Organizations and projects
Set up your organization, projects, API keys, team members, and plan in the QualityGate app.
Everything outside your CI lives in the app at app.qualitygate.dev.
Accounts and sign-in
Sign up with email and password, then verify your address from the email we send. You can also sign in with GitHub, GitLab, or Bitbucket. Those sign-ins only confirm who you are; they never grant QualityGate access to your repositories. Manage your password and connected sign-in methods on Account. The last remaining sign-in method cannot be removed until you add another one.
Organizations
An organization is your team, company, or agency. It owns the plan, members, projects, report branding, and notifications. You can belong to several; the active one is shown at the top of the app and every page acts on it.
Projects
A project is one repository. Create one under Projects:
| Provider | What you enter |
|---|---|
| GitHub | Choose Connect GitHub, install the GitHub App on selected repositories, and pick one. |
| GitLab | The project path, as in CI_PROJECT_PATH, and the default branch. |
| Bitbucket | workspace/repository, the repository UUID, and the default branch. |
Every project also needs allowed domains: the hosts QualityGate may scan
for it. Enter hosts without https:// or a path. *.example.com allows every
subdomain of example.com (not example.com itself). A project can have up to
50 entries. Each repository can belong to one project.
The default branch matters for regression mode: runs on it record the baselines pull requests are compared against.
API keys
Create API keys on a project’s card for GitLab, Bitbucket, or GitHub
repositories not connected through the App. Name each key after where it is
used, such as GitLab CI, so you know what to rotate.
- A key is shown once. Copy it straight into your CI’s secret store.
- A key works for its own project only.
- Revoking a key takes effect immediately; runs using it are refused with
key_revoked.
To rotate a key, create the new one, update the CI secret, confirm a run passes, then revoke the old key.
Team members and roles
Invite people under Organizations → Invite by email. An invitation is tied to that email address, expires after seven days, and is accepted by signing in with a verified account for the same address and choosing Join.
| Action | Owner | Admin | Member |
|---|---|---|---|
| View projects, run history, reports, and usage | Yes | Yes | Yes |
| Create projects, connect GitHub, create and revoke keys | Yes | Yes | No |
| Invite members | Yes | Yes | No |
| Invite admins | Yes | No | No |
| Report branding, report domain, notifications | Yes | Yes | No |
| Send reports to clients | Yes | Yes | Yes |
| Change the plan | Yes | No | No |
Plans and usage
| Plan | Runs per month | Scheduled scans per month | Projects | Bundles |
|---|---|---|---|---|
| Free | 25 | 5 | 1 | a11y |
| Developer | 100 | 60 | 3 | All ten |
| Team | 1,000 | 300 | 10 | All ten |
| Agency | 5,000 | 1,500 | Unlimited | All ten |
Every paid package includes private client report links. Agency also adds a custom report domain. See Pricing and packages for current-price sources and legacy account allowances.
A run is one authorized scan: one URL with one bundle. Re-running a workflow is a new run. Scans that fail before QualityGate authorizes them, for example because the preview never came up, do not count. A run whose browser crashes after authorization is released and does not count either.
Billing shows everyone in the organization the month’s completed runs,
runs in progress, what is left, and the reset date (the start of each calendar
month, UTC). The app warns at 50%, 80%, and 100%. At 100%, new runs are refused
with quota_exceeded until the next month or an upgrade.
Owners change plans under Billing → Compare packages, which opens secure Stripe checkout. A failed payment keeps paid access while Stripe retries it; a cancelled or unpaid subscription returns the organization to Free.