# ADAGuard ai-train: yes ai-input: yes search: yes > Automated Web Accessibility Scanner — WCAG 2.2, ADA & European Accessibility Act (EAA) Compliance ADAGuard is a SaaS platform that scans websites for WCAG 2.2, ADA Title III, and European Accessibility Act (EAA) compliance issues and pre-fills VPAT/ACR reports from scan results (criteria requiring manual testing are flagged as such). Automated checks cover ~73% of WCAG 2.2 Level A/AA success criteria (40 of 55, fully or partly), with support for authenticated page scanning (login-protected pages). The EAA enforcement deadline for B2C digital services was June 28, 2025 — the law is now in effect across the EU. ## Engine Coverage ADAGuard has automated checks for ~73% of WCAG 2.2 Level A+AA success criteria — 40 of 55 (26 fully covered + 14 partially covered), based on a criterion-by-criterion code audit. The other 15 criteria need manual testing. This is a count of criteria, not a percentage of issues found. Full coverage matrix, checker inventory, and methodology: [WCAG 2.2 Coverage](https://www.adaguard.io/wcag-coverage) ## Free Tools - [Free Accessibility Scanner](https://www.adaguard.io/free-accessibility-scanner): Scan any public URL instantly for WCAG and ADA issues — no account required. - [Color Contrast Checker](https://www.adaguard.io/tools/color-contrast-checker): Check foreground/background color pairs against WCAG AA and AAA contrast ratio requirements. Generates shareable URLs and CSS snippets. - [Shopify Accessibility Checker](https://www.adaguard.io/accessibility-checker/shopify): Audit Shopify storefronts for WCAG/ADA compliance. - [WordPress Accessibility Checker](https://www.adaguard.io/accessibility-checker/wordpress): Scan WordPress sites and themes for accessibility violations. - [Squarespace Accessibility Checker](https://www.adaguard.io/accessibility-checker/squarespace): Scan Squarespace sites for the contrast, heading and alt-text failures template palettes introduce. - [React Accessibility Checker](https://www.adaguard.io/accessibility-checker/react): Test React web apps for keyboard, ARIA, and contrast issues. - [SaaS Accessibility Checker](https://www.adaguard.io/accessibility-checker/saas): Check SaaS dashboards and authenticated apps for accessibility problems. - [Ecommerce Accessibility Checker](https://www.adaguard.io/accessibility-checker/ecommerce): Identify accessibility barriers on online retail and checkout flows. ## API Base URL Production: `https://api.adaguard.io/v1` Interactive docs (Swagger UI): `https://api.adaguard.io/v1/docs` OpenAPI spec (machine-readable): `https://api.adaguard.io/v1/openapi.json` ## Authentication All API requests require an API key passed via header: ``` X-API-Key: your_api_key_here ``` API keys are available from your dashboard at `https://app.adaguard.io/settings`. API access requires the **Professional** plan or higher. ## Core Endpoints ### Start a Scan `POST /v1/scan` Returns immediately with a `scan_id`. The scan runs in the background — poll `/v1/scan/{scan_id}/status` to track progress. Request body: ```json { "url": "https://example.com", "scan_mode": "single", "max_pages": 1, "min_score": 80, "auth_target": "latest", "include_subdomains": true } ``` - `scan_mode`: `single` (default) | `crawl` | `sitemap` | `layout` - `max_pages`: 1–5000, capped to plan limit. Ignored for `single` mode. - `min_score`: CI/CD gate — result includes `passed: true/false` when set. - `auth_target`: a named target from the dashboard, or `"latest"`, to scan login-protected pages. Omit for a public scan. - `include_subdomains`: `true` (default) | `false` — set to `false` to restrict crawl to the exact hostname only, excluding subdomains such as `api.example.com` or `blog.example.com`. Only applies in `crawl`, `sitemap`, and `layout` modes. Response: ```json { "scan_id": "abc123", "status": "queued", "url": "https://example.com", "created_at": "2025-01-01T00:00:00Z", "poll_url": "/v1/scan/abc123/status" } ``` ### Poll Scan Progress `GET /v1/scan/{scan_id}/status` Call repeatedly until `status` is `completed` or `failed`. Use `poll_again_in` as retry interval hint. Response: ```json { "scan_id": "abc123", "status": "completed", "url": "https://example.com", "score": 87, "passed": true, "pages_scanned": 1, "max_pages": 1, "issues_critical": 2, "issues_warning": 5, "issues_info": 3, "auth_status": "not_requested", "poll_again_in": null } ``` `auth_status` values: - `not_requested` — no auth session provided - `authenticated` — scan ran with the stored session - `expired_fallback` — session expired; scan fell back to public pages - `public_only` — site detected as public ### Get Full Scan Results `GET /v1/scan/{scan_id}` Returns the complete scan including all issues with WCAG criteria, severity, element selectors, and remediation suggestions. Includes a `canonical_url` field — the normalized form of the URL used for website identity (HTTPS-forced, `www.