Paid access without an account
How it works#
- Pay for Full or Deep.
- You receive a one time, opaque token. No account is created.
- Run the scan from the server you want checked:
curl https://qsa.sh/<token>The token authorizes the tier. It does not choose the target. The scan still runs against the IP you connect from, exactly as the free scan does. There is no field for a different address.
Delivery differences#
Full returns asynchronously. The command returns when the scan is ready rather than streaming line by line, because full port coverage takes minutes rather than seconds.
Deep emails the report, which suits a 13 to 16 minute run you do not want to hold a terminal open for.
Keep your token private#
The token is the credential. Anyone holding it can spend the scans it authorizes. Treat it like an API key: keep it out of shell history where you can, and out of committed files.
Next#
- Scan tiers
- Data retention
- Back to the index