#116 · MFA using Time-Based One-Time Passwords (TOTP) is now fully supported in our Web App Scanner
We are excited to announce that Multi-Factor Authentication (MFA) using Time-Based One-Time Passwords (TOTP) is now fully supported in our Web App Scanner!
The use of multi-factor authentication (MFA) significantly enhances identity security by introducing an additional layer of verification beyond traditional login credentials. While this strengthens protection against unauthorized access, it can present a challenge for most of the DAST tools since they are typically designed for unattended execution, where manual interaction – such as approving a sign-in request or entering a time-sensitive code – can disrupt the automation workflow.
With the new support for TOTP-based MFA, Escape’s DAST scanner is now fully equipped to handle these scenarios. You can securely test web applications protected by MFA without needing manual intervention during the scanning process. This means you can automate the security testing of applications that require MFA, ensuring comprehensive coverage while maintaining a streamlined workflow.
Getting started is easy! Just use the Browser Agent authentication preset. Here's an example setup:
presets:
- type: browser_agent
login_url: https://auth.example.com/login
users:
- username: frontend-user-with-totp@example.com
password: pass
post_login_actions:
- action: fill_totp
auto_submit: true
locator: input[id="totp-input"]
secret: '123456'
Learn how to configure this preset for your needs in our documentation!

