Free while in beta

Find out what breaks in your visitors' browsers.

Every modern browser notices when something on your site goes wrong — a script gets blocked, a page crashes, code stops being supported. It writes a report and looks for somewhere to send it. for.duty is that somewhere.

No credit card, no script on your site.

Browsers already do the work

When a script is blocked or a page crashes, the browser writes a report. With nowhere to send it, that report is thrown away.

Real visits, real devices

These reports come from people actually using your site — not from a test run in a lab.

Nothing to install

No SDK, no JavaScript, no tracking script. Two response headers and you are collecting.

Why it is worth having

Hear about problems before your users tell you

Broken pages report themselves, the moment they break, from the browser that saw it happen.

See it when something injects itself into your site

Blocked scripts are exactly what a Content-Security-Policy stops — and every one of them is reported.

Know when a third party breaks your site

Analytics, embeds and widgets fail quietly. The browser still notices, and still reports it.

Get warned before browsers remove things

Deprecation reports arrive while there is still time to act, not after an update breaks your site.

How it works

  1. 1

    Create a project. You get your own endpoint address.

  2. 2

    Add two headers to the responses your site already sends.

  3. 3

    Watch the reports arrive, grouped per project, with the page, the browser and what went wrong.

Reporting-Endpoints: default="https://in.forduty.app/YOUR-TOKEN"

Content-Security-Policy: …; report-to default

What gets collected

Browsers report far more than blocked scripts. for.duty accepts every kind of report they send.

Blocked scripts and styles
Deprecated code
Browser interventions
Page crashes
Cross-origin isolation (COEP)
Cross-origin isolation (COOP)
Integrity failures
Permissions policy violations
Network errors
Document policy violations

Built for teams

Invite your colleagues, keep every site in its own project, and get told in the app and by email when new reports land.

Common questions

Will it slow my site down?

No. There is no script on your page. Browsers send the reports themselves, in the background, after the page has loaded.

Do I have to change my code?

No. You add two response headers. Nothing about your pages changes.

What ends up in a report?

The address of the page, what went wrong, and the browser's user-agent. Browsers never send cookies or credentials to a reporting endpoint on another domain.

Give your browsers somewhere to report to.

Create a project, paste two headers, and see what your visitors have been running into.

Start free

Free while in beta, no payment details needed.