FAQ

Frequently asked questions

The long tail: comparisons, auth, billing, access. If yours isn't here, email support@supergorilla.ai and a person will answer.

How is this different from Playwright or Cypress?+

Different layer. Playwright and Cypress are frameworks: you write the tests, maintain the selectors, and debug the flake. SuperGorilla is a service: it runs your app and tests it like a user, with no test code in your repo and nothing that breaks when the UI changes.

How is it different from an AI code reviewer?+

A reviewer reads the diff. SuperGorilla runs it. A reviewer can tell you the code looks wrong; SuperGorilla can tell you the signup form throws on submit, with the recording. The two compose well; nothing about running one replaces the other.

Our agents write tests too. Why this?+

Generated unit tests assert that the code does what the code does. Neither they nor the diff can catch a broken flow in a real running app: a form that renders but never submits, a redirect loop, a payment that silently fails. That takes using it.

Will it work with my stack? Monorepo? Multiple services?+

Whatever your stack. SuperGorilla works out how to run your app on its own, and you can steer it in plain English when your setup needs a hint. Bring the weird stack; that is what the beta is for.

How does it log in? What about OTPs and SSO?+

With the test credentials you keep in environment variables, encrypted before they reach our database and handed only to the run's sandbox. For OTPs or SSO, a fixed test code or a bypass account keeps runs unattended, and when a run is blocked it asks you on the pull request, the way a teammate would. If your auth does something unusual, tell it in plain English in the agent instructions.

What happens if my app fails to start?+

The run reports that, with the output that explains why, so you can fix the start and run it again.

Can I tell it what to test, or is it fully autonomous?+

Both. Left alone, it derives tests from what changed. Soon you can also record your critical flows once and have them tested on every change. Steered, it follows plain-language instructions, from "focus on checkout" to "skip the admin panel entirely."

Can I limit what the agents are allowed to do?+

Yes. Guardrails are standing rules in plain English that outrank every other instruction the agent gets: pages to stay out of, actions never to take, data never to touch. Steering shapes what a run focuses on; guardrails come first, every run.

How noisy is it? Will it flag things that are not real?+

Every finding has a severity rating and reproduction steps, and the run's full recording sits alongside it, so judging one takes seconds rather than an investigation. SuperGorilla re-checks earlier findings on the same pull request and remembers how your app runs between runs.

How do I control when it runs, and the bill?+

You configure triggers per repository: pull requests into chosen branches, pushes to chosen branches, or on demand. Each run spends credits for what it used, shown in dollars per run on your usage page. When credits run low you are told, and when they reach zero new runs wait for you rather than charging anything.

What does it cost?+

Free to start, with $10 of credits on your first organisation and no card needed. Starter is $99 a month or $999 a year and Team $199 a month or $1,999 a year; each cycle adds the same amount in credits, with three or ten seats and three or ten runs at a time. Top up from $10 whenever you like, or set auto-reload.

When do mobile and desktop arrive?+

They are on the roadmap. Web is live today. Tell us which you need at support@supergorilla.ai; it genuinely shapes the order.

How do I get started?+

Sign up, install the GitHub App, pick your repositories and test environment, and your next pull request does the rest. SuperGorilla keeps what it learns about running your app, so starting sooner helps.

What happens to my data?+

The short answer: repository access is read-only for code with write access limited to checks and pull request comments, environment variables are encrypted, every environment is isolated, runs execute in sandboxes destroyed afterwards, and recordings are yours to delete. The longer answer is on the security page, and every processor involved is listed in the privacy policy.

Send the gorillas in.

Get started

Free to start, no card needed. Your first organisation gets $10 of credits.