> ## Documentation Index
> Fetch the complete documentation index at: https://docs.agentgg.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Live validation

> Test each finding against a running copy of your application. The scan records the proof and uses the result in the verdict.

A browser runs the attack of each finding against your application and records the requests, screenshots, and a video as proof. Live validation is optional.

<Warning>
  Live tests send real attack requests, and a test can change or delete data. Test only applications that you own or are authorized to test. Use a test or staging environment, not production.
</Warning>

## What the target needs

* It must be reachable from the public internet, on port 80, 443, or a port from 8000 to 8999.
* If a firewall protects it, allow the IP address that the scan form shows.
* The scan must run on pay as you go, or on your own model with an OpenRouter key.

## Test the findings of one scan

In the **live validation** step of the scan form:

1. Enter the **target URL**, for example `https://staging.example.com`.
2. Optionally, add **testing instructions**, such as the test account to sign in with, the pages to test, and the actions to avoid. Put the login here, not in the URL.
3. Confirm that you are authorized to test the target.

To skip live tests, leave the fields empty, unless the repository has a saved target.

## Save a target for a repository

An Owner or Admin can save a target for a connected repository. Every scan of that repository then tests against it, including pull request scans.

1. Select **GitHub** in the sidebar.
2. On the repository's row, select **Live validation**.
3. Enter the target URL and the testing instructions, confirm your authorization, and select **Save**.

The scan form fills in the saved target, and you can change it for one scan. To stop live tests for the repository, select **Remove** in the same dialog.

A pull request scan tests the code that is deployed on the target, which may not include the changes in the pull request. Pull requests from forks never run live tests.

<Warning>
  Every member of your organization, viewers included, can read saved testing instructions and the evidence of each test. The evidence includes the session of the test login. Use a test account with no access to real data.
</Warning>

## What gets tested

After the review step, the platform tests every finding that is not a duplicate and not out of scope. Each test has a time limit of 10 minutes. A finding that describes a missing control, such as a missing security header, gets **nothing to reproduce** without a test.

## Results

| Result | Meaning |
| - | - |
| **reproduced** | The attack worked against the running application. |
| **refuted** | The attack did not work. |
| **timed out** | The test reached its time limit. The issue is not ruled out. |
| **inconclusive** | The test found no clear evidence. The issue is not ruled out. |
| **run failed** | The test did not complete. This says nothing about the issue. |
| **nothing to reproduce** | The finding is a missing control that a browser test cannot show. |
| **refused** | The testing agent declined to run the test. |
| **not tested live** | The finding was not tested. The finding page says why. |

Each finding on the scan page shows a **live** badge with its result. On the finding page, the **Validation** tab shows the test and the **Evidence** tab shows its proof. See [Findings](/platform/findings#finding-detail). If the tests did not run, the scan page says why.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.