Skip to main content
Mjolnir analyses the repositories you selected in Connect GitHub statically by default. You can continue this step without adding a URL. Add live HTTPS URLs only if you also want Mjolnir to test a running application. Live targets get a connectivity check and, at launch, domain verification.

Static analysis (default)

Leave the URL fields empty and click Continue. Mjolnir uses your connected source code. It does not send attack traffic to an application, and it does not need an allowlist.

Optional: live target URLs

Enter the URLs that make up a running application’s scope.
You can add multiple URLs. Each one can have its own custom headers.
Only add URLs you own and are authorised to test. Mjolnir will send real HTTP requests, including probes that may look like attack traffic, to everything in scope.

Custom headers

Each live URL can have custom HTTP headers attached. These are sent with every request Mjolnir makes to that URL. Common uses: Click Add header under any URL to add key/value pairs.
If your application uses a WAF like Cloudflare or AWS WAF, allowlisting our IPs is usually more reliable than header bypasses. See Allowlisting.

Connectivity check (live URLs only)

Once you’ve added at least one valid HTTPS URL, you can run the connectivity check. This takes a few seconds per URL.

Status indicators

If you see warnings or failures

Add Mjolnir’s IP ranges to your allowlist, then click Re-run check.

How to set up an allowlist for Mjolnir

Step-by-step instructions for Cloudflare, AWS WAF, and others
You can proceed with remaining connectivity issues, but live coverage will be reduced. Static analysis of the selected repositories is unaffected.

Next: Review & verify

Review the setup. Domain verification is only required when you added live URLs.