# CLI & browser extension (developer tools)

**Category:** [Accessibility](https://help.totalctrl.app/hc/totalctrl/totalctrl-help-center/en-US/categories/accessibility)
**Updated:** 2026-10-04

## Test where you build

Two optional tools let you run accessibility checks outside the app. Download both from **Accessibility → Downloads → CLI & Browser**.

- **Command-line tool (`totalctrl-a11y`)** — a single Python file (standard library only, no Chromium to install). Queue a hosted scan, wait for it, and **fail a CI build** when critical/serious issues exceed your thresholds.
- **Browser extension** — a Chrome / Edge extension (Manifest V3) that scans the page you're on with one click, including pages behind your own login, and can queue a full hosted scan into a project.

## Connect a tool to your workspace

Both tools use the same two things:

- An **API token + secret** — create one under **Developer → API tokens** with the `app:accessibility` scope. The secret is shown only once.
- A **project UUID** — the ID in a project's URL, or run `totalctrl-a11y projects` to list them.

## Using the CLI

Set your credentials as environment variables and run a command:
```
export TOTALCTRL_API_TOKEN=your_token
export TOTALCTRL_API_SECRET=your_secret

totalctrl-a11y projects
totalctrl-a11y scan --project PROJECT_UUID \
  --wait --max-critical 0 --max-serious 5
```

Exit codes: **0** = passed, **1** = gate failed, **2** = usage or API error — so a failing gate stops the build. Add `--min-score 90` to also require a minimum score. Pass `--token`/`--secret` instead of env vars if you prefer.
## Using the extension

- Unzip the download to get a `totalctrl-a11y-extension` folder.
- Open `chrome://extensions`, turn on **Developer mode**, click **Load unpacked**, and pick that folder.
- Open any page and click **Scan this page**. The in-page scan runs entirely in your browser — no login required.
- To also queue a hosted scan, open the extension's **Settings** and paste your API token, secret, and a default project UUID. These are stored only in your browser.

## Security

The tool files themselves contain no secrets. A token is scoped to `app:accessibility` and tied to your workspace — treat it like a password, store it in your CI secret manager, and revoke it from **Developer → API tokens** if it leaks.

---

## Related Articles

- [Getting started with Accessibility](https://help.totalctrl.app/en-US/articles/accessibility-getting-started-1)
- [Scanning pages behind a login](https://help.totalctrl.app/en-US/articles/accessibility-authenticated-scans-1)
- [Scheduling, alerts & automation](https://help.totalctrl.app/en-US/articles/accessibility-automation-1)
- [VPAT / ACR reports & Accessibility Statements](https://help.totalctrl.app/en-US/articles/accessibility-reports-1)
- [Manual audits & sign-off](https://help.totalctrl.app/en-US/articles/accessibility-manual-audits-1)

---
[← Back to TotalCtrl Help Center](https://help.totalctrl.app/en-US/)