> For the complete documentation index, see [llms.txt](https://docs.didomi.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.didomi.io/tracker-and-vendor-discovery/tracker-and-vendor-discovery-domains/configure-tracker-and-vendor-discovery-xl-scan.md).

# Configure tracker and vendor discovery (XL Scan)

{% hint style="success" %}
**Access Type**: Compliance Report - Editor

**Premium Feature**: XL Scan
{% endhint %}

The Didomi tracker and vendor discovery (XL scan) is a tool that enables your organization to generate a comprehensive scan of your domain (up to 20,000 pages) and receive a GDPR compliance evaluation from a Didomi perspective. In this article, we will cover how to configure a tracker and vendor discovery (XL scan) for your organization.

{% hint style="warning" %}
**Note**: XL scan is a premium feature for your organization's Didomi account. Please contact your Didomi representative for more information.
{% endhint %}

Click **Tracker and Vendor Discovery** on the left-hand panel and select **Add Domain** on the subsequent page.

<figure><img src="/files/mX179GV1Xb51aSFcukJb" alt="" width="563"><figcaption></figcaption></figure>

Select **XL Scan** in the next modal.

<figure><img src="/files/vCb6Z0mG91eZIO0FLeOx" alt="" width="375"><figcaption></figcaption></figure>

Use the provided fields to input the following information:

<table><thead><tr><th width="223.666748046875">Field</th><th>Description</th></tr></thead><tbody><tr><td>Give this domain a recognisable name</td><td>Internal name used to identify the domain</td></tr><tr><td>Target domain</td><td>URL of the domain that will be scrapped by the Didomi bot for the tracker and vendor discovery<br><br><strong>Example</strong>: <code>https://demosite.com</code></td></tr><tr><td>Launched from</td><td>Select a country from which the Didomi bot scans. <br><br>Since the Didomi bot mimics an end-user's behavior (including the location from which the end-user accesses a domain), this field enables the Didomi bot to experience the CMP behavior targeted at end-users in a specific country. </td></tr><tr><td>Regulation</td><td>Select a regulation that the tracker and vendor discovery XL scan supports.</td></tr></tbody></table>

<figure><img src="/files/iXnu35fuPk7PFop6G1ZA" alt="" width="563"><figcaption></figcaption></figure>

When configuring the domain for an XL scan, your organization has the option to specify the pages to scan either via:

* [Auto page discovery](#auto-page-discovery)
* [Manual input](#manual-input)

<figure><img src="/files/2YgdfDtsLXBzAsY1sHHY" alt="" width="563"><figcaption></figcaption></figure>

#### Auto page discovery

Select the **Auto page discovery** card to enable the Didomi bot to automatically crawl pages (up to 20,000 pages) for the domain.

#### Manual input

Select the **Manual input** card to specify the exact URLs to scan and click **Download CSV template**.

<figure><img src="/files/O040KYctDie1aNfCaBt0" alt="" width="563"><figcaption></figcaption></figure>

The csv template will be downloaded onto your machine. Open the file and add the exact URLs that should be scanned by the Didomi bot. When finished, drag and drop the csv file into the provided space.

<figure><img src="/files/SkGjQHNna6rkQHKPDq4e" alt="" width="563"><figcaption></figcaption></figure>

For XL scans, your organization can select a **single** default or customized bot scenario to run for the scan.&#x20;

<table><thead><tr><th width="240.5333251953125">Bot scenario</th><th>Description</th></tr></thead><tbody><tr><td>Accept all</td><td>Will locate and click the action to accept all purposes from the first layer of the consent notice.</td></tr><tr><td>Refuse all</td><td>Will locate and click the action to reject all purposes from the first layer of the consent notice.</td></tr><tr><td>No actions</td><td>Will perform no actions on the consent notice and/or domain</td></tr><tr><td>Custom</td><td>Fully customized instructions for the bot to perform</td></tr></tbody></table>

{% hint style="info" %}
All bot scenarios can be customized with additional instructions when configuring a tracker and vendor discovery (XL scan). For example, your organization can add instructions in the case where your refuse all button is only present on the second layer of your consent notice or if your organization utilizes a multi-step login form for the domain being scanned.
{% endhint %}

<figure><img src="/files/OSfr1ctiKvAEBXsTjyoN" alt="" width="563"><figcaption></figcaption></figure>

Expand the accordion below for more information on customizing a bot scenario:

<details>

<summary>Tracker and vendor discovery (XL scan) - Customize bot scenario</summary>

In order to customize a bot scenario either expand the accordion for an existing scenario or click **Add scenario**.

