#144 · Multi-user authentication fallback
With Escape, you can now configure multiple authentication users and enable fallback mode.
Why this matters¶
At scale, teams may maintain several test users with identical permissions. All of them are valid on paper, but at scan time:
- One user may already have an active session
- Some users may be temporarily disabled or locked
- A user’s password may have been rotated
In those cases, authenticated DAST scans can fail simply because the selected user wasn’t valid when the scan ran, even though another equivalent user would have worked.
When scans are automated and run unattended, this leads to failed scans, retries, and manual intervention, wasting precious time of already quite stretched security teams.
Escape now takes care of selecting the working user for you.
With fallback enabled, Escape will attempt authentication using each configured user and proceed with the first one that succeeds. The scan then runs normally using that user.
This removes the need to decide in advance which specific user a scan should rely on.
How to set it up¶
-
Go to a dedicated scan profile
Create or open the scan profile where you want to enable authenticated scanning.
-
Open Settings → Authentication
This is where authentication behavior is configured for the scan.
-
Enable multi-user fallback
Turn on fallback mode by setting:
multi_user_is_fallback: true -
Configure multiple users using a Browser Agent preset
In your Browser Agent authentication preset, define all users that can be used interchangeably for the scan.
Here is a full setup example:
presets:
- type: browser_agent
users:
- password: user1
username: user1@test.com
- password: user2
username: user2@test.com
- password: user3
username: user3@test.com
- password: user4
username: user4@test.com
login_url: https://example.com/login
auto_extraction_urls: []
logged_in_detector_text: Login successful
multi_user_is_fallback: true
If only user3@test.com is active and valid, Escape will attempt authentication with user1@test.com (fails), then user2@test.com (fails), and finally user3@test.com (succeeds). The scan will then proceed using user3@test.com credentials.
Important limitation¶
Multi-user fallback cannot be used with tenant isolation testing.
Fallback mode runs the scan using a single authenticated user. If you need to test access boundaries between users, run separate scans per user and disable fallback.
This feature is designed to improve reliability of your DAST scans.
Use it when:
- You have multiple users with the same role
- Authentication failures occasionally block scans
- Scans run automatically (CI/CD, scheduled scans)
- You want scans to complete without manual retries
For more information on enabling fallback mode for multiple users, please refer to our documentation.