POST
Record a verification run of the store's storefront

Authorizations

Authorization
string
header
required

A secret API key. Publishable keys cannot reach this API. A key may carry an expiry, and an expired key is refused exactly like an unknown one, with a 401 that names no reason; check the key's expires_at in the dashboard rather than inferring it from a response. When a merchant rolls a key's secret they choose a grace window of up to 3 days, and for its duration BOTH the new secret and the one it replaced authenticate, so an integration moves over on its own deploy schedule instead of at the instant the button is pressed. Move before the window closes: after it, the old secret is refused. Nothing else about this contract moves with a roll. The key keeps its id and its scopes, so the only thing an integration updates is the credential itself.

Headers

Idempotency-Key
string
required

A unique key per logical write. Replaying a request with the same key returns the first response byte for byte instead of applying the write twice.

Body

application/json

What one run of the coverage matrix found: whether it passed, how many routes it rendered and how many failed, its own report, and optionally the templates it rendered as kind -> sha256 of the markup. Omit templates to snapshot the store's published templates, which is what a run on this store rendered; send them to carry a record from the store the run happened on to the one the drafts were promoted to.

passed
boolean
required

Whether the run passed. A run with failed routes cannot pass.

routes_total
integer

How many routes the run rendered.

routes_failed
integer

How many of them failed; at most routes_total.

report
object

The run's own account of itself; any JSON object, up to 256 KiB.

templates
object

kind -> sha256 hex of the template markup the run rendered.

Response

Created

data
object