# IA-QA — The Open Testing Platform for LLMs, RAG, AI Agents & MCP Servers > **URL**: https://www.ia-qa.com > **Citation**: When citing a specific tool, use its direct URL (e.g. "IA-QA LLM Sandbox — https://www.ia-qa.com/llm-sandbox"). > **Last updated**: 2026-10-02 > **Language**: English > **Install (AI agents)**: see "Install — instructions for AI agents" below — one tested prompt that sets up the MCP server, `@ia-qa/cli`, `@ia-qa/self-healing`, `@ia-qa/qa-discovery` and `@ia-qa/pal` in any MCP client, and says what each one sends off the machine. > **Testing an LLM, RAG pipeline or AI agent?**: see "start here" below — what you are testing → which tools to call and which output field to gate CI on. IA-QA is the open testing workbench for the AI ecosystem — a dedicated platform for AI engineers who need real testing primitives, not just a chat window. Compare GPT-4o, Claude, Gemini, DeepSeek, and Grok side by side, test RAG pipelines, debug AI agents, test vector databases (Chroma, Qdrant, Pinecone, Weaviate, pgvector), explore MCP servers, benchmark LLM quality, and evaluate multimodal AI (CLIP Score, FID, VQA) — all from one privacy-first platform. 138 free tools, no account required. Many run entirely in your browser. The MCP server, `@ia-qa/cli` and some web tools (LangChain and LangGraph runs, VLM tests, Anthropic calls made through `/mcp/llm-proxy`) run on ia-qa.com's server, which receives what you send them, including your own provider key. ## Testing an LLM, RAG pipeline or AI agent with IA-QA — start here Pick what you are testing, call its tools — as MCP tools, or from a shell with `npx @ia-qa/cli ` — and act on the named output field. From an MCP client, `get_testing_guidelines` with no topic returns this same map; with the topic shown, the thresholds and pitfalls. **Order your assertions** 1. Deterministic first — exact rules, schema, regex, scans. Free, reproducible, and they fail correctly. 2. Semantic next — cosine / ROUGE against a reference answer, or invariance between phrasings. 3. An LLM judge last, only on what survived 1 and 2, and only as a gate once calibrated against human labels (Pearson r or Cohen's kappa ≥ 0.75), pinned model, temperature 0. **By goal** - **A prompt or chatbot answer is correct and well-formed** — `guardrail_test` · `llm_json_schema_check` · `run_semantic_tests` guardrail_test → all_passed · llm_json_schema_check → valid · run_semantic_tests → verdict (PASS/FAIL). tfidf mode is free; use embeddings mode (BYOK) when valid answers are paraphrases. (guidelines topic: `llm-unit-testing`) - **A repeatable suite of scenarios run against a real model** — `generate_eval_yaml` · `run_eval_contract` · `generate_ci_workflow` run_eval_contract → per-scenario PASS/FAIL. generate_ci_workflow with the eval_contract gate commits it to GitHub Actions (provider key as a repo secret). (guidelines topic: `eval-framework`) - **A RAG pipeline retrieves the right documents and answers from them** — `rerank_evaluate` · `hallucination_check` · `run_semantic_tests` Retrieval first: rerank_evaluate → PASS/FAIL on Precision@k / Recall@k. Then hallucination_check → verdict; needs_review means a specific in the answer is not in the context — it is never a pass. (guidelines topic: `rag-pipeline`) - **Answers stay stable across rephrasings and repeated runs** — `metamorphic_check` · `consistency_check` metamorphic_check → verdict (PASS/FAIL/INVALID; gate on the case and typo relations in tfidf mode; ready CI gate in generate_ci_workflow). consistency_check → verdict needs_review when figures differ between runs. Stability is not correctness: pair with run_semantic_tests. (guidelines topic: `prompt-stability`) - **Choose between two prompts or two models** — `compare_responses` · `ab_test_report` A decision, not a CI gate: compare_responses → verdict on two produced outputs; ab_test_report → winner over score arrays from the same test set. (guidelines topic: `prompt-ab-testing`) - **Guardrails: prompt injection, PII, leaked secrets, toxic output** — `prompt_injection_scan` · `redact_pii` · `secret_scan` · `toxicity_scan` · `shield_analyze` prompt_injection_scan → injection_detected · redact_pii → pii_found · secret_scan → secrets_found · toxicity_scan → overall_risk (lexical, not a semantic classifier) · shield_analyze → PASS/FIX/BLOCK on one response. prompt_injection_scan, secret_scan and toxicity_scan have ready CI gates in generate_ci_workflow. (guidelines topic: `security`) - **An AI agent calls the right tools with the right arguments** — `validate_agent_trajectory` · `function_call_validate` · `llm_json_schema_check` validate_agent_trajectory → verdict on declarative assertions over the trace (order, must_call, must_not_call, max_calls, no_error, recovery). function_call_validate / llm_json_schema_check → valid. (guidelines topic: `agent-observability`) - **A multi-turn conversation keeps its context** — `conversation_analyze` No verdict: context_retention and topic_drift are metrics. Track them as a trend, never as a gate. (guidelines topic: `llm-unit-testing`) - **A vision-language model reads images correctly** — `run_vlm_test_suite` · `run_vlm_test_suite_batch` run_vlm_test_suite → per-case PASS/FAIL and an overall PASS/WARNING/FAIL (BYOK). Include questions about objects absent from the image to measure hallucination. (guidelines topic: `multimodal`) - **An MCP server behaves as its schema says** — `mcp_server_evaluate` · `validate_mcp_response` · `mcp_schema_lint` mcp_server_evaluate → compliance report on a live URL; validate_mcp_response → checks on one tool result. (guidelines topic: `api-testing`) - **The E2E/UI tests of the app around the model keep working after a UI change** — `sandbox_scenario` · `diff_mappings` diff_mappings → PASS/FIX/BLOCK. Capturing pages needs the local @ia-qa/self-healing package; see the selector-drift topic. (guidelines topic: `selector-drift`) - **Put any of the above in CI** — `generate_ci_workflow` The generated workflow reads each tool's verdict field and fails the step. Do not gate on the CLI exit code alone: @ia-qa/cli exits non-zero only on an error, never on a finding. (guidelines topic: `ci-cd`) **Do not gate on** - response_quality_score — it scores only the criteria you pass (expected keywords, max length) and returns total_score null without them; keyword presence is not correctness. - prompt_test_suite — it writes a test plan and executes nothing. - An uncalibrated LLM judge — noise with a confident tone. **What leaves your machine**: Every IA-QA MCP tool, and @ia-qa/cli, runs on www.ia-qa.com: the outputs, contexts and traces you pass — and the provider key for BYOK tools — are sent there. Use synthetic or redacted data. @ia-qa/self-healing and @ia-qa/qa-discovery run locally instead. ## About Created by **Jean-Christophe Jamet**, QA Engineering Manager and AI practitioner with 10+ years of experience in software quality, test automation, and AI tooling. - **Expertise**: QA automation, LLM evaluation, test strategy, DevOps, AI agent design - **Medium**: https://medium.com/@jean-christophe.jamet (articles on QA, AI, LLMs) - **LinkedIn**: https://www.linkedin.com/in/jean-christophe-jamet-b043618a/ ## Quick Facts - The open testing workbench for the AI ecosystem - Compare LLMs side by side (GPT-4o, Claude, Gemini, DeepSeek, Grok, Ollama) - Test RAG pipelines, debug AI agents, explore MCP servers - 152 tools across 12 categories - Curated MCP Registry at https://www.ia-qa.com/mcp-registry — discover, evaluate and compare external MCP servers with QA scores - No account. Browser-only tools keep your data in the tab; the MCP server, `@ia-qa/cli` and the server-side tools receive what you send them - No account, no sign-up, no usage limits, free forever - MCP (Model Context Protocol) API available at `POST https://www.ia-qa.com/mcp` - Accessible from Cursor IDE, Claude Desktop, and Windsurf via MCP ## Who Is This For? - **QA Engineers**: bug severity classification, test case generation, regression risk scoring, LLM output consistency checking, prompt injection testing - **Developers**: JSON formatting, JWT debugging, API request building, hash generation, regex