Skip to main content
Version: v6.2

Release Notes

These are the currently supported versions of the AudioEye Accessibility Testing SDK.

Version 6.2.0​

New​

  • Impact in the MCP scan report and inspector: each failure table in the scan report has an Impact column (High, Medium, Low) after Rule, and rows are ordered by impact first. The inspector panel shows one impact pill per component row and before each rated rule code in the details view.
  • Rule codes link to the AudioEye Platform: every rule code in the scan report links to https://portal.audioeye.com/rules/<ruleCode>?rulesVersion=…, which shows the rule's description, impact, WCAG mapping, and fix guidance without a login.
  • Markdown report saved beside the scan JSON: every scan writes scan-<n>.md next to scan-<n>.json under .agent/a11y-scans/<session>/, and the result always links both. A report over 8000 characters is returned as a header plus those links. See The scan report.
  • Inspector panel and audioeye_inspect: the AudioEye-controlled Chrome gets an in-page inspector panel that lists scanned components, outlines the selected instance, and selects it in DevTools. The agent drives it with the new audioeye_inspect tool. Turn it off per project with "inspector": false in .audioeye-mcp.json.
  • One Chrome shared across hosts: every MCP host on the machine now shares one browser per profile. A host that starts while the browser is open attaches to it instead of launching another.

Changed​

  • Registration runs through npx, no global install: every host entry is now npx --prefix / -y @audioeye/testing-sdk-mcp@latest, so a host restart picks up the newest release and --prefix / avoids EOVERRIDE from the open workspace's package.json. setup itself runs as npx -y @audioeye/testing-sdk-mcp@latest setup. Codex alone is registered through your login shell ($SHELL -lic 'exec npx …') with startup_timeout_sec = 60. See Step 1: Install and register and re-run setup to migrate an existing entry.

Fixed​

  • audioeye_login re-checks a saved sign-in instead of reporting "Already signed in", and starts a new pairing when the stored credentials are invalid or inactive. Scans that fail on stale credentials now name audioeye_login as the fix. See Tools fail with a license message.
  • audioeye_get_source_context rejects a bundler URL (webpack://…) that matches no workspace file with a clear message naming the path inside the bundle, instead of resolving it to a made-up workspace path. See Available tools.
  • audioeye_get_a11y_facts always reports accessibleName, as "" when the accessibility tree computed no name.
  • Two MCP hosts starting at the same instant no longer fail with a Chrome connection error; the second session waits for the first launch and attaches to the shared browser.

Version 6.1.0​

New​

  • Browser sign-in for every SDK package: aetest login and audioeye-mcp login pair the machine through the AudioEye portal's device-approval page and store the license credentials at ~/.config/audioeye/credentials.json. whoami shows the active identity and logout removes it. A stored sign-in takes precedence over the AUDIOEYE_TESTING_SDK_CLIENT_ID and AUDIOEYE_TESTING_SDK_CLIENT_TOKEN environment variables, which remain the fallback for CI. See Sign in and the CLI reference.
  • MCP server on the public npm registry: @audioeye/testing-sdk-mcp installs from npmjs with no private-registry setup, and audioeye-mcp setup registers it with Claude Code, Codex, Gemini CLI, Cursor, VS Code, Windsurf, and Zed in one step (--dry-run previews the changes). Claude Desktop installs it from a .mcpb bundle and signs in from the chat through the audioeye_login tool.
  • Markdown output: md joins html, json, csv, and sarif as an output format.

Changed​

  • License errors carry a machine-readable code (missing_credentials, invalid_token, validation_unreachable, not_initialized, unverifiable_grace) and point at the portal's Testing SDK Credentials card instead of a bare failure.
  • MCP scans block the AudioEye runtime overlay, so results measure the page's own DOM.
  • Updated package dependencies to address security vulnerabilities.

Version 6.0.3​

Changed​

  • MCP ignore rules: cssSelector replaces cssSelectorPrefix and cssSelectorContains: the new cssSelector field on an ignore entry is a real CSS selector evaluated against the live DOM during the scan. An entry matches when the failing element — or any of its ancestors — matches the selector, so one field covers both "this element" and "anything inside this container", including attribute selectors ([data-devtools]) and structural selectors (footer:has(> .TanStackRouterDevtoolsPanel)). The removed fields only substring-matched the generated selector string, which such selectors can never appear in; if your .audioeye-mcp.json uses them, rewrite each as an equivalent cssSelector. Ignore entry fields are now ruleCode, cssSelector, fileNamePrefix, fileNameContains, and comment.
  • Updated package dependencies to address security vulnerabilities.