<figure><img src="/files/FjmwXzkLEGPWGRHZv0P7" alt="" width="563"><figcaption></figcaption></figure>

When customizing a default or custom scenario your tracker and vendor discovery your organization can select four different instructions to give to the Didomi bot:

{% hint style="info" %}
The default scenarios **Accept All** and **Refuse All** that are provided by Didomi will always include an Accept and Refuse instruction, respectively. These actions can not be removed from the default scenarios.
{% endhint %}

<table><thead><tr><th width="257.13330078125">Instruction</th><th>Description</th></tr></thead><tbody><tr><td>Accept</td><td><p>Will locate and click the action to accept all purposes in the consent notice (either programmatically or via specified CSS selector)</p><div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><p><strong>Note</strong>: This instruction can only be included in a scenario once and will prohibit the use of the <strong>Refuse</strong> instruction in the same scenario.</p></div></td></tr><tr><td>Refuse</td><td><p>Will locate and click the action to refuse all purposes in the consent notice (either programmatically or via specified CSS selector).</p><div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><p><strong>Note</strong>: This instruction can only be included in a scenario once and will prohibit the use of the Accept instruction in the same scenario.</p></div></td></tr><tr><td>Click</td><td>Will click on the specified element (identified by the CSS selector).</td></tr><tr><td>Fill in</td><td>Will navigate to an input field (identified by the CSS selector) and input the configured text.</td></tr></tbody></table>

<figure><img src="/files/3Nzxh05b4kLHbNjOwLfv" alt="" width="563"><figcaption></figcaption></figure>

{% hint style="info" %}
For the **Click** and **Fill in** instructions, your organization can find the CSS selector by performing the following:

1. Navigate to your website and load your consent notice
2. Right-click the desired element on the consent notice where the Didomi bot should click (or insert text)
3. Select **Inspect** from the subsequent menu
4. The element should be highlighted in the Inspector. Right-click the highlighted item in the Inspector and select **Copy > Copy selector** (or **CSS Selector** depending on browser).
5. Repeat as necessary for elements that the Didomi bot will need to click in order to achieve the desired behavior.
   {% endhint %}

Review the table below for actions that can be taken when configuring a scenario:

<table><thead><tr><th width="211">Action</th><th>Description</th></tr></thead><tbody><tr><td>CSS selector</td><td>Enables your organization to direct the Didomi bot to identify an element and execute the desired action.</td></tr><tr><td>Label</td><td>Each instruction has an optional Label field where your organization can add an internal label to the instruction. This label can be useful in identifying the action taken in the tracker and vendor discovery results.</td></tr><tr><td>Reorder instructions</td><td>Use the provided arrows to the left of an instruction to order the instructions into the desired sequence.</td></tr></tbody></table>

</details>

Next, expand the **Compliance Recommendations** accordion to select/deselect the factors that will be used to calculate the Didomi rating for the domain.

{% hint style="info" %}
All factors are enabled by default and will be used to calculate the Didomi rating for your domain unless otherwise configured.
{% endhint %}

<figure><img src="/files/YVuZvBwiZB9sw5VmlDwB" alt="" width="563"><figcaption></figcaption></figure>

The Didomi tracker and vendor discovery (XL scan) utilizes a bot to scan your configured domains and extract the information relevant to your compliance with GDPR regulations. Defining a custom user agent provides extra security for your domain and eliminates the need to [whitelist the default user agent](https://docs.didomi.io/compliance-report/introduction/whitelist-compliance-report) utilized by the Didomi bot.

If required, expand the **Advanced** tab and use the **User agent** field to define a custom user agent (UA) that will be used by the Didomi bot while scanning.

<figure><img src="/files/KcN5tSbERzAfPfOMPmRf" alt="" width="563"><figcaption></figcaption></figure>

If required, expand the **Scan logged in environment** to configure instructions for the Didomi bot to access a domain that requires credentials.