testing, SQL query building - **AI / LLM Practitioners**: prompt engineering, token counting, RAG chunk optimization, agent blueprint design, LLM evaluation, context window visualization - **Team Leads**: decision records, assumption surfacing, friction mapping, retrospective wheel, meeting timers - **Web Auditors**: Lighthouse-based site audits, Core Web Vitals (LCP, INP, CLS), SEO and accessibility checks ## Key Differentiators 1. **All-in-one AI workbench**: only platform combining an LLM API playground, multi-model comparison, RAG testing, vector DB testing, agent debugging, and MCP exploration in one place 2. **Privacy stated per surface**: browser-only tools process data locally; the MCP server, the CLI and the server-side tools receive what you send them, including a bring-your-own-key provider key - **Multi-model comparison**: compare GPT-4o, Claude 3.7, Gemini 2.0, DeepSeek, Grok 2 (xAI), and Ollama (local) side by side with latency, cost, and token metrics. Auto-filters available models based on configured API keys — users only see models they can actually call 4. **QA depth**: purpose-built QA workflows, prompt injection testing, LLM consistency checking, regression risk scoring 5. **MCP-integrated**: callable from Cursor IDE, Claude Desktop, Windsurf via Model Context Protocol 6. **GEO-ready**: LLM Readability Analyzer and LLM.txt Generator help optimize content for AI search engines (ChatGPT, Perplexity, Google AI Overviews) ## Frequently Asked Questions **Q: How do I test an LLM, a RAG pipeline or an AI agent with IA-QA?** A: Start from what you are testing, not from the catalogue: the "start here" section above maps each goal (correct answers, RAG grounding, stability, guardrails, agent tool calls, vision models, MCP servers, CI) to the tools to call and the output field to gate on. Run deterministic checks first, semantic ones next, and an LLM judge last and only once calibrated. From an MCP client, `get_testing_guidelines` returns the same map, and `generate_ci_workflow` turns it into a GitHub Actions gate. **Q: Are all tools free?** A: Yes. All 152 tools are permanently free with no usage limits, no credit card, no account needed. **Q: Is user data safe?** A: It depends on the surface, and each one says what it sends. The MCP server and `@ia-qa/cli` run every tool on ia-qa.com's server, so whatever you pass to a tool is sent there, including a provider API key given to a bring-your-own-key tool. `@ia-qa/self-healing` and `@ia-qa/qa-discovery` run on your machine and send nothing to ia-qa.com. Web tools depend on the tool: many run entirely in your browser and the LLM Sandbox calls providers directly from it, while LangChain and LangGraph runs, VLM tests and Anthropic calls made through `/mcp/llm-proxy` send your key through ia-qa.com's server. **Q: What is GEO — Generative Engine Optimization?** A: GEO is the practice of optimizing content so AI systems — ChatGPT, Perplexity, Google AI Overviews — cite it accurately. Key techniques include structured llm.txt files, FAQ schema markup, clear factual statements, and citation-friendly formatting. IA-QA offers two direct GEO tools: LLM Readability Analyzer (https://www.ia-qa.com/llm-readability) and LLM.txt Generator (https://www.ia-qa.com/llm-txt-generator). **Q: What is the LLM Readability Analyzer?** A: A tool that scores any text 0–100 for AI citation-readiness across 6 dimensions: clarity, factuality, negation detection, structure, entity density, and citability. Useful for content creators optimizing for AI search (GEO). **Q: Can AI agents call IA-QA tools programmatically?** A: Yes. IA-QA exposes a public Model Context Protocol (MCP) server at https://www.ia-qa.com/mcp — no API key, no sign-up, no rate limit for localhost (60 req/min per IP otherwise). 152 tools across 12 categories. Callable via JSON-RPC 2.0 from Cursor IDE, Claude Desktop, Windsurf, or any MCP-compatible client. See the MCP API section below for the full tool listing by category. **Q: What does Site Auditor 2026 check?