Verifying you own your app

1 min read

Why this is asked

Active mode makes write, RPC and authentication requests against your app. Unlike the passive scan, it cannot run without proof you own it. It's a hard gate: until verification passes, the API refuses every active scan.

Three methods, any one is enough

A unique token is generated per app. Pick whichever method is easiest for your setup: one is enough, no need to do all three.

Meta tag, inside <head>
<meta name="detektd-verify" content="<ton-token>">
.well-known file, served at this exact path
https://ton-app.com/.well-known/detektd-<ton-token>.txt
DNS TXT record
; nom de l'enregistrement
_detektd-verify.ton-app.com.  TXT

; valeur attendue
detektd-verify=<ton-token>

After putting it in place

Click "Verify" in the panel. It never errors if nothing is detected yet; just retry once the deploy has propagated (can take a few minutes, especially for DNS, where propagation depends on your zone's TTL).

It expires after 90 days

Verification isn't permanent: it has to be renewed exactly every 90 days (the panel warns as the deadline nears). Once it expires, active mode is blocked again until you re-verify.

You can leave the tag/file/DNS record in place indefinitely and just click "Verify" again: no reason to remove it between verifications.

Was this article helpful?