NewQODEX QA Services for API teams.Learn more →

Pricing

Continuous testing, priced for every team

Other bug bots read the diff and guess. Qodex runs your real test scenarios against every pull request and shows what actually broke, with the failing request and response. One platform for PR review, API and UI testing, and security, with deterministic runs that stay cheap as your suite grows.

Rated 4.9 / 5 on G2 · works in GitHub, the CLI, and Slack

Free

Try continuous testing

$0

Free for every developer

Limited monthly usage to evaluate Qodex against your real app.

  • Connect one GitHub repository
  • Real test runs on your pull requests
  • Import scenarios from OpenAPI, Postman, spreadsheets, and existing tests
  • API and UI scenario runs against your app
  • Core OWASP-aligned security probes
  • Findings with the failing request, response, and screenshot
  • Community support
Recommended

Pro

Continuous testing for your team

Usage for active teams shipping every day.

Everything in Free, plus:

  • Unlimited repositories and projects
  • Continuous testing on every pull request and deploy
  • Scenario layer that adapts as your code changes, with coverage-gap generation in chat
  • Full API testing: multi-step flows, auth profiles, and API governance
  • Full UI testing: browser runs and the UI Pages catalog
  • Full OWASP security suite, with findings filed against the PR
  • Velocity analytics: review cycle time, queue depth, flaky rate, and coverage
  • CI/CD, Slack, Jira, and Cursor (MCP) integrations
  • Scheduled and webhook-triggered runs
  • Priority support

Enterprise

Continuous testing at scale

Talk to the team

Custom pricing for larger organizations

Custom usage and limits, shaped around your org.

Everything in Pro, plus:

  • SSO / SAML, role-based access, and audit logs
  • Advanced security and compliance, data redaction, and mTLS
  • Custom data retention controls
  • Custom usage limits and unlimited environments
  • Webhooks and API access
  • Dedicated support, onboarding, and SLAs

Compare plans

What each plan can do

Every plan runs your scenarios against the real app. Higher plans add coverage, security depth, and the controls larger teams need.

CapabilityFreeProEnterprise
Scenario layer
Import from OpenAPI, Postman, spreadsheets, and existing testsImport from OpenAPI, Postman, spreadsheets, and existing tests: includedImport from OpenAPI, Postman, spreadsheets, and existing tests: includedImport from OpenAPI, Postman, spreadsheets, and existing tests: included
Manage your test scenarios in one placeManage your test scenarios in one place: includedManage your test scenarios in one place: includedManage your test scenarios in one place: included
Generate scenarios to close coverage gaps in chatGenerate scenarios to close coverage gaps in chat: not includedGenerate scenarios to close coverage gaps in chat: includedGenerate scenarios to close coverage gaps in chat: included
Scenarios adapt as your code changesScenarios adapt as your code changes: not includedScenarios adapt as your code changes: includedScenarios adapt as your code changes: included
PR review
Real test runs on your pull requestsReal test runs on your pull requests: includedReal test runs on your pull requests: includedReal test runs on your pull requests: included
Inline findings: failing request, response, and screenshotInline findings: failing request, response, and screenshot: includedInline findings: failing request, response, and screenshot: includedInline findings: failing request, response, and screenshot: included
GitHub App and PR status checkGitHub App and PR status check: includedGitHub App and PR status check: includedGitHub App and PR status check: included
Runs on every PR and deployLimitedEvery PR + deployEvery PR + deploy
Repositories1 repoUnlimitedUnlimited
API testing
HTTP and GraphQL scenario runsHTTP and GraphQL scenario runs: includedHTTP and GraphQL scenario runs: includedHTTP and GraphQL scenario runs: included
Multi-step flows and auth profilesMulti-step flows and auth profiles: not includedMulti-step flows and auth profiles: includedMulti-step flows and auth profiles: included
API governance coverage viewAPI governance coverage view: not includedAPI governance coverage view: includedAPI governance coverage view: included
UI testing
Browser (Playwright) scenario runsBrowser (Playwright) scenario runs: includedBrowser (Playwright) scenario runs: includedBrowser (Playwright) scenario runs: included
Natural-language UI steps with screenshotsNatural-language UI steps with screenshots: includedNatural-language UI steps with screenshots: includedNatural-language UI steps with screenshots: included
UI Pages catalogUI Pages catalog: not includedUI Pages catalog: includedUI Pages catalog: included
Security
OWASP-aligned hostile-mode probes (SQLi, XSS, SSRF, IDOR/BOLA, auth bypass)CoreFull suiteFull suite
Security findings filed against the PRSecurity findings filed against the PR: includedSecurity findings filed against the PR: includedSecurity findings filed against the PR: included
Advanced compliance, data redaction, and mTLSAdvanced compliance, data redaction, and mTLS: not includedAdvanced compliance, data redaction, and mTLS: not includedAdvanced compliance, data redaction, and mTLS: included
Velocity analytics
Review cycle time, queue depth, flaky rate, and coverage trendsReview cycle time, queue depth, flaky rate, and coverage trends: not includedReview cycle time, queue depth, flaky rate, and coverage trends: includedReview cycle time, queue depth, flaky rate, and coverage trends: included
Integrations and support
CI/CD, Slack, Jira, and Cursor (MCP)CI/CD, Slack, Jira, and Cursor (MCP): not includedCI/CD, Slack, Jira, and Cursor (MCP): includedCI/CD, Slack, Jira, and Cursor (MCP): included
Scheduled and webhook-triggered runsScheduled and webhook-triggered runs: not includedScheduled and webhook-triggered runs: includedScheduled and webhook-triggered runs: included
SupportCommunityPriorityDedicated + SLA
Security and administration
SSO / SAMLSSO / SAML: not includedSSO / SAML: not includedSSO / SAML: included
Role-based accessRole-based access: not includedRole-based access: not includedRole-based access: included
Audit logsAudit logs: not includedAudit logs: not includedAudit logs: included
Custom data retentionCustom data retention: not includedCustom data retention: not includedCustom data retention: included
Webhooks and API accessWebhooks and API access: not includedWebhooks and API access: not includedWebhooks and API access: included

Trusted by 10k+ teams

Trusted company logoTrusted company logoTrusted company logoTrusted company logoTrusted company logoTrusted company logoTrusted company logoTrusted company logoTrusted company logo

Make testing continuous.

Run your scenarios against every PR and deploy, and see what actually broke. Start free in minutes.