跳转至

Manage test credentials

Test credentials are stored logins, headers, certificates and scripts that Ostorlab uses to sign in to your target during a scan. A scan uses the credentials you select when you create it, or that a CI job or schedule passes to it.

Credential types

Every type also has an optional label, which is the credential name. Use it to tell credentials apart. A label can have up to 250 characters.

Type Fields Use it for
Login & Password Login, Password, URL, optional Role A sign-in form with a username and a password. The URL is the login page of a web application. It is optional for mobile scans.
Basic Authentication Login, Password Targets that use the HTTP Basic Authentication scheme.
Certificates A TLS/SSL client certificate Mutual TLS. For mobile applications, the certificate must be in the PEM format.
Script A Puppeteer script Complex sign-in flows and interactions such as checkout.
Custom Name and value pairs Custom form fields, such as username, password and domain name.
HTTP Header The name and value of one header Headers such as Authorization, User-Agent or X-API-KEY, commonly used by APIs.
2FA SMS Sender Phone Number A sign-in that sends a one-time code by SMS.
2FA Email Email Sender, and the email address and password of the test mailbox A sign-in that sends a one-time code by email.
2FA TOTP TOTP Secret A sign-in that uses an authenticator app.
2FA Manual Sender Any other code. The scan pauses until you enter it.

Set the Role of a Login & Password credential through the API or the CI integrations. The web application does not offer it.

You can no longer create Email, Credit card, Phone Number or Address credentials.

Create and edit credentials

Where How
Test Credentials menu Go to Scan > Test Credentials > New. Choose a type, fill in the fields and save.
While you create a scan In the Set scan credentials step, click Add Test Credentials. Choose a type, fill in the fields and save.
GraphQL API createTestCredentials, updateTestCredentials, deleteTestCredentials and the testsCredentials query. See API.
MCP server list_test_credentials, create_test_credential, update_test_credential and delete_test_credential. See MCP Server.
CI --test-credentials-login, --test-credentials-password, --test-credentials-url, --test-credentials-role, --test-credentials-name, --test-credentials-value, --sms-2fa-sender, --email-2fa-sender-email-address, --email-2fa-email-address, --email-2fa-password and --totp-2fa-seed. See CI scan options.

Rules for stored credentials:

  • To create, update or delete a credential, the API key or user needs the write action. The User and Admin roles have it. Listing needs the read action. See Choose a role.
  • An update must keep the credential type.
  • Through MCP, an update replaces every field. Fields you leave out are cleared, including the label. Pass the current value of anything you want to keep.
  • Creating a credential that matches an existing one returns the existing credential.
  • A scan copies the credential values when you create it. Later edits and deletion do not change a scan that already exists.
  • A monitoring rule and a rescan read the credential again each time they create a new scan. The new scan gets the values the credential has at that moment.
  • Deleting a credential removes it from the monitoring rules that use it, and a rescan skips it. The scans they create afterwards run without it. To rotate a value, update the credential instead.

Select credentials in a scan

You can select several credentials in one scan.

Scan Where to select them
Authenticated web scan The Set scan credentials step. Select one or more credentials or add new ones. See Authenticated Web Scan.
Mobile scan from the store or TestFlight Choose the Full scan. The credentials step is optional. See Scan Mobile Application from the Store.
Web or mobile Deep Agentic Scan The credentials step. Select or add credentials to enable authenticated testing. See Web Deep Agentic Scan and Mobile Deep Agentic Scan.
Mobile Shielding Scan Step 4, Add Prompts & Test Credentials. See Mobile Shielding Scan.
Multi Asset Scan The Test Credentials step. The credentials apply to every asset in the scan. See Run a Multi Asset Scan.
Mobile application monitoring rule The Select Test Credentials step. See Whitelisting domains in mobile application monitoring rules.
API The credentialIds list of the create-scan mutation. See API.

For a login that asks for a code, select a 2FA credential next to the Login & Password credential.

Rules for each type

HTTP Header and user agent. To scan a web application with your own user agent, add an HTTP Header credential. Set the name to User-Agent and the value to the user agent you want. Select it in the Set scan credentials step. Add one credential for each header you need to send.

mutation CreateTestCredentials($credentials: TestCredentialsInput!) {
  createTestCredentials(testCredentials: $credentials) {
    testCredentials {
      ... on TestHeaders {
        id
        credentialName
        testHeaders {
          name
          value
        }
      }
    }
  }
}
{
  "credentials": {
    "credentialName": "Custom User Agent",
    "testHeaders": {
      "testHeaders": [
        { "name": "User-Agent", "value": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36" }
      ]
    }
  }
}

HTTP Header and API keys. If the target API expects a key in a header, add an HTTP Header credential. Set the name to the header the API expects, for example X-API-KEY, and the value to the key.

2FA SMS.

  • Ask Ostorlab Support for a dedicated testing phone number. Set it on the test account.
  • Enter the number that your application sends the codes from as the Sender Phone Number. It must match the number shown on the device when a code arrives.

2FA Email.

  • Enter the address your application sends codes from as the Email Sender.
  • Enable IMAP/SMTP access on the test mailbox.
  • If the mailbox provider enforces 2FA, use an App Password, not the regular password.

2FA TOTP.

  • Enable TOTP on the test account and keep the seed from the authenticator setup.
  • Enter the Base32-encoded seed as the TOTP Secret. Ostorlab generates the codes, which refresh every 30 seconds.

2FA Manual.

  • Enter a label such as helpdesk as the Sender.
  • The scan pauses at the 2FA step. Open the scan details and enter the code to resume it.

Login & Password. Use a dedicated test account that does not lock out after failed logins.

Script. Generate the Puppeteer script with the Chrome DevTools Recorder, then upload it.

For the full 2FA procedures, see Two-Factor Authentication (2FA) for Automated Scans.