Using a session cookie or a token
1 min read
Why this option exists
A CAPTCHA, two-factor authentication or an OAuth-only login (Google, GitHub...) structurally cannot be automated by a scanner: no tool can solve that on your behalf, and that's not what we're trying to do. Pasting an already-open session sidesteps the problem cleanly.
Getting a session cookie
- 1Log in with your test account
In a normal browser window, not a private one: the cookie needs to exist in the browser's storage.
- 2Open dev tools (F12)
Application tab (Chrome/Edge) or Storage (Firefox) → Cookies → your app's domain.
- 3Copy the right cookie's value
The name depends on your stack: often `session`, `sb-access-token` (Supabase), or your auth framework's equivalent. Paste the value into the "cookie" field in the Active scan panel; multiple `name=value` pairs separated by `; ` are accepted if needed.
Or a bearer token
If your app uses a bearer token (JWT in localStorage, `Authorization` header), paste it in the "token" field instead of "cookie", under "Advanced options" in the Active scan panel.
The catch: it expires, and it isn't saved
Unlike a login/password, a pasted session is never saved for the automatic rescan: it expires, often within hours. Reliable for a one-off scan; for the authenticated weekly rescan, a real test account (email/password) is the only option that holds up over time.