Skip to main content
Startup plan or higher required. Live battletest is not available on Free or Dev plans. View plans →

Before you start

  • You must own or have explicit written authorisation to test the domain
  • The domain must be reachable from the public internet (VPN-only and localhost targets are not supported)
  • Your plan must have at least one free target slot — check Tests to see how many slots you’ve used. Slot counts and cooldowns per plan are in Limits & Quotas
  • Your email address must be verified. If you signed up with email and password, check your inbox or resend the verification from Settings → Account

Add the target

1

Open New Environment

2

Enter the domain

Enter the domain name — for example, app.example.com — without a protocol prefix.
3

Set permission tier

Select the initial permission tier. Start with Read-only for a first assessment.
4

Add target

Click Add Target.

Activate and run the first scan

1

Open the environment

From the Tests page, click on the environment you just created.
2

Activate

Click Activate. The discovery scan begins within a few minutes and the status changes to Running.
3

Wait for discovery

Discovery completes in 5–15 minutes depending on the application size. The environment detail page then shows the discovered endpoint inventory.

Approve active probing

To go beyond passive discovery, approve a higher permission tier:
1

Open Approvals

Go to the environment detail page → Approvals.
2

Review tier description

Read what each tier does. See How Live BattleTest works for details.
3

Approve the tier

Click Approve next to the tier you want to enable and confirm.
4

Start a new scan

Start a new scan from the Tests page.

Add multiple domains to one environment

An environment can cover multiple domains belonging to the same application — for example, api.example.com and app.example.com. From the environment detail page, click Add domain and enter additional hostnames. All domains in one environment share the same target slot.

Run a scan immediately (bypass cooldown)

Each plan enforces a minimum time between scans: 4 hours on Startup, 2 hours on Observability. To scan sooner — for example, immediately after a deploy:
1

Open the environment

Go to the environment detail page.
2

Bypass cooldown

Click Run scan now (visible when a cooldown is active).
3

Confirm purchase

Confirm the $49 one-time purchase. The scan starts immediately.
The cooldown bypass applies to a single scan on a single target. The regular cooldown resumes after the bypassed scan completes. If you bypass cooldowns frequently, upgrading to Observability (2-hour cooldown) is more cost-effective.