Recipes

Deploy hook (URL-only)

Trigger a crawl after Vercel or Railway deploys without repo access.

POST to /api/hooks/deploy with your customer API token (same as CLI). The audit runs asynchronously — the hook returns immediately with jobId and statusUrl.

curl
curl -sS -X POST "$QA_AUDIT_API_URL/api/hooks/deploy" \
  -H "Authorization: Bearer $QA_AUDIT_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"url":"https://staging.example.com","environment":"staging","label":"vercel-main"}'

Optional callbackUrl (HTTPS, Team or Engineering Monitor): we POST audit.complete with X-QA-Audit-Signature HMAC (sha256) when the crawl finishes. Verify with QA_AUDIT_DEPLOY_HOOK_SECRET.

Vercel: add a Deploy Hook or post-deploy webhook that curls this endpoint with your staging URL. Railway: use a service hook after deploy with the public service URL.