Verifying you own your app
1 min read
Why this is asked
Active mode makes write, RPC and authentication requests against your app. Unlike the passive scan, it cannot run without proof you own it. It's a hard gate: until verification passes, the API refuses every active scan.
Three methods, any one is enough
A unique token is generated per app. Pick whichever method is easiest for your setup: one is enough, no need to do all three.
<meta name="detektd-verify" content="<ton-token>">
https://ton-app.com/.well-known/detektd-<ton-token>.txt
; nom de l'enregistrement _detektd-verify.ton-app.com. TXT ; valeur attendue detektd-verify=<ton-token>
After putting it in place
Click "Verify" in the panel. It never errors if nothing is detected yet; just retry once the deploy has propagated (can take a few minutes, especially for DNS, where propagation depends on your zone's TTL).
It expires after 90 days
Verification isn't permanent: it has to be renewed exactly every 90 days (the panel warns as the deadline nears). Once it expires, active mode is blocked again until you re-verify.
You can leave the tag/file/DNS record in place indefinitely and just click "Verify" again: no reason to remove it between verifications.