Running a Pentest
From the dashboard
- Go to New Pentest
- Enter your target URL (e.g.
https://app.example.com) - Optionally add a GitHub repository URL for white box analysis
- Click Start Pentest
The pentest will consume one credit and begin immediately. You will be redirected to the results page where you can watch tool progress in real time.
From the API
curl -X POST https://turbopentest.com/api/pentests \
-H "Authorization: Bearer $TURBOPENTEST_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"targetUrl": "https://app.example.com",
"repoUrl": "https://github.com/org/repo"
}'Request body
| Field | Type | Required | Description |
|---|