit/ folder with reports — not generated tests in your repo. Team includes the compare plus AI fix suggestions; Engineering adds manual drafts for uncovered pages and key controls.

Optional: run qa-audit init in the repo for testDirs, fileCap, and exclude — loaded automatically on bundle --path. Artifact list: /docs/bundle-artifacts.

bundle
qa-audit bundle --job-id <job-id> --path ./your-app
# → ./your-app/qa-audit/report.md, coverage.csv, per-page.md, tests/*.md, bundle.json
qa-audit bundle download --job-id <job-id> --path ./your-app

Security Pro network exports

Run DNS verify and network scan from the dashboard, then download Plain-English, raw, or JSON exports from the setup wizard.

08

What is not in the package

  • No crawl engine, nmap, or scoring — only HTTP calls to our API
  • No outbound email or operator tools
  • Repo scan reads your project locally; only inventory JSON goes upstream