` stripped, trailing slash removed). Useful for grouping scans of the same site entered in different forms. ### Download Report `GET /v1/scan/{scan_id}/report?format=json` Formats: `json` (default) | `html` | `csv` | `pdf` - `json` — structured data, ideal for CI/CD parsing - `html` — self-contained HTML report - `csv` — spreadsheet-friendly issue list for QA teams - `pdf` — professional PDF for compliance/executive sharing ### List Scans `GET /v1/scans?limit=10&offset=0&url=https://example.com` Returns scan history sorted newest first. Filter by URL prefix with `?url=`. ### Usage Statistics `GET /v1/scans/stats` Returns total scans, scans used this month, average score, and issue counts. ### List Authenticated Sessions `GET /v1/auth-sessions` Lists stored browser auth sessions (created in the dashboard under Settings → Authenticated Scans). Use `session_id` as `auth_session_id` in POST /v1/scan. ### Delete a Scan `DELETE /v1/scan/{scan_id}` Permanently deletes a scan and its stored data. ## Plan Limits | Tier | Price/mo | Scans/Month | Pages/Scan | Websites | API Access | GitHub App (private repos) | |-------------|----------|-------------|------------|----------|------------|----------------------------| | Free | $0 | Unlimited* | 1 | 1** | No | 1 (∞ public) | | Starter | $49 | 4 | 50 | 1 | No | 2 (∞ public) | | Professional | $129 | 30 | 500 | 3 | Yes (100/h)| 5 (∞ public) | | Business | $249 | 150 | 1,000 | 10 | Yes (500/h)| Unlimited | | Enterprise | Custom | Custom | Custom | Custom | Custom | Unlimited | Scan quota is per calendar month and resets on the 1st. Free is the exception: it has no monthly quota at all — see below. * Free tier has no monthly scan cap: rescan your one page as often as you want (a short per-URL cooldown, ~45s, only guards against scripted abuse, not a real limit for normal use). ** Free tier's single website is locked once added — it can't be deleted or repointed to a new URL. Multi-page crawling (2+ pages/scan) requires Starter or above. Public repos are free on all plans for the GitHub App. Annual billing saves ~17% (2 months free) on all paid plans. Full pricing: https://www.adaguard.io/pricing ## Error Responses All errors follow this shape: ```json { "error": "Human-readable summary", "details": [{"field": "url", "message": "Only http and https URLs are allowed"}] } ``` Common status codes: - `422` — validation error (invalid request body) - `429` — rate limit or monthly scan quota exceeded - `404` — scan or session not found - `409` — operation not valid for scan in current state (e.g. report on incomplete scan) ## CI Integration (GitHub Action) `adaguard-io/accessibility-action@v1` runs a scan as a workflow step and fails the build when the score drops. Requires a Professional plan or above. ```yaml - uses: adaguard-io/accessibility-action@v1 with: api-key: ${{ secrets.ADAGUARD_API_KEY }} url: https://example.com min-score: 80 ``` Required inputs: `api-key`, `url`. Optional: `min-score` (80), `scan-mode` (single | crawl | sitemap | layout), `max-pages` (1), `include-subdomains` (true), `auth-target`, `fail-on-scan-error` (false), `comment-on-pr` (true), `max-wait-minutes` (30), `idempotency-key`, `api-base`. Outputs: `score`, `passed`, `critical`, `warning`, `info`, `pages`, `scan-id`, `scan-status`, `auth-status`, `dashboard-url`, `report-url`. Full reference: https://www.adaguard.io/docs/github-action The GitHub App (https://www.adaguard.io/docs/github-app) is separate: install once for zero-config scanning on every pull request, available on all plans. ## Links - Website: https://www.adaguard.io - App: https://app.adaguard.io - Developer Docs (overview of the three guides): https://www.adaguard.io/docs - REST API Docs: https://www.adaguard.io/docs/api - API Docs (Swagger UI): https://api.adaguard.io/v1/docs - GitHub Action Docs: https://www.adaguard.io/docs/github-action - GitHub App Docs: https://www.adaguard.io/docs/github-app - OpenAPI Spec: https://api.adaguard.io/v1/openapi.json