What you need
A real account on your app, made for this: an email and a password that sign in through your normal login form. Give it the data a typical user would have — a project or two, a few records — so there is something to open, search and edit.
Sign-in with Google or another provider is not supported yet; use an email-and-password account. For more than one role — an admin and a regular user — an app can hold several named accounts; see Several accounts and roles.
Where to enter it
- When you add your app — the “Test login” section of the form.
- Later, in the app’s settings — Dashboard → your app → “Test login”. Change the email or type a new password and press Save; leave the password empty to keep the current one.
- For a single check — on the home page, open “Add login & notes” before you press the button.
- From your coding agent — ask it to add the app with a test account; see Connect your coding agent.
How the password is kept
- Encrypted before it is stored (AES-256-GCM), and decrypted only while a check of your app is running.
- Never written to logs, never in evidence. The step descriptions and network records on your verdict page never contain it — if your app echoes it back, it is blanked out before anything is saved.
- Never shown back to you. The settings page shows which email is on file; the password field is always empty. Replacing it is the only thing you can do with it.
- Typed only into your app’s own pages. If a page on another address asks for it, it is refused.
- Kept only as long as it is needed. For a single check, the password is deleted when the check finishes. For an app on Daily Watch it stays stored, encrypted, so tomorrow’s check can sign in too — until you replace it or delete the app.
When the password stops working
Passwords get rotated and test accounts get reset. When your sign-in turns the stored details away, CheckMyApp stops right there:
- It tries once. It does not retry within the run — repeated failed sign-ins can lock an account.
- It is not reported as your bug. A login that refuses a wrong password is working correctly. Nothing behind the login is described as broken.
- You are told plainly. The verdict says the signed-in part could not be checked because the sign-in details on file no longer work, and asks for new ones. Everything a signed-out visitor can reach is still checked.
Put the new password into the app’s settings and the next check signs in again.
good to know
Nothing is created in your app unless you allow it. With “May we create test records?” switched on, CheckMyApp creates, edits and deletes records as the test account, inside that account’s own space, names each one “CheckMyApp test” and removes it again. It never invites people, publishes, messages anyone or spends money.
Put passwords only in the test-login fields. Notes and scenarios are stored as you write them, not encrypted.