{% hint style="info" %}
Didomi currently does not support two-factor authentication (2FA) scanning.
{% endhint %}

<details>

<summary>Tracker and vendor discovery (XL scan) - Scan logged in environment </summary>

In this section we will cover how to configure a tracker and vendor discovery (XL scan) for a:

* [Single-step (combined) login](#single-step-combined-login)
* [Multi-step login](#multi-step-login)

#### Single-step (combined) login

If the login form used by the domain is a traditional login form where the credentials are collected and submitted in a single interaction then your organization can utilize the **Scan logged in environment** feature.&#x20;

From the expanded the **Scan logged in environment** accordion enable the checkbox for **Scan logged environment**.

<figure><img src="/files/v9WkUeNxc81EzIMVCK2q" alt="" width="563"><figcaption></figcaption></figure>

Your organization will be prompted to input required credentials and/or optional CSS selectors to aid the Didomi bot in accessing the domain and performing its XL scan.&#x20;

<table><thead><tr><th width="171">Field</th><th width="106.5" data-type="checkbox">Required</th><th>Description</th></tr></thead><tbody><tr><td>Login page URL</td><td>true</td><td>Login form where URL is present</td></tr><tr><td>Username</td><td>true</td><td>Username that will be used by the Didomi bot to log into your website</td></tr><tr><td>Password</td><td>true</td><td><p>Password associated with the username that will be used by the Didomi bot to log into your website</p><div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><p><strong>Note</strong>: The password is encrypted by Didomi to avoid causing any security breaches.</p></div></td></tr><tr><td>Username CSS selector</td><td>false</td><td>The Didomi bot will automatically attempt to insert the username when accessing your website. Your organization can directly configure the Didomi bot's actions when selecting and inserting the username by giving it the CSS selector of the appropriate field. See the hint below for how to find the CSS selector</td></tr><tr><td>Password CSS selector</td><td>false</td><td>The Didomi bot will automatically attempt to insert the password when accessing your website. Your organization can directly configure the Didomi bot's actions when selecting and inserting the password by giving it the CSS selector of the appropriate field. See the hint below for how to find the CSS selector</td></tr><tr><td>Submit button CSS selector</td><td>false</td><td>The Didomi bot will automatically attempt to click the submit button after inserting the username and password when accessing your website. Your organization can directly configure the Didomi bot's actions when selecting the submit button by giving it the CSS selector of the appropriate field. See the hint below for how to find the CSS selector</td></tr></tbody></table>

{% hint style="info" %}
Your organization can find the CSS selector by performing the following:

1. Navigate to your website&#x20;
2. Right-click the desired element in the login form where the Didomi bot should click (or insert text)
3. Select **Inspect** from the subsequent menu
4. The element should be highlighted in the Inspector. Right-click the highlighted item in the Inspector and select **Copy > Copy selector** (or **CSS Selector** depending on browser).
5. Repeat as necessary for elements that the Didomi bot will need to click in order to achieve the desired behavior.
   {% endhint %}

<figure><img src="/files/vtZMkTHy0iv6HaUqQrHL" alt="" width="563"><figcaption></figcaption></figure>

#### Multi-step login

If the login form used by the domain is a multi-step form where end-users provide credentials in separate steps (such as the identifier-first login used by Google or Microsoft) then your organization will need to manually customize the scenario in the tracker and vendor discovery (XL scan).

{% hint style="warning" %}
**Note**: When configuring a scan for a domain that utilizes a multi-step login, do not enable the **Scan logged in environment** feature.

Additionally, please be aware that Didomi does not provide password encryption Didomi-side for multi-step login forms.
{% endhint %}

Before continuing your organization will need to retrieve the CSS selectors for each element the Didomi bot will interact with when logging into your domain.

1. Navigate to your website&#x20;
2. Right-click the desired element in the login form where the Didomi bot should click (or insert text)
3. Select **Inspect** from the subsequent menu
4. The element should be highlighted in the Inspector. Right-click the highlighted item in the Inspector and select **Copy > Copy selector** (or **CSS Selector** depending on browser).
5. Repeat as necessary for elements that the Didomi bot will need to click in order to achieve the desired behavior.