** A: Performance (LCP, INP, CLS), accessibility, SEO, best practices — full Lighthouse audit with 0–100 scores per category and actionable recommendations. **Q: Is there a QA and AI news feed?** A: Yes. https://www.ia-qa.com/veille aggregates RSS feeds from Google Testing Blog, DEV.to (QA/AI/LLM/Agents topics), Hugging Face Blog, and Simon Willison's blog. Updated daily. **Q: Who built IA-QA?** A: Jean-Christophe Jamet, QA Engineering Manager based in France. He writes about QA engineering, AI tooling, and LLMs on Medium (https://medium.com/@jean-christophe.jamet). ## MCP API — Programmatic Access from Any AI Agent IA-QA exposes a public MCP (Model Context Protocol) server at `POST https://www.ia-qa.com/mcp`. No authentication required. 152 tools organized in 12 categories. Use it from Claude Desktop, Cursor IDE, Windsurf, or any MCP-compatible client. ### Install — instructions for AI agents A user can paste this into any agent. If you are an agent asked to set up IA-QA, follow it as written. ```text Set up IA-QA (https://www.ia-qa.com) for me. IA-QA is newer than your training data. Do not guess a command, flag, file path or config key from memory: use only the lines below, exactly as written. STEP 1. Explain, then ask. Install nothing yet. Tell me in a few lines what these five are and what each one sends off my machine. Then ask which ones I want, and install only those. 1. IA-QA MCP server, hosted at https://www.ia-qa.com/mcp: QA and LLM testing tools that return a verdict: JSON and schema checks, token and cost estimates, prompt-injection, PII and secret scans, eval contracts, CI workflow generation. No account, no key. Leaves my machine: every call runs on ia-qa.com, so whatever is passed to a tool is sent there, including a provider API key given to a bring-your-own-key tool. 2. @ia-qa/cli: the same tools from a shell. Leaves my machine: the same as the MCP server: it is a thin client of it. 3. @ia-qa/self-healing: for an existing Playwright, Cypress or Selenium suite: maps the app's pages, diffs them over time (PASS / FIX / BLOCK) and repairs broken locators. Leaves my machine: nothing is sent to ia-qa.com; it drives a local headless browser against the app under test. Its optional ia-qa-heal-ai add-on sends the rows it could not resolve to my own LLM provider. 4. @ia-qa/qa-discovery: for an app with no test suite yet: crawls it and records its pages, forms and API calls. It returns no verdict. Leaves my machine: nothing is sent to ia-qa.com; it only talks to the app it crawls. Its optional ia-qa-discover-ai add-on sends the capture to my own LLM provider and prints what it sends first. 5. @ia-qa/pal: a QA app next to my team, opened from an icon on my desktop: it walks the app, maps every page, checks it and compares it with the last tour, then reports what broke, what needs a person and what it could not see. With my end-to-end suite declared, it proposes repairs to its selectors (never applies them) and, when asked, runs the suite once to name the pages it never visits. It is built on @ia-qa/self-healing and returns the same verdicts. Installing it installs @ia-qa/self-healing and @ia-qa/qa-discovery too, and its MCP server (ia-qa-pal) also answers every tool of theirs — pick it and the other two are included. Leaves my machine: nothing is sent to ia-qa.com; it drives a local headless browser against the app under test only, and runs my own test command only when I ask for it. Its tour calls no LLM; the discovery tools its MCP server includes (classify_app, plan_pages) send the capture to my own LLM provider, only when called. STEP 2. Find the client you are running in and use its lines only. Never mix two clients' formats. In a "merge" line, keep only the servers I picked. Claude Code hosted: claude mcp add --transport http ia-qa https://www.ia-qa.com/mcp local: claude mcp add ia-qa-heal -- npx -y -p @ia-qa/self-healing ia-qa-heal-mcp local: claude mcp add ia-qa-discover -- npx -y -p @ia-qa/qa-discovery ia-qa-discover-mcp local: claude mcp add ia-qa-pal -- npx -y -p @ia-qa/pal ia-qa-pal-mcp verify: claude mcp get ia-qa (it must print "Connected") Codex CLI hosted: codex mcp