Verifying you own an app
Fifteen seconds, one paste, and why we insist.
What to do
Copy the prompt we give you and paste it into whatever you built the app with — Lovable, Bolt, Cursor, Replit, v0. It adds one meta tag to your <head>. Redeploy, then press Verify.
You can remove the tag afterwards, though leaving it costs nothing.
Why we insist
The verified checks send requests to your application’s backend — asking your database whether a table answers, for example. We will not do that to anyone’s infrastructure on a claim alone, because a claim is not proof and "they ticked a box" is not a defensible position.
It also means that when we do it, there is a timestamped record of what we requested and on what authority.
If it will not verify
Give it a minute after redeploying — some hosts serve a cached page. Confirm the tag is in the HTML your live site returns, not just in your editor: open the page and use View Source.
If your app is on a platform where you cannot edit the head, use the file upload or the DNS TXT record instead. We try all three every time you press Verify.
Not sure whether this applies to you?
Give us the address and we will tell you. No code, no access, no install — and every finding we have is shown in full, including on the free trial.
Check a site