- Scans
- Lancer un scan
- Gérer les identifiants de test
Manage test credentials
Test credentials are stored logins, headers, certificates and scripts that Ostorlab uses to sign in to your target during a scan. A scan uses the credentials you select when you create it, or that a CI job or schedule passes to it.
Credential types
Every type also has an optional label, which is the credential name. Use it to tell credentials apart. A label can have up to 250 characters.
| Type | Fields | Use it for |
|---|---|---|
| Login & Password | Login, Password, URL, optional Role | A sign-in form with a username and a password. The URL is the login page of a web application. It is optional for mobile scans. |
| Basic Authentication | Login, Password | Targets that use the HTTP Basic Authentication scheme. |
| Certificates | A TLS/SSL client certificate | Mutual TLS. For mobile applications, the certificate must be in the PEM format. |
| Script | A Puppeteer script | Complex sign-in flows and interactions such as checkout. |
| Custom | Name and value pairs | Custom form fields, such as username, password and domain name. |
| HTTP Header | The name and value of one header | Headers such as Authorization, User-Agent or X-API-KEY, commonly used by APIs. |
| 2FA SMS | Sender Phone Number | A sign-in that sends a one-time code by SMS. |
| 2FA Email | Email Sender, and the email address and password of the test mailbox | A sign-in that sends a one-time code by email. |
| 2FA TOTP | TOTP Secret | A sign-in that uses an authenticator app. |
| 2FA Manual | Sender | Any other code. The scan pauses until you enter it. |
Set the Role of a Login & Password credential through the API or the CI integrations. The web application does not offer it.
You can no longer create Email, Credit card, Phone Number or Address credentials.
Create and edit credentials
| Where | How |
|---|---|
| Test Credentials menu | Go to Scan > Test Credentials > New. Choose a type, fill in the fields and save. |
| While you create a scan | In the Set scan credentials step, click Add Test Credentials. Choose a type, fill in the fields and save. |
| GraphQL API | createTestCredentials, updateTestCredentials, deleteTestCredentials and the testsCredentials query. See API. |
| MCP server | list_test_credentials, create_test_credential, update_test_credential and delete_test_credential. See MCP Server. |
| CI | --test-credentials-login, --test-credentials-password, --test-credentials-url, --test-credentials-role, --test-credentials-name, --test-credentials-value, --sms-2fa-sender, --email-2fa-sender-email-address, --email-2fa-email-address, --email-2fa-password and --totp-2fa-seed. See CI scan options. |
Rules for stored credentials:
- To create, update or delete a credential, the API key or user needs the write action. The User and Admin roles have it. Listing needs the read action. See Choose a role.
- An update must keep the credential type.
- Through MCP, an update replaces every field. Fields you leave out are cleared, including the label. Pass the current value of anything you want to keep.
- Creating a credential that matches an existing one returns the existing credential.
- A scan copies the credential values when you create it. Later edits and deletion do not change a scan that already exists.
- A monitoring rule and a rescan read the credential again each time they create a new scan. The new scan gets the values the credential has at that moment.
- Deleting a credential removes it from the monitoring rules that use it, and a rescan skips it. The scans they create afterwards run without it. To rotate a value, update the credential instead.
Select credentials in a scan
You can select several credentials in one scan.
| Scan | Where to select them |
|---|---|
| Authenticated web scan | The Set scan credentials step. Select one or more credentials or add new ones. See Authenticated Web Scan. |
| Mobile scan from the store or TestFlight | Choose the Full scan. The credentials step is optional. See Scan Mobile Application from the Store. |
| Web or mobile Deep Agentic Scan | The credentials step. Select or add credentials to enable authenticated testing. See Web Deep Agentic Scan and Mobile Deep Agentic Scan. |
| Mobile Shielding Scan | Step 4, Add Prompts & Test Credentials. See Mobile Shielding Scan. |
| Multi Asset Scan | The Test Credentials step. The credentials apply to every asset in the scan. See Run a Multi Asset Scan. |
| Mobile application monitoring rule | The Select Test Credentials step. See Whitelisting domains in mobile application monitoring rules. |
| API | The credentialIds list of the create-scan mutation. See API. |
For a login that asks for a code, select a 2FA credential next to the Login & Password credential.
Rules for each type
HTTP Header and user agent. To scan a web application with your own user agent, add an HTTP Header credential. Set the name to User-Agent and the value to the user agent you want. Select it in the Set scan credentials step. Add one credential for each header you need to send.
mutation CreateTestCredentials($credentials: TestCredentialsInput!) {
createTestCredentials(testCredentials: $credentials) {
testCredentials {
... on TestHeaders {
id
credentialName
testHeaders {
name
value
}
}
}
}
}
{
"credentials": {
"credentialName": "Custom User Agent",
"testHeaders": {
"testHeaders": [
{ "name": "User-Agent", "value": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36" }
]
}
}
}
HTTP Header and API keys. If the target API expects a key in a header, add an HTTP Header credential. Set the name to the header the API expects, for example X-API-KEY, and the value to the key.
2FA SMS.
- Ask Ostorlab Support for a dedicated testing phone number. Set it on the test account.
- Enter the number that your application sends the codes from as the Sender Phone Number. It must match the number shown on the device when a code arrives.
2FA Email.
- Enter the address your application sends codes from as the Email Sender.
- Enable IMAP/SMTP access on the test mailbox.
- If the mailbox provider enforces 2FA, use an App Password, not the regular password.
2FA TOTP.
- Enable TOTP on the test account and keep the seed from the authenticator setup.
- Enter the Base32-encoded seed as the TOTP Secret. Ostorlab generates the codes, which refresh every 30 seconds.
2FA Manual.
- Enter a label such as
helpdeskas the Sender. - The scan pauses at the 2FA step. Open the scan details and enter the code to resume it.
Login & Password. Use a dedicated test account that does not lock out after failed logins.
Script. Generate the Puppeteer script with the Chrome DevTools Recorder, then upload it.
For the full 2FA procedures, see Two-Factor Authentication (2FA) for Automated Scans.