Skip to content

#144 · Multi-user authentication fallback

With Escape, you can now configure multiple authentication users and enable fallback mode.

Why this matters

At scale, teams may maintain several test users with identical permissions. All of them are valid on paper, but at scan time:

  • One user may already have an active session
  • Some users may be temporarily disabled or locked
  • A user’s password may have been rotated

In those cases, authenticated DAST scans can fail simply because the selected user wasn’t valid when the scan ran, even though another equivalent user would have worked.

When scans are automated and run unattended, this leads to failed scans, retries, and manual intervention, wasting precious time of already quite stretched security teams.

Escape now takes care of selecting the working user for you.

With fallback enabled, Escape will attempt authentication using each configured user and proceed with the first one that succeeds. The scan then runs normally using that user.

This removes the need to decide in advance which specific user a scan should rely on.

How to set it up

  • Go to a dedicated scan profile

    Create or open the scan profile where you want to enable authenticated scanning.

  • Open Settings → Authentication

    This is where authentication behavior is configured for the scan.

  • Enable multi-user fallback

    Turn on fallback mode by setting: multi_user_is_fallback: true

  • Configure multiple users using a Browser Agent preset

In your Browser Agent authentication preset, define all users that can be used interchangeably for the scan.

Here is a full setup example:

presets:
  - type: browser_agent
    users:
      - password: user1
        username: user1@test.com
      - password: user2
        username: user2@test.com
      - password: user3
        username: user3@test.com
      - password: user4
        username: user4@test.com
    login_url: https://example.com/login
    auto_extraction_urls: []
    logged_in_detector_text: Login successful
multi_user_is_fallback: true

If only user3@test.com is active and valid, Escape will attempt authentication with user1@test.com (fails), then user2@test.com (fails), and finally user3@test.com (succeeds). The scan will then proceed using user3@test.com credentials.

Important limitation

Multi-user fallback cannot be used with tenant isolation testing.

Fallback mode runs the scan using a single authenticated user. If you need to test access boundaries between users, run separate scans per user and disable fallback.


This feature is designed to improve reliability of your DAST scans.

Use it when:

  • You have multiple users with the same role
  • Authentication failures occasionally block scans
  • Scans run automatically (CI/CD, scheduled scans)
  • You want scans to complete without manual retries

For more information on enabling fallback mode for multiple users, please refer to our documentation.