Help

Add a test account

Most of a product sits behind sign-in. With a test account, the scan signs in the way a person would and captures the pages it finds there, and journeys replay as a signed-in user.

What account to create

  • A new account made for us, in a non-production or seeded environment if you have one. Never a real person's account.
  • The least access that still shows the product your customers use. The scan follows links and opens pages; it doesn't need an admin.
  • A username or email and a password on a sign-in form. The scan looks for the form from your navigation and the usual addresses, such as /login and /sign-in, fills both fields and submits. Single sign-on and one-time codes aren't filled.

Scan with the account

  1. Enter the username and password under Sign-in on Scope.
  2. Choose Sign in and scan. It captures up to 12 pages behind sign-in.
  3. Check Session for Valid and its date, or Failed. If it failed, the alert at the top of Scope gives the reason.

The password and signed-in session are stored sealed. The password is never shown, logged or put in a capture.

What we store

  • The username, as you typed it. Scope shows it, and the scan log names it.
  • The password, sealed. It's encrypted (AES-256-GCM) before it's saved, and is never shown, logged or put in a capture. Only the worker that runs scans opens it, to fill the sign-in form.
  • The signed-in session, sealed. The cookies the browser holds after signing in are sealed the same way, so replays can start signed in.

Wherever the password could reach the text we capture (the accessibility tree, the virtual screen-reader transcript, the page's HTML), it's masked before anything is stored.

Change or revoke it

  • Revoke our access by deleting the account in your product. The next sign-in fails, and Scope's Session line says Failed. Changing the password also stops new sign-ins, but a session your product already issued lasts as long as your product keeps it.
  • Give us another account by entering it on Scope. Its password replaces the sealed one.
  • Sign in again with the same account: leave the password blank on Scope and choose Sign in again. We reuse the sealed password.