> ## Documentation Index
> Fetch the complete documentation index at: https://docs.turen.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Authorized HTTP testing

> Scope, capture, replay, and report an authorized security test

TurenOS includes a bounded HTTP testing workflow for systems you are explicitly authorized to assess.

<Warning>
  Never configure a target you do not own or have written authorization to test. TurenOS does not expand scope automatically.
</Warning>

## 1. Define the target

Configure one HTTP or HTTPS base URL, an authorization note, and exact allowed URL prefixes. Requests outside those prefixes are rejected.

```text theme={null}
Configure https://staging.example.com as the authorized target. Limit scope to /api/test/ and record ticket SEC-123 as the authorization note.
```

## 2. Capture a baseline flow

Send a bounded request inside scope. TurenOS retains a redacted flow with sensitive headers and bodies protected.

## 3. Inspect and replay

List captured flows, inspect one by ID, and replay it with a deliberate method, header, or body mutation. Replay remains inside the configured URL scope.

## 4. Preserve evidence

Attach a concise analyst note to the relevant flow. Claims should identify the request, observed response, security impact, and uncertainty without storing credentials.

## 5. Report and cancel

Pentest runs expose durable execution state, findings, evidence, board state, cancellation, and report generation through the TurenOS API. Cancel a run when authorization changes or the target behaves unexpectedly.

The HTTP testing tools do not perform arbitrary network scans, browser exploitation, credential attacks, or out-of-scope requests.
