Expert Usage: Advanced Configuration and Control¶
Use expert YAML configuration to tune API testing. Open the profile settings, then Scan configuration > Expert, to edit it.
Expert Configuration¶
Configuration Guides¶
- Custom Payloads: Define custom scalar types and test values.
- Authentication: Configure authenticated scanning.
- API Scope: Select which operations are tested.
- Coverage: Diagnose endpoints that aren't reached or tested.
- Rate Limiting: Control API request frequency.
- Hotstart: Supply requests to initialize the scan.
- GraphQL Schema Retrieval: Retrieve a schema for testing.
Exploration Depth¶
Both rest_api_dast and graphql_api_dast support exploration_depth: light (fast), balanced (default) or deep (more exhaustive).
Both also support explore_with_all_users (default false) to explore once per authenticated user, and cross_user_memory_enabled (default false) to reuse extracted memory across users. in_scope_only (default false) disables extensive endpoint fuzzing outside the supplied specification, including checks for exposed .git or .env files. REST supports query_params_are_required (default false). GraphQL supports max_generated_depth (default 3) for generated query depth, and url to override the default endpoint URL.
The global profile preset accepts surface, cicd, default, deep or unrestricted. See the REST and GraphQL references for the full configuration.
Best Practices¶
- Start with default configurations
- Gradually introduce custom settings
- Test and validate each configuration change
- Monitor scan results and performance
Customization Flexibility
Use the configuration references to check field names and defaults before changing the expert YAML configuration.