Reference
OpenAPI contract, QA credential vault, authenticated session probe — Security Pro.
Security Pro can go beyond a public crawl: you supply an OpenAPI JSON contract, store encrypted QA test credentials, and run an authenticated session probe that observes logged-in routes and APIs. This is assessment framing — not BOLA, injection, or a pentest.
| Step | Where | Notes |
|---|---|---|
| Verify DNS | Dashboard Security Pro setup | Required before credentials / probe |
| Attach OpenAPI 3 JSON | Same panel | Merges paths into API inventory; flags gaps |
| Store QA login | Encrypted at rest | No MFA accounts; confirm QA-only checkbox |
| Run authenticated probe | One-shot session | Credentials purged after successful login |
BOLA object-access checks, injection canaries, and rate-limit abuse probes are not enabled. Passwords never appear in report JSON.