It lets you hook into the moment the change actually happened — the deploy — instead of waiting for the next scheduled scan.
Who is this for
- Teams with a CI/CD pipeline
- Anyone who wants notifications in Slack or their own dashboard
- Account managers who send evidence to clients regularly
Prerequisites
- URLs that are already being monitored
- A CI secret store you can keep the token in
Step-by-step
- Create a trigger token
Tokens are generated with the clt_ prefix, shown in full only at the moment of creation, and stored hashed on the server.
- Narrow the scope
A token is scoped to a project or a single URL. Its only permission is to start a scan; it reads no data and changes no settings. It is not a general API key.
- Call it after the deploy
Add the trigger request to the end of your deploy step. The scan enters the queue and the result is evaluated through the normal flow.
- Pre/post release check
If you want more than a single scan: before the release, POST /api/deploy-checks (with a project id and an optional label) captures the “before”; after you release, POST /api/deploy-checks/{id}/after captures the “after”. You read the report with GET /api/deploy-checks/{id} — once the captures are done the status becomes completed. The baseline does not advance; this is a separate comparison from monitoring.
- Revoke the token
Revoke the token when you suspect it leaked or when you part ways with a client. It stops working immediately.
- Outbound webhook and sharing
Send change events to your own endpoint. To share evidence with a client, create a time-limited share link: 7 days by default, between 1 and 30, always revocable.
Operational outputs
- Scan records tied to a deploy
- Change events flowing into your own system
- Time-limited evidence links you can send to a client
- One before/after report per release
Plan availability
- Trigger tokens are available on the Pro and Agency plans
- Webhook count: Free 0, Pro 2, Agency 10
- Share links on every paid plan
Limits and guardrails
- A token only starts a scan; it has no other permission
- Triggered scans consume the daily trigger quota
- A share link only opens the screenshot, diff, date, URL and change summary; it does not open the HTML archive or organization data
- A cancelled or expired link returns a silent 404
- There is no ready-made Slack or Jira app; the connection is made through a webhook
- A release check runs with the same project token; it cannot open a check in another project
- If that URL already has a scan running when the “after” capture is requested, the new capture does not take over and you are asked to run it again — a capture started before the deploy would otherwise be compared against itself
Expected outcome
- The gap between deploy and scan closes
- Notifications land where the team already looks
- Evidence reaches the client without creating an account
Troubleshooting paths
- If a trigger returns 401 the token may have been revoked or copied wrong
- If a trigger returns 403 the token’s scope does not include that URL
- If a trigger returns 402 the daily trigger quota is full