New: E2E testing on staging and production

Every user journey, mapped, tested and explained by AI.

Connect a GitHub repo. MerlinJourneys reads your code, finds every flow and endpoint, then walks each journey in a real browser on desktop and mobile, circling every click and explaining every bug it meets.

No credit card. No test scripts. Pay only for the tokens you use.

LandingSign upChoose planCheckoutSuccess
staging.acme.app/checkout
Pay now3
HighBug · E2E test
Checkout fails with a discount code

POST /api/orders returns 500 after “Pay now”. The total is computed before the coupon is applied, so the price is nil.

Desktop + mobile
screenshots of every step
Every endpoint
mapped from your code
Zero scripts
to write or maintain
Read-only
mode for production

Built for the AI era

Code now ships faster than anyone can click through it.

AI writes features in minutes. Knowing that sign-up still works, that checkout survives a coupon, that the mobile menu opens, still takes hours of clicking. MerlinJourneys gives that time back: it understands the code, uses the product like a person would, and tells you, in plain words, what it saw.

How it works

From repository to verdict in four steps

  1. 01

    Connect GitHub

    Link a repository with a read-only token. Pick any branch, from main to the feature you merged an hour ago.

  2. 02

    Merlin reads the code

    Routes, pages, controllers and API handlers become a map of every user journey and every endpoint.

  3. 03

    It tests the live app

    On staging, sandbox or production, a real browser walks each journey on desktop and mobile.

  4. 04

    Your team sees everything

    Annotated screenshots, pass or fail per journey, and every bug explained with a fix.

Features

Everything your team needs to trust a release

Journey storyboards

See every flow the way your users do

Each journey becomes a storyboard: the screen, the element being used circled and numbered, a short comment on what happens, and the same step on a phone right next to it. Product, design and engineering finally look at the same thing.

  • Desktop 1440 px and mobile 390 px side by side
  • Every click, tap and form entry annotated
  • Where the user ends up, captured at the end
Journey · Sign up and onboarding
  1. 1
    Click “Start free”
    The visitor opens sign-up from the hero.
  2. 2
    Type “Email”
    Inline validation appears as they type.
  3. 3
    Click “Create account”
    They land on the onboarding checklist.

End-to-end testing

A QA engineer that never gets tired of clicking

Merlin compares what the app does with what the code promises. Console errors, JavaScript crashes and failed requests are recorded on the exact step they happen, and every journey ends with a clear verdict.

  • Passed, failed or blocked for every journey
  • Console and network errors tied to the screen
  • Runs on any branch, against any environment
Run #128 · staging · feature/billing
Sign up and onboardingpassed
Upgrade to Profailed
Invite a teammateblocked
Reset passwordpassed
[desktop] Failed request: POST /api/subscriptions returned 422
[mobile] JavaScript crash: Cannot read properties of undefined (reading 'plan')

Endpoint map

Every API endpoint, found and checked

Rails routes, Next.js handlers, Express, Django, OpenAPI: Merlin lists every endpoint with its handler and whether it needs a login. A safe smoke test calls the GET endpoints to catch server errors, slow responses and data served without authentication.

  • Method, path, handler and auth for each endpoint
  • GET-only smoke test, nothing is ever changed
  • Calls the app makes that the code map does not explain
Endpoints · 42 mapped · 18 smoke tested
GET/api/projects200112 ms
POST/api/projectsskipped
GET/api/reports/export5002.1 s
GET/api/admin/users200no auth!
DELETE/api/projects/:idskipped

Bugs, explained

Not just what broke, but why, and how to fix it

Every issue comes with severity, evidence and a suggested fix, written for a person who did not watch the test. Code-level risks like missing authorization checks are flagged too, before they reach production.

  • Severity, category, evidence and fix
  • Linked to the exact screenshot
  • Security and performance risks from the code
Issues · 1 critical · 2 high
CriticalsecurityAPI smoke test
GET /api/admin/users returns data without logging in

The code marks this endpoint as admin-only, but an anonymous request received the full user list. Anyone who finds the URL can read customer emails.

Suggested fix: add the admin check to Admin::UsersController and return 401 for anonymous requests.

Safe on production

Read-only mode blocks every request that would change data. The smoke test only sends GET. Tests stop before payments, deletions and messages.

Secrets stay secret

Tokens and test passwords are encrypted. The AI types a placeholder and the server fills in the real password, so the model never sees it.

Pay per token

No seats, no subscriptions. Every run shows the tokens it used, and each journey is charged when it finishes.

Who it is for

One map of the product, for everyone who builds it

Product managers

See how users really move through the product, screen by screen, without asking engineering for a demo.

QA engineers

Get end-to-end coverage of every flow on every branch, without writing or maintaining a single script.

Founders and CTOs

Ship faster with AI-written code and still know that sign-up, checkout and onboarding work before customers find out.

Agencies and new hires

Understand an unfamiliar codebase in minutes: its journeys, its endpoints and where it is fragile.

Pricing

Start free. Pay only for what you run.

Starter

$9
500,000 tokens

Try it on a side project or a single app.

Pro

Most popular
$29
2,000,000 tokens

Weekly runs across a few repos and branches.

Scale

$119
10,000,000 tokens

Teams testing every release on staging.

Every new account starts with 200,000 free tokens. See pricing details

FAQ

Questions, answered

What does MerlinJourneys actually do?+

It connects to a GitHub repository, reads the code on the branch you choose and maps the user journeys and HTTP endpoints it finds. If you add a deployed environment, it then walks every journey in a real browser on desktop and mobile, takes annotated screenshots of each step, checks that the app behaves as the code promises, and explains every problem it finds with a suggested fix.

Do I need to write tests or scripts?+

No. There is nothing to record or maintain. The AI derives the journeys from your code and decides how to click through the live app, the way a careful QA engineer would. Run it again on a new branch and it adapts to what changed.

Is it safe to run against production?+

Yes. Production environments are read-only by default: the browser blocks every request that would change data, except signing in, and the API smoke test only ever sends GET requests. Tests stop before payments, deletions or messages to real people. For full end-to-end flows we recommend a staging or sandbox environment.

What do the screenshots show?+

For every step you get a desktop and a mobile screenshot with the element being clicked circled and numbered, a short comment on what the user does there, and any console errors, crashes or failed requests the browser recorded. The last screen shows where the user ends up.

Which frameworks and languages are supported?+

Any web app in a GitHub repository. MerlinJourneys reads routes, pages, controllers and API handlers in frameworks such as Rails, Next.js, React, Vue, Django, Laravel, Express and Go, and uses OpenAPI specs when they exist. Live testing works on anything that runs in a browser.

How does pricing work?+

You pay for the AI tokens a run uses, nothing else. New accounts get 200,000 tokens free. After that you buy token packages, and every run shows exactly how many tokens it used. Code analysis alone is inexpensive; full E2E testing with screenshots uses more because the AI looks at every screen.

What happens to my code and credentials?+

Your GitHub token and test account passwords are encrypted at rest. The AI never sees test passwords: it types a placeholder and the server fills in the real value. Code is read only for the run you start, and repository access is read-only.

Can I test a specific branch or pull request?+

Yes. Every run is tied to a branch and its exact commit, with the date and environment, so you can compare a feature branch against main or keep a history of how each release behaved.

Let Merlin walk your app tonight.

Connect a repository in a minute and wake up to a map of every journey, with screenshots and a list of what to fix first.

Start free with 200,000 tokens