Skip to main content
Create an account to start on the Developer Sandbox plan, or sign in to an existing account.

Keys

To rotate, issue the new key, switch your application, then revoke the old one.

Sites

Open Sites & keys and add the domain where your page runs. Each site has its own public keys and session history. Both the collector and widget require a verified domain. On the site’s panel, set the domain and publish the token as a DNS TXT record at _heretic.<domain> with the value heretic-site-verification=<token>, or as the body of https://<domain>/.well-known/heretic-site-verification. Press Check now. Changing the domain requires verification again. Retiring a site stops collection and verdict reads for its keys. Deleting it also removes its stored verdicts. Unknown, deleted, and foreign request IDs all answer 404.

Clearance

The site’s panel shows the hosted page URL, the JWKS URL, and the current key id and public key for clearance. Set the TTL, escalation, and whether concealment indicators run a ceremony. Rotate signing key issues a new key version; see rotation.

Plan and usage

Plan & usage shows this month’s probes and challenges against your plan, with the overage incurred so far. Choose a plan there, or open the billing portal for payment details, invoices, and cancellation. See pricing.

Sessions

The session list shows the selected site’s ordinary sessions for seven days. Open one for its verdict, findings, coverage, network, identifiers, and record. Zero-data-retention sessions do not appear.

Challenges

Open Challenges to see outcome counts and recent challenge events. Choose the last 24 hours or seven days, filter by outcome, and page through the records. This view follows the seven-day challenge retention period. The widget appearance controls generate an embed for your site’s key, theme, width, and language. Your backend still supplies the verification policy at siteverify; the appearance controls do not authorize actions.