Skip to content

#116 · MFA using Time-Based One-Time Passwords (TOTP) is now fully supported in our Web App Scanner

We are excited to announce that Multi-Factor Authentication (MFA) using Time-Based One-Time Passwords (TOTP) is now fully supported in our Web App Scanner!

The use of multi-factor authentication (MFA) significantly enhances identity security by introducing an additional layer of verification beyond traditional login credentials. While this strengthens protection against unauthorized access, it can present a challenge for most of the DAST tools since they are typically designed for unattended execution, where manual interaction – such as approving a sign-in request or entering a time-sensitive code – can disrupt the automation workflow.

With the new support for TOTP-based MFA, Escape’s DAST scanner is now fully equipped to handle these scenarios. You can securely test web applications protected by MFA without needing manual intervention during the scanning process. This means you can automate the security testing of applications that require MFA, ensuring comprehensive coverage while maintaining a streamlined workflow.

Getting started is easy! Just use the Browser Agent authentication preset. Here's an example setup:

presets:
-   type: browser_agent
    login_url: https://auth.example.com/login
    users:
    -   username: frontend-user-with-totp@example.com
        password: pass
        post_login_actions:
        -   action: fill_totp
            auto_submit: true
            locator: input[id="totp-input"]
            secret: '123456'

Learn how to configure this preset for your needs in our documentation!