Static analysis (default)
Leave the URL fields empty and click Continue. Mjolnir uses your connected source code. It does not send attack traffic to an application, and it does not need an allowlist.Optional: live target URLs
Enter the URLs that make up a running application’s scope.Custom headers
Each live URL can have custom HTTP headers attached. These are sent with every request Mjolnir makes to that URL. Common uses:
Click Add header under any URL to add key/value pairs.
If your application uses a WAF like Cloudflare or AWS WAF, allowlisting our IPs is usually more reliable than header bypasses. See Allowlisting.
Connectivity check (live URLs only)
Once you’ve added at least one valid HTTPS URL, you can run the connectivity check. This takes a few seconds per URL.Status indicators
If you see warnings or failures
Add Mjolnir’s IP ranges to your allowlist, then click Re-run check.How to set up an allowlist for Mjolnir
Step-by-step instructions for Cloudflare, AWS WAF, and others
Next: Review & verify
Review the setup. Domain verification is only required when you added live URLs.