Reference

Authenticated security

OpenAPI contract, QA credential vault, authenticated session probe — Security Pro.

Security Pro can go beyond a public crawl: you supply an OpenAPI JSON contract, store encrypted QA test credentials, and run an authenticated session probe that observes logged-in routes and APIs. This is assessment framing — not BOLA, injection, or a pentest.

StepWhereNotes
Verify DNSDashboard Security Pro setupRequired before credentials / probe
Attach OpenAPI 3 JSONSame panelMerges paths into API inventory; flags gaps
Store QA loginEncrypted at restNo MFA accounts; confirm QA-only checkbox
Run authenticated probeOne-shot sessionCredentials purged after successful login

BOLA object-access checks, injection canaries, and rate-limit abuse probes are not enabled. Passwords never appear in report JSON.