Version 6.0.2​

New​

  • Component source locations for React apps: when scanning a React app running a development build, each issue now resolves the offending component's source file:line.
    • Issues carry a sourceLocation; resolution is skipped at zero cost on non-React pages.
    • Playwright: a failing expect(page).toBeAccessible() now points at the component source instead of the test line. Opt-in { perIssueErrors: true } emits one located error per issue, and { sourcePathPrefix } supports monorepo sub-package roots.
    • Cypress: a failing cy.checkA11y() points at the component source, with one Cypress.log entry per issue.
  • Deterministic MCP scan summaries: audioeye_scan responses now include summaryMarkdown, a canonical scan report rendered server-side, so agents present the same report for the same scan on every host instead of improvising their own output from the raw JSON.

Changed​

  • Updated rules version to 11.2.19.
  • MCP server renamed: the server registers as audioeye (previously audioeye-mcp) and its prompts are now scan, fix, and scan-and-fix — surfaced in Claude Code as /mcp__audioeye__scan, /mcp__audioeye__fix, and /mcp__audioeye__scan-and-fix, with an optional url argument on the two scan prompts. Re-register the server under the key audioeye, and re-run audioeye-mcp setup --claude (the host flag is now required) to refresh the permissions allowlist with the new mcp__audioeye__* rule.
  • Updated package dependencies to address security vulnerabilities.

Fixed​

  • The v5.0.0 workaround that let skip-link rules (e.g. Html_SkipLink_Missing) run inside the Cypress AUT iframe silently stopped working against the obfuscated production rules bundle, because it patched the bundle's text. It has been replaced with a runtime Proxy shim over the AUT window, which works regardless of how the bundle is minified or obfuscated.

Version 6.0.0​

v6 is a major release that introduces idiomatic per-framework APIs. Old APIs continue to work in v6 with a one-time deprecation warning per process and will be removed in v7. See the v5 → v6 upgrade guide for a walkthrough.

New requirement: license check

Starting in v6, every scan runs a license check against the AudioEye API. Both AUDIOEYE_TESTING_SDK_CLIENT_ID and AUDIOEYE_TESTING_SDK_CLIENT_TOKEN must be present in the environment when the SDK runs, not only when you install packages. This is the one change that can break an otherwise-working v5 setup on upgrade — wire your credentials into every environment that runs scans before rolling out v6. See License check below.

License check​

  • What runs. Before each scan, the SDK validates your entitlement (Client ID + Client Token) against the AudioEye API. On success it caches a signed grace token locally that stays valid for up to 7 days, so subsequent scans run without a network round-trip — including fully offline — until the window expires. The SDK refreshes the token about every 24 hours when it can, but falls back to the cached copy whenever AudioEye is unreachable.
  • Credentials. Set AUDIOEYE_TESTING_SDK_CLIENT_ID and AUDIOEYE_TESTING_SDK_CLIENT_TOKEN in the environment of every machine and CI job that runs scans. They come from the AudioEye Customer Portal; the Client Token also authenticates package downloads. See How licensing works.
  • Fails closed. If the credentials are missing, rejected (revoked / unknown / inactive), or unverifiable with no valid cached grace token, the scan stops with a non-zero exit code rather than silently passing. A cancelled or revoked entitlement is locked out once its last grace token expires (within 7 days), and a stale or forged local cache cannot extend access.
  • Network. The machine running scans needs outbound access to the AudioEye API at least once per 7-day window. Air-gapped CI that can never reach AudioEye is not supported.
  • CI caching (optional). Set AUDIOEYE_TESTING_SDK_CACHE_DIR to relocate the grace-token cache onto a persisted path so a warm cache can carry across jobs within its 7-day lifetime.

New​

  • Jest matcher: expect(node).toBeAccessible(options?). Pair with import { toBeAccessible } from '@audioeye/testing-sdk-jest'; expect.extend({ toBeAccessible }).
  • Jest functional API: scan(source, options?) returning A11yResults.
  • Playwright matcher: await expect(page).toBeAccessible(options?). Auto-attaches a11y-report.json to test.info() on failure for inline display in the Playwright HTML report.
  • Playwright functional API: await accessibility.scan(target?, options?) accepting either a Page or a Locator.
  • Cypress commands: cy.checkA11y(scope?, options?) (assertion-style; fails the test on issues) and cy.scanA11y(scope?, options?) (chainable; resolves to A11yResults). Both accept an optional subject, so cy.checkA11y('.modal') and cy.get('.modal').checkA11y() are equivalent.
  • CLI --format sarif: SARIF v2.1.0 output suitable for GitHub code-scanning upload. Each result carries partialFingerprints.issueFingerprint.
  • CLI --baseline <path>: read a SARIF file of issue fingerprints and suppress matching issues from the report. Exit code drops to 0 if every issue is suppressed.
  • Fluent filter API on A11yResults: withRule(...), withoutRule(...), withinSelector(...), excludingSelector(...), excludingIds(...), plus query helpers has(code), get(code), count, isEmpty, issues. All filter methods return a new A11yResults instance. Selector filters use normal CSS ancestor matching in Jest, Cypress, and Playwright.
  • conformanceLevel(level, { exact }): opt-in exact-level filtering. The default (cumulative) semantics are unchanged.
  • Enriched issue shape: each issue now carries id (SARIF fingerprint based on rule, target path, and target markup), helpUrl (https://developer.audioeye.com/rules/{ruleCode}), xpath, boundingBox (real-browser scans only), frame, and relatedNodes.
  • Scan context on the report: A11yReport.context exposes scanId, timestamp, engine.{sdk, rules}, rulesEvaluated, and viewport. Runtime errors surface as a structured errors[] array.

Changed​

  • RuleMetaOutput.wcagSuccessCriteriaLevelCode (the field exposed via aetest describe, every issue's ruleMetadata, and the keys of resultsGroupedByWcagSuccessCriteriaLevel) is now always a single value: one of 'A', 'AA', 'AAA', or ''. v5 emitted a comma-joined string like 'A, AA' for rules that mapped to multiple WCAG criteria; v6 collapses these to the most stringent level (A > AA > AAA).

Fixed​

  • conformanceLevel filter now correctly buckets rules with multiple WCAG criteria. v5 stored a comma-joined level code ('A,AA') and compared it lexicographically against the filter, which quietly dropped these rules from level-A and level-AA buckets. v6's single-level representation makes the comparison straightforward, so you may see additional issues appear in those buckets — they were always failing, just bucketed wrong.

Deprecated (still work in v6, removed in v7)​

  • accessibility.evaluate(...) and the a11y / accessibility singleton exports in @audioeye/testing-sdk-jest. Use scan(...) or expect(node).toBeAccessible(...) instead.
  • accessibility.evaluate(...) on Playwright's AudioEyeA11y. Use accessibility.scan(...) or await expect(page).toBeAccessible(...).
  • cy.accessibility(...) and cy.a11y(...) (the legacy magic-string output form). Use cy.checkA11y(...) or cy.scanA11y(...).

Each deprecated entry point emits a one-time console.warn per process and carries a JSDoc @deprecated tag for editor strike-through.

Version 5.1.0​

  • Updated rules version to 11.1.1
  • Updated package dependency puppeteer.
  • Reduced @audioeye/testing-sdk-core package size.

Version 5.0.0​

  • Updated rules version to 11.0.35
  • Fixed a bug where skip link rules (e.g. Html_SkipLink_Missing) were not being evaluated when running inside a Cypress AUT iframe, due to a window.self !== window.top check in the rules bundle. The SDK now patches this check at runtime to ensure full accessibility coverage in Cypress environments.
  • Updated package dependencies lodash and puppeteer.

Version 4.1.1​

  • Updated rules to version 10.4.6
  • Updated package dependencies commander and puppeteer.

Version 4.1.0​

  • Updated rules to version 10.4.4
  • Updated package dependencies commander, htmlparser2, lodash, marked, papaparse, and puppeteer.

Version 4.0.2​

  • Updated rules to version 10.3.21.
  • Fixed an issue where sites with malformed HTML would cause the CLI to throw an exception.

Version 4.0.1​

  • Removed the ESM build files for Cypress and Playwright. There were some incompatibilities with the ESM builds that were causing some difficulty during setup.
  • Updated package dependencies to address security vulnerabilities.

Version 4.0.0​

  • Updated rules to version 10.3.17.
  • Updated package dependencies to address security vulnerabilities.

Version 3.3.0​

  • The Cypress SDK now supports tests that require a real browser.
  • We now support Cypress v15.
  • Updated package dependencies to address security vulnerabilities.

Version 3.2.0​

  • Factored out optional peer dependencies into their own SDK packages.

Version 3.1.0​

  • Fixed the version of rules shown in the CLI output.
  • Stop using ts-results.
  • Added support to Cypress tests for when the cucumber plugin is used.

Version 3.0.0​

  • Updated to the latest version of the AudioEye RuleSet (8.3.5).
  • Added support for Playwright.
  • The CLI now supports tests that require a real browser.
  • Jest and Cypress tests changed from custom assertions to results that you can write your own assertions against.
  • Other minor bug fixes and improvements.

Version 2.0.3​

  • Updated package dependencies to address security vulnerabilities.

Version 2.0.2​

  • Fix CLI for Windows users.
  • Improved CSS selectors.

Version 2.0.0​

  • Updated to the latest version of the AudioEye RuleSet.
  • Removed tests that need a real browser and were causing false positives.

Version 1.2.3​

  • Improved accessibility of the html output.
  • Added "Must Be Fixed At Source" info to the html, json, and csv output files.

Version 1.2.2​

  • Improved the npm build step to include transitive types in the exported type definition files.
  • Fixed a bug with how we handle jQuery selected elements (impacts Cypress).
  • Added new command line options to control the viewport size and turn on mobile emulation.
  • Changed some of the command line options to be more consistent.
  • Added documentation for calling the test function directly (not just through the CLI or Jest/Cypress).

Version 1.1.3​

  • Removed async/await from the Jest and Cypress assertions.
  • Additional rule updates.