Multi-Domain Pentests
Multi-domain pentests let you test multiple URLs at once. Each URL becomes its own pentest, but they share a groupId for tracking.
Requirements
- All domains must be verified
- You need one credit per target (up to 20 domains)
- All domains can optionally share the same GitHub repository
API usage
curl -X POST https://turbopentest.com/api/pentests \
-H "Authorization: Bearer $TURBOPENTEST_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"targetUrls": [
"https://app.example.com",
"https://api.example.com",
"https://admin.example.com"
],
"repoUrl": "https://github.com/org/repo"
}'Response
{
"groupId": "uuid",
"scans": [
{ "id": "uuid-1", "targetUrl": "https://app.example.com", "status": "queued" },
{ "id": "uuid-2", "targetUrl": "https://api.example.com", "status": "queued" }
],
"queuedScans": [
{ "id": "uuid-3", "targetUrl": "https://admin.example.com", "status": "capacity_queued" }
]
}scans lists the pentests launched immediately. Launching is capacity-aware: pentests beyond the available capacity (or your concurrency limit) appear in queuedScans with status capacity_queued and launch automatically as capacity frees up.
Limits
- Maximum 20 domains per request
- Each domain must pass URL validation (must be a valid HTTPS URL, not an IP address)
- Each domain can only appear once, and none of the targets may already have an active pentest
- Credits are consumed atomically - either all pentests are created or none are (overflow pentests queue rather than fail)
Black Box vs White Box
Understand black-box vs white-box pentesting in TurboPentest, what each covers, and when to connect GitHub source code for deeper white-box analysis.
Understanding Results
How to read TurboPentest findings - severity, CVSS scores, and evidence - and prioritize which vulnerabilities your team should remediate first.