Hosted dashboard¶
The CLI gates a single run. The dashboard does the thing the CLI can't: persist runs and track regressions across builds over time.
What you get¶
- Run history — every adversarial sweep, stored and searchable.
- Regression diffing — each run is compared to the last green run for the same target. New failure / rising severity / more findings → an alert.
- Scheduled runs — fire the suite on an interval against staging.
- Alerts — in-app, plus a Slack-compatible webhook and (optionally) email, on every regression or recovery.
- API keys —
Authorization: Bearer gnt_…for CI / scripts. - Accounts — per-user isolation; billing on the Team tier.
Run it locally¶
cd apps/dashboard
python -m venv .venv && source .venv/bin/activate
pip install -r requirements.txt
pip install -e ../../packages/gauntlet
uvicorn app.main:app --port 8001 # then open http://localhost:8001
API¶
Session cookie or Authorization: Bearer <api_key>:
| Method | Path | |
|---|---|---|
| POST | /api/runs |
trigger a run (CI) → {id, status} 202 |
| GET | /api/runs |
list your runs |
| GET | /api/runs/{id} |
run detail + full report |
Plans¶
| Free | Team | |
|---|---|---|
| CLI + engine | ✓ | ✓ |
| Run history | ✓ | ✓ |
| Scheduled runs | 1 | unlimited |
| Regression alerts + webhooks | — | ✓ |
Self-hosting
The dashboard is a FastAPI + SQLite app. Production deployments should run
behind auth with GAUNTLET_ENV=production (enables SSRF target validation)
and a sandboxed runner for untrusted targets.