This guide is for testing protected Vercel preview deployments from CI/CD
pipelines. To run QA.tech from CI, see PR Testing and
Regression Testing. For Vercel Firewall /
WAF rules, see Vercel Firewall.
Overview
Vercel’s Protection Bypass for Automation allows automated tools like QA.tech to access protected deployments using a special secret. This bypasses all deployment protection methods including:- Password Protection
- Vercel Authentication
- Trusted IP restrictions
Setting Up Vercel Protection Bypass
Step 1: Enable Protection Bypass in Vercel
1
Navigate to Project Settings
Go to your Vercel project dashboard and navigate to Settings → Deployment
Protection
2
Enable Protection Bypass
Find the Protection Bypass for Automation section and enable it. This
will generate a secret token.
3
Copy the Secret
Copy the generated secret - you’ll need this for configuring QA.tech
The secret is automatically added to your Vercel deployments as the
environment variable
VERCEL_AUTOMATION_BYPASS_SECRET. Regenerating the
secret will invalidate previous deployments, requiring a redeploy to use the
new value.Step 2: Add custom headers on the environment
Add the bypass headers on the QA.tech environment that points at the protected Vercel URL:1
Open the environment
Go to Settings → Applications &
Envs, open the
application, and edit the environment (or create one for the preview URL).
2
Set the environment URL
Use the clean preview URL only, for example
https://example-vercel-protected-git-branch-qa-tech.vercel.app. Do not
append bypass query parameters.3
Add a custom header rule
Under Custom headers, add a rule with domain pattern
*.vercel.app (or
your preview host pattern) and these headers:Use
x-vercel-set-bypass-cookie for browser tests so Vercel sets a bypass
cookie for the rest of the session. For API tests, send only
x-vercel-protection-bypass. Do not send x-vercel-set-bypass-cookie on
API tests: the sandbox has no cookie jar, so that header loops and the
request fails.4
Save
Save the environment. Matching hosts receive these headers on browser,
crawler, and API requests.
Persist headers from CI
When you create or reuse a preview environment from GitHub Actions or the Start Run API, pass the same headers incustomHeaders:
customHeaders writes them to the environment. Omit the field to leave
stored headers unchanged. Pass [] to clear them. See
GitHub and
Environment custom headers.