Back home

API Docs

For automation, scripts, or CI — use audityxe-cli instead of this REST API. It's the same audit engine, running on your own machine — free, genuinely unlimited, no account and no rate limit. This REST API is what the website's own UI calls, documented here for transparency, and it's subject to the same per-plan daily limits as the site itself.

POST /api/audit

Runs a full audit and returns the complete scored result. Full machine-readable spec: openapi.yaml.

Authentication

  • No Authorization or x-api-key header — rejected with 401. Authentication is required for all audits.
  • Authorization: Bearer <Firebase ID token> — uses that account's plan limit instead. This is a Firebase ID token obtained by signing in through the Firebase client SDK, not a static API key. Tokens expire in about an hour and need refreshing through Firebase, which is straightforward from a browser but extra work from a plain script.
  • x-api-key: atx_live_... — a long-lived, revocable key for Pro-plan accounts, purpose-built for scripts/CI where refreshing a Firebase token every hour isn't practical. Uses that account's own daily limit, not a separate quota — and skips the cross-site Origin/bot checks below, since those exist for browser CSRF protection and don't apply to a keyed, non-browser caller. Keys aren't self-serve — see "Requesting an API key" below.
  • A cross-site browser request (no x-api-key present) is rejected with 403 — CSRF protection for browser clients specifically, not a block on server-side/script callers, which typically don't send an Origin header at all.

Requesting an API key

API keys are issued manually from the admin panel — there's no self-serve signup — and only to accounts already on the Pro plan. If that's you, email a request and we'll get one issued.

Email [email protected] to request a key

Opens your email client with the subject and a starter message already filled in — just add your account email and what you're building.

Request body

{
  "url": "https://example.com",        // required
  "competitorUrl": "https://...",      // Standard/Pro only, ignored otherwise
  "confirmPageSpeed": true,            // Pro only — opt-in real Lighthouse pass
  "crawlMode": "fast" | "deep" | "max" | "ultra" // default "fast"
}

Example

curl -X POST https://audityxe.vercel.app/api/audit \
  -H "Content-Type: application/json" \
  -d '{"url": "https://example.com"}'

With a Pro API key, add -H "x-api-key: atx_live_...".

Response

The full AuditResult object (score, categories, every module and finding, fixes) plus:

  • _usage — your remaining quota after this request: { used, limit, remaining, plan }
  • pageSpeedLockReason — present when the Lighthouse pass wasn't run: "not_confirmed" or "weekly_limit"

Status codes

200Audit completed
400Invalid request (missing/malformed URL, oversized body)
401Invalid/expired Firebase ID token, or an invalid, revoked, or no-longer-Pro API key
403Cross-site request rejected, or automated-traffic pattern detected
429Daily/weekly quota exhausted
502The audit itself failed (target site unreachable, timed out)

Prefer automation without any auth or rate limit at all? See audityxe-cli and the GitHub Action.