API Docs
For automation, scripts, or CI — use audityxe-cli instead of this REST API. It's the same audit engine, running on your own machine — free, genuinely unlimited, no account and no rate limit. This REST API is what the website's own UI calls, documented here for transparency, and it's subject to the same per-plan daily limits as the site itself.
POST /api/audit
Runs a full audit and returns the complete scored result. Full machine-readable spec: openapi.yaml.
Authentication
- No
Authorizationorx-api-keyheader — rejected with 401. Authentication is required for all audits. Authorization: Bearer <Firebase ID token>— uses that account's plan limit instead. This is a Firebase ID token obtained by signing in through the Firebase client SDK, not a static API key. Tokens expire in about an hour and need refreshing through Firebase, which is straightforward from a browser but extra work from a plain script.x-api-key: atx_live_...— a long-lived, revocable key for Pro-plan accounts, purpose-built for scripts/CI where refreshing a Firebase token every hour isn't practical. Uses that account's own daily limit, not a separate quota — and skips the cross-site Origin/bot checks below, since those exist for browser CSRF protection and don't apply to a keyed, non-browser caller. Keys aren't self-serve — see "Requesting an API key" below.- A cross-site browser request (no
x-api-keypresent) is rejected with403— CSRF protection for browser clients specifically, not a block on server-side/script callers, which typically don't send anOriginheader at all.
Requesting an API key
API keys are issued manually from the admin panel — there's no self-serve signup — and only to accounts already on the Pro plan. If that's you, email a request and we'll get one issued.
Email [email protected] to request a keyOpens your email client with the subject and a starter message already filled in — just add your account email and what you're building.
Request body
{
"url": "https://example.com", // required
"competitorUrl": "https://...", // Standard/Pro only, ignored otherwise
"confirmPageSpeed": true, // Pro only — opt-in real Lighthouse pass
"crawlMode": "fast" | "deep" | "max" | "ultra" // default "fast"
}Example
curl -X POST https://audityxe.vercel.app/api/audit \
-H "Content-Type: application/json" \
-d '{"url": "https://example.com"}'With a Pro API key, add -H "x-api-key: atx_live_...".
Response
The full AuditResult object (score, categories, every module and finding, fixes) plus:
_usage— your remaining quota after this request:{ used, limit, remaining, plan }pageSpeedLockReason— present when the Lighthouse pass wasn't run:"not_confirmed"or"weekly_limit"
Status codes
| 200 | Audit completed |
| 400 | Invalid request (missing/malformed URL, oversized body) |
| 401 | Invalid/expired Firebase ID token, or an invalid, revoked, or no-longer-Pro API key |
| 403 | Cross-site request rejected, or automated-traffic pattern detected |
| 429 | Daily/weekly quota exhausted |
| 502 | The audit itself failed (target site unreachable, timed out) |
Prefer automation without any auth or rate limit at all? See audityxe-cli and the GitHub Action.