---
title: "Multi-Domain Pentests"
description: "Test up to 20 domains in a single TurboPentest request - each URL runs as its own pentest while sharing a groupId so you can track them together."
canonical: https://turbopentest.com/docs/pentesting/multi-domain
source: "TurboPentest Docs"
---

# Multi-Domain Pentests

Multi-domain pentests let you test multiple URLs at once. Each URL becomes its own pentest, but they share a `groupId` for tracking.

## Requirements

- All domains must be verified
- You need one credit per target (up to 20 domains)
- All domains can optionally share the same GitHub repository

## API usage

```bash title="Terminal"
curl -X POST https://turbopentest.com/api/pentests \
  -H "Authorization: Bearer $TURBOPENTEST_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "targetUrls": [
      "https://app.example.com",
      "https://api.example.com",
      "https://admin.example.com"
    ],
    "repoUrl": "https://github.com/org/repo"
  }'
```

### Response

```json title="Response"
{
  "groupId": "uuid",
  "scans": [
    { "id": "uuid-1", "targetUrl": "https://app.example.com", "status": "queued" },
    { "id": "uuid-2", "targetUrl": "https://api.example.com", "status": "queued" }
  ],
  "queuedScans": [
    { "id": "uuid-3", "targetUrl": "https://admin.example.com", "status": "capacity_queued" }
  ]
}
```

`scans` lists the pentests launched immediately. Launching is capacity-aware: pentests beyond the available capacity (or your concurrency limit) appear in `queuedScans` with status `capacity_queued` and launch automatically as capacity frees up.

## Limits

- Maximum 20 domains per request
- Each domain must pass URL validation (must be a valid HTTPS URL, not an IP address)
- Each domain can only appear once, and none of the targets may already have an active pentest
- Credits are consumed atomically - either all pentests are created or none are (overflow pentests queue rather than fail)
