Barrion Docs
AI Pentesting

Authenticated Testing

Supply a test account, including a two-factor (TOTP) key, so the agent can test behind your login.

By default a pentest tests what an anonymous visitor can reach. Give the agent a test account and it logs in and tests the authenticated surface too: pages and APIs that require a session, access control between roles and tenants (IDOR), and privilege escalation. The deeper, more interesting classes of finding almost always live behind the login, so a working test account is the single biggest thing you can do to improve a run.

Supply credentials in the Credentials step of the pentest wizard. For most accounts a username and password are enough. When the account has two-factor authentication turned on, also supply its TOTP authenticator key so the agent can generate the one-time codes itself at login time.

What the TOTP key is

The TOTP key (also called the authenticator key, setup key, or secret) is the base32 string that your authenticator app stores when you first set up 2FA. It is the same secret the QR code encodes. With it, the agent generates the same rotating six-digit codes your authenticator app would show, so it can complete the second factor on its own.

You need the text key itself, not a screenshot of the QR code and not a single current six-digit code. A code expires in seconds; the key is what generates every code.

Getting the key from your provider

The key is only shown while you are setting up (or re-setting-up) an authenticator app for the account. If 2FA is already configured and you no longer have the key, remove and re-add the authenticator to reveal a fresh one.

Google account

  1. Go to your Google Account, then Security -> 2-Step Verification.
  2. Under Authenticator, start adding an authenticator app.
  3. On the QR code screen, click Can't scan it?.
  4. Copy the setup key it shows (the base32 string), not the QR image.

Use a dedicated account on your own company domain for this, not a brand-new free Gmail created just for the test. Google frequently flags automated logins to fresh consumer Gmail accounts as suspicious and blocks them, which will stall the run at the login step.

Microsoft / Entra

  1. In your account security settings, add a sign-in method and choose the authenticator app.
  2. When prompted, choose I want to use a different authenticator app.
  3. The secret key is shown as text on the next screen. Copy it.

Any other app

On the 2FA setup screen, look for a can't scan the QR code or enter a code / enter key manually option. That reveals the text secret the QR code stands in for. Copy that string.

Entering it in the wizard

Paste the key into the TOTP field for that account in the Credentials step.

  • Spaces in the key are fine. Providers often group the secret into blocks for readability; the spaces are stripped before use.
  • The key is stored encrypted and is used only to generate codes at login time during the run.

If you cannot export a key

Some providers never reveal a copyable secret, or your account policy forbids sharing one. In that case you can leave the TOTP field empty and rely on live code entry: during Save & Test the agent can pause when it hits the second-factor prompt and ask you to type a current one-time code directly in the wizard. You read the code from your own authenticator and enter it, and the agent continues the login. This keeps the secret with you while still letting the run test behind the login.