Using a session cookie or a token

1 min read

Why this option exists

A CAPTCHA, two-factor authentication or an OAuth-only login (Google, GitHub...) structurally cannot be automated by a scanner: no tool can solve that on your behalf, and that's not what we're trying to do. Pasting an already-open session sidesteps the problem cleanly.

Getting a session cookie

  1. 1
    Log in with your test account

    In a normal browser window, not a private one: the cookie needs to exist in the browser's storage.

  2. 2
    Open dev tools (F12)

    Application tab (Chrome/Edge) or Storage (Firefox) → Cookies → your app's domain.

  3. 3
    Copy the right cookie's value

    The name depends on your stack: often `session`, `sb-access-token` (Supabase), or your auth framework's equivalent. Paste the value into the "cookie" field in the Active scan panel; multiple `name=value` pairs separated by `; ` are accepted if needed.

Or a bearer token

If your app uses a bearer token (JWT in localStorage, `Authorization` header), paste it in the "token" field instead of "cookie", under "Advanced options" in the Active scan panel.

The catch: it expires, and it isn't saved

Unlike a login/password, a pasted session is never saved for the automatic rescan: it expires, often within hours. Reliable for a one-off scan; for the authenticated weekly rescan, a real test account (email/password) is the only option that holds up over time.

Was this article helpful?