<figure><img src="/files/1L9jtqfjqBPo1xDemjxQ" alt="" width="563"><figcaption></figcaption></figure>

With the CSS selectors copied, expand the accordion for the scenario used in the tracker and vendor (XL scan) and utilize the **Add an instruction** tools to select the first step in the login flow.

<img src="https://docs.didomi.io/~gitbook/image?url=https%3A%2F%2F1825037175-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FNDxbAdc00ce6bH5u1urh%252Fuploads%252FuMbcdw93uuHLuYmqi8YS%252FScreenshot%25202026-01-12%2520at%25206.18.36%25E2%2580%25AFAM.png%3Falt%3Dmedia%26token%3D1d8b6fce-49f2-4406-b24c-ea7f30022feb&#x26;width=768&#x26;dpr=3&#x26;quality=100&#x26;sign=402c9933&#x26;sv=2" alt="" width="563">

Depending on the instruction selected, your organization will need to input the following:

<table><thead><tr><th width="138.5">Instruction</th><th>Required fields</th></tr></thead><tbody><tr><td>Click</td><td><ul><li>CSS selector</li></ul></td></tr><tr><td>Fill in</td><td><ul><li>Text to input into the field for your login form</li><li>CSS selector of the field where an end-user inputs the text</li></ul></td></tr></tbody></table>

<img src="https://docs.didomi.io/~gitbook/image?url=https%3A%2F%2F1825037175-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FNDxbAdc00ce6bH5u1urh%252Fuploads%252FTJXzUT6cYnnhNEm6zqXF%252FScreenshot%25202026-01-12%2520at%25206.30.11%25E2%2580%25AFAM.png%3Falt%3Dmedia%26token%3D6e16b807-0206-49b6-911b-36b4a111ef4c&#x26;width=768&#x26;dpr=3&#x26;quality=100&#x26;sign=4df5512f&#x26;sv=2" alt="" width="563">

Repeat as necessary to reproduce the sequential steps needed to successfully login. When finished, use the provided arrows to ensure that the login steps precede any actions performed for the consent notice.

<img src="https://docs.didomi.io/~gitbook/image?url=https%3A%2F%2F1825037175-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FNDxbAdc00ce6bH5u1urh%252Fuploads%252FWS6ynQ3xJF2rT3Vskvyj%252FScreenshot%25202026-01-12%2520at%25206.36.15%25E2%2580%25AFAM.png%3Falt%3Dmedia%26token%3Dfb0d2593-7c54-4e0f-80bf-687dbaf65c47&#x26;width=768&#x26;dpr=3&#x26;quality=100&#x26;sign=87860294&#x26;sv=2" alt="" width="563">

</details>

<figure><img src="/files/wbYjVAL2tSXuYKXBv3DQ" alt="" width="563"><figcaption></figcaption></figure>

Confirm that you own the domain or acting on behalf of the domain owner to run the discovery and click **Save & Run Discovery** when finished.&#x20;

<figure><img src="/files/AFXSPaKZTL61Bw8w4Zi1" alt="" width="563"><figcaption></figcaption></figure>

Once successfully added, Didomi will run a discovery for the domain. Once the discovery is complete, the scan will be annotated with a **Discovery Complete** label.

Click **Details** inline with the tracker and vendor discovery (XL scan).

<figure><img src="/files/4Ov2NRKUaeJgckiSICNp" alt="" width="563"><figcaption></figcaption></figure>

The following page provides details about the discovery and allows your organization view a recording of how the Didomi bot interacted with your domain and download a list of discovered pages.

Generate the tracker and vendor discovery (XL scan) by clicking **Run XL** scan

<figure><img src="/files/j0EbueN2AT2RQZV1Adpp" alt="" width="563"><figcaption></figcaption></figure>

A subsequent modal will relay the number of XL scans contracted for by your organization, the number of XL scans used, and remaining scans.

Click **Proceed with Scan**.&#x20;

<figure><img src="/files/DqANMMC2mqByF5NYoTDm" alt="" width="375"><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.didomi.io/tracker-and-vendor-discovery/tracker-and-vendor-discovery-domains/configure-tracker-and-vendor-discovery-xl-scan.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
