Browse the docs

Organizations and projects

Set up your organization, projects, API keys, team members, and plan in the QualityGate app.

Everything outside your CI lives in the app at app.qualitygate.dev.

Accounts and sign-in

Sign up with email and password, then verify your address from the email we send. You can also sign in with GitHub, GitLab, or Bitbucket. Those sign-ins only confirm who you are; they never grant QualityGate access to your repositories. Manage your password and connected sign-in methods on Account. The last remaining sign-in method cannot be removed until you add another one.

Organizations

An organization is your team, company, or agency. It owns the plan, members, projects, report branding, and notifications. You can belong to several; the active one is shown at the top of the app and every page acts on it.

Projects

A project is one repository. Create one under Projects:

ProviderWhat you enter
GitHubChoose Connect GitHub, install the GitHub App on selected repositories, and pick one.
GitLabThe project path, as in CI_PROJECT_PATH, and the default branch.
Bitbucketworkspace/repository, the repository UUID, and the default branch.

Every project also needs allowed domains: the hosts QualityGate may scan for it. Enter hosts without https:// or a path. *.example.com allows every subdomain of example.com (not example.com itself). A project can have up to 50 entries. Each repository can belong to one project.

The default branch matters for regression mode: runs on it record the baselines pull requests are compared against.

API keys

Create API keys on a project’s card for GitLab, Bitbucket, or GitHub repositories not connected through the App. Name each key after where it is used, such as GitLab CI, so you know what to rotate.

  • A key is shown once. Copy it straight into your CI’s secret store.
  • A key works for its own project only.
  • Revoking a key takes effect immediately; runs using it are refused with key_revoked.

To rotate a key, create the new one, update the CI secret, confirm a run passes, then revoke the old key.

Team members and roles

Invite people under Organizations → Invite by email. An invitation is tied to that email address, expires after seven days, and is accepted by signing in with a verified account for the same address and choosing Join.

ActionOwnerAdminMember
View projects, run history, reports, and usageYesYesYes
Create projects, connect GitHub, create and revoke keysYesYesNo
Invite membersYesYesNo
Invite adminsYesNoNo
Report branding, report domain, notificationsYesYesNo
Send reports to clientsYesYesYes
Change the planYesNoNo

Plans and usage

PlanRuns per monthScheduled scans per monthProjectsBundles
Free2551a11y
Developer100603All ten
Team1,00030010All ten
Agency5,0001,500UnlimitedAll ten

Every paid package includes private client report links. Agency also adds a custom report domain. See Pricing and packages for current-price sources and legacy account allowances.

A run is one authorized scan: one URL with one bundle. Re-running a workflow is a new run. Scans that fail before QualityGate authorizes them, for example because the preview never came up, do not count. A run whose browser crashes after authorization is released and does not count either.

Billing shows everyone in the organization the month’s completed runs, runs in progress, what is left, and the reset date (the start of each calendar month, UTC). The app warns at 50%, 80%, and 100%. At 100%, new runs are refused with quota_exceeded until the next month or an upgrade.

Owners change plans under Billing → Compare packages, which opens secure Stripe checkout. A failed payment keeps paid access while Stripe retries it; a cancelled or unpaid subscription returns the organization to Free.