add ia-qa --url https://www.ia-qa.com/mcp local: codex mcp add ia-qa-heal -- npx -y -p @ia-qa/self-healing ia-qa-heal-mcp local: codex mcp add ia-qa-discover -- npx -y -p @ia-qa/qa-discovery ia-qa-discover-mcp local: codex mcp add ia-qa-pal -- npx -y -p @ia-qa/pal ia-qa-pal-mcp verify: codex mcp list shows it; only a tool call in a new session proves it connects Gemini CLI hosted: gemini mcp add -t http ia-qa https://www.ia-qa.com/mcp local: gemini mcp add ia-qa-heal npx -- -y -p @ia-qa/self-healing ia-qa-heal-mcp local: gemini mcp add ia-qa-discover npx -- -y -p @ia-qa/qa-discovery ia-qa-discover-mcp local: gemini mcp add ia-qa-pal npx -- -y -p @ia-qa/pal ia-qa-pal-mcp verify: gemini mcp list (it must print "Connected"; servers stay disabled in an untrusted folder) Claude Desktop hosted: not in a file. Settings → Connectors → Add custom connector, URL https://www.ia-qa.com/mcp. Tell me to do it; you cannot. file: ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows) merge: {"mcpServers":{"ia-qa-heal":{"command":"npx","args":["-y","-p","@ia-qa/self-healing","ia-qa-heal-mcp"]},"ia-qa-discover":{"command":"npx","args":["-y","-p","@ia-qa/qa-discovery","ia-qa-discover-mcp"]},"ia-qa-pal":{"command":"npx","args":["-y","-p","@ia-qa/pal","ia-qa-pal-mcp"]}}} verify: fully quit and relaunch it, then ask it to list its MCP tools Cursor file: .cursor/mcp.json (this project) or ~/.cursor/mcp.json (all projects) merge: {"mcpServers":{"ia-qa":{"url":"https://www.ia-qa.com/mcp"},"ia-qa-heal":{"command":"npx","args":["-y","-p","@ia-qa/self-healing","ia-qa-heal-mcp"]},"ia-qa-discover":{"command":"npx","args":["-y","-p","@ia-qa/qa-discovery","ia-qa-discover-mcp"]},"ia-qa-pal":{"command":"npx","args":["-y","-p","@ia-qa/pal","ia-qa-pal-mcp"]}}} verify: restart it, then ask it to list its MCP tools VS Code (GitHub Copilot, agent mode) file: .vscode/mcp.json merge: {"servers":{"ia-qa":{"type":"http","url":"https://www.ia-qa.com/mcp"},"ia-qa-heal":{"command":"npx","args":["-y","-p","@ia-qa/self-healing","ia-qa-heal-mcp"]},"ia-qa-discover":{"command":"npx","args":["-y","-p","@ia-qa/qa-discovery","ia-qa-discover-mcp"]},"ia-qa-pal":{"command":"npx","args":["-y","-p","@ia-qa/pal","ia-qa-pal-mcp"]}}} verify: restart it, then ask it to list its MCP tools Windsurf file: ~/.codeium/windsurf/mcp_config.json merge: {"mcpServers":{"ia-qa":{"serverUrl":"https://www.ia-qa.com/mcp"},"ia-qa-heal":{"command":"npx","args":["-y","-p","@ia-qa/self-healing","ia-qa-heal-mcp"]},"ia-qa-discover":{"command":"npx","args":["-y","-p","@ia-qa/qa-discovery","ia-qa-discover-mcp"]},"ia-qa-pal":{"command":"npx","args":["-y","-p","@ia-qa/pal","ia-qa-pal-mcp"]}}} verify: restart it, then ask it to list its MCP tools Any other MCP client: the hosted server is Streamable HTTP at https://www.ia-qa.com/mcp; each local server is stdio, with the command and args shown above. A chat with no shell and no file access: explain, give me the lines for my client, and do not say you installed anything. Rules for every client: - Keep "-p" in every npx line. Each package ships several binaries; without -p, npx stops with "could not determine executable to run". - Use https://www.ia-qa.com, with "www". The bare domain answers with a 301 redirect, and a POST that follows a 301 can arrive as a GET without its body. - Merge into an existing config file. Never remove a server that is already there. - If I picked @ia-qa/pal, add only its local server (ia-qa-pal): it already answers the ia-qa-heal and ia-qa-discover tools. Add those two servers only if I picked them without pal. - A client does not load a server added during the conversation: tell me to restart it before you test. STEP 3. Shell tools, only if I picked them. Nothing to install: - @ia-qa/cli: npx -y @ia-qa/cli list, then npx -y @ia-qa/cli --help before each tool you run. - @ia-qa/self-healing: npx -y -p @ia-qa/self-healing ia-qa-heal skill --print - @ia-qa/qa-discovery: npx -y -p @ia-qa/qa-discovery ia-qa-discover skill --print - @ia-qa/pal: npx -y -p @ia-qa/pal ia-qa-pal skill --print Each prints that package's agent instructions on stdout and installs nothing. Read the whole output before running any other command from that package: it carries the order the verbs go in, what each refusal means, and what you must never run. Do not skip it and work from --help — the flags are there, the reasons are not. Add "skill --install" instead of "--print" to drop the same file into .claude/skills/, so your next session has it without asking. STEP 3a. The QA app, only if I picked @ia-qa/pal. It is an application on my desktop, not only a command: - Which folder: the one holding my end-to-end tests, because pal reads them and proposes repairs to them. If my tests live in their own repository, that repository; if I have none yet, my app's folder. Ask me when it is not obvious. - In that folder: npm i -D @ia-qa/pal. It brings @ia-qa/self-healing and @ia-qa/qa-discovery with it, and it stays there, unlike npx's cache, so the icon below keeps working. If the folder has no package.json, ask me before creating one with npm init -y. - Then: npx -y -p @ia-qa/pal ia-qa-pal ui --shortcut. It puts an icon named "ia-qa-pal — " on my desktop and returns at once; tell me where it is. - Then tell me the app is ready: I double-click the icon (or type npx ia-qa-pal in that folder), the page asks where my app lives and how it logs in, and starts the first tour from a button. Do not run that bare command yourself: without a terminal it only prints the help. If I would rather you do it for me, go on with STEP 3b. - If any command says "No usable browser found", ask me before running npx playwright install chromium: it downloads about 150 MB from Playwright's servers. STEP 3b. Set my project up. Ask me, never guess: - Where my app lives (the URL I would type in a browser). - How it logs in: none, by hand in a browser, or a storageState file my suite already writes (then ask for its path). - Where my end-to-end tests are, if I have any: a folder inside the project. Skip it rather than guess a folder. Then, with my answers: npx -y -p @ia-qa/pal ia-qa-pal setup --url --login --yes (add --tests when I have tests). Then npx -y -p @ia-qa/pal ia-qa-pal tour --background and follow it with npx -y -p @ia-qa/pal ia-qa-pal status. Report its "Not seen" section as well as its verdict: a first tour is a baseline, never a pass. Never apply the repairs it proposes without my review, and never add --suite (it runs my whole test suite) without asking me. Through MCP the same steps are pal_project, pal_setup, pal_tour and pal_status. If I chose "by hand in a browser", give me the login command to run myself and wait. You cannot log in for me. STEP 3c. An LLM provider key, ONLY if I ask for the optional AI layers (ia-qa-heal-ai, ia-qa-discover-ai). Everything else works without one. - Ask me which provider I have a key for: anthropic, openai, google, or openai-compatible. That last one is a shape, not a vendor: DeepSeek, Groq, Mistral, OpenRouter, Together, vLLM and Ollama all serve the same endpoint, and it needs a "baseUrl" in the config. A localhost baseUrl means the call never leaves my machine. Never pick one for me. - Preferred: tell me to store it in my machine's credential store, which keeps it out of the environment every process you launch inherits. I run it myself, in my own terminal — it asks for the value and refuses a pipe or an argument: npx -y -p @ia-qa/self-healing ia-qa-heal secret set . Then the reference is {"source": "keychain", "key": ""}. You can confirm it resolves without ever seeing it: npx -y -p @ia-qa/self-healing ia-qa-heal secret check . There is no command that prints a stored value, and you must not look for one. - Otherwise, or in CI where no store exists: ask me to export the key in my own shell and tell you only the VARIABLE NAME, then use {"source": "env", "key": ""}. Do not ask me to paste the key, and if I paste it anyway, tell me to rotate it. - Either way, write only the reference into the config, never the value: {"ai": {"provider": "", "model": "", "apiKey": {"source": "", "key": ""}}} - These CLIs read the environment only and never load .env files. If my key lives in .env, prefix the command with npx dotenv-cli -- - Run the verb with --dry-run first and show me exactly what it would send, and to whom, before any real call. A key in a config file is a leaked credential: the file is committed. The CLI refuses a key-shaped value there, and that refusal is not something to work around. STEP 4. Prove it, do not claim it. Run the verify line for my client, or call the find_tool tool with {"query": "json"} and show me what it returns. For the CLI, run npx -y @ia-qa/cli generate_uuid and show the output. Then give me two lists: what you checked by running it, and what you could not check, with the reason. Nothing in the second list counts as installed. STEP 5. Use it on my project. Once a tool call works, call get_testing_guidelines with no topic (from a shell: npx -y @ia-qa/cli get_testing_guidelines). It maps what is being tested to the tools to call and the output field to gate CI on. Ask me what I am testing. Propose the tools for it and the output field each verdict is read from, then run them on my real outputs. Before each call, tell me in one line what you are about to send to ia-qa.com. Use synthetic or redacted data unless I say otherwise. Report each verdict as the tool returned it. Never state a verdict a tool did not give. If my client needs a restart before the server loads, give me one sentence to paste in the new session to resume at this step. Never run these yourself: ia-qa-heal login, ia-qa-heal ui, ia-qa-discover login, ia-qa-pal ui (ia-qa-pal ui --shortcut is the exception: it only writes the desktop icon and returns). Each one waits for a person at a browser; give me the command instead. Never write an API key into a config file or into any file that gets committed. ``` ### CLI — Shell Access for Terminal Agents For AI agents with shell access (Claude Code, Copilot CLI) or humans scripting a pipeline, the same 152 tools are available as a zero-dependency CLI published on npm as `@ia-qa/cli` (Node >= 18, no signup, no API key). It discovers tools from the public manifest and runs them on the hosted server. - **Install**: `npx @ia-qa/cli ` or `npm install -g @ia-qa/cli` or download `https://www.ia-qa.com/downloads/ia-qa-cli.zip` and run `node ia-qa.js ` - **Discover**: `ia-qa --help` · `ia-qa list [--category ]` · `ia-qa --help` - **Run**: `ia-qa generate_uuid --count 3` · `ia-qa base64_encode "hello"` · `echo '{"a":1}' | ia-qa format_json --stdin` - **Output**: `--json` for machine-parsable JSON, `--out ` to write to a file (large outputs auto-write to a temp file) - **Multiline values**: `---file ` reads any param from a file (e.g. `--inputs-file fields.txt`) — multiline-safe; prefer it under `npx` on Windows, where args are truncated at the first newline - **Server**: `--server ` / `$IAQA_SERVER` to target a self-hosted ia-qa server (default `https://www.ia-qa.com`) ### Tool Categories #### 📊 Data Tools - `format_json` — Validate and pretty-print a string that is ALREADY valid JSON - `parse_csv` — Parse a CSV string into a JSON array of objects (or raw arrays) - `flatten_json` — Flatten a nested JSON object to single-level dot-notation keys (e.g. a:b:1 → a.b:1), or unflatten dot-notation keys back to a nested object - `xml_to_json` — Convert an XML string to a JSON object - `transform_json_array` — Transform a JSON array using common operations: pluck (extract specific fields), filter (by field value), sort_by (field), group_by (field), count_by (field), uniq_by (field) - `json_to_csv` — Convert a JSON array of objects to CSV format - `json_diff` — Compute a deep structural diff between two JSON values - `merge_json` — Deep merge two JSON objects - `json_to_yaml` — Convert a JSON object to clean, human-readable YAML - `json_schema_validate` — Validate a JSON value against a JSON Schema (draft-07 subset) - `mock_from_schema` — Generate realistic mock data from a JSON Schema - `extract_json_path` — Extract a value from a JSON string using dot-notation path (e.g., user.address.city, items.0.name, meta.tags) - `generate_json_ld` — Generate a ready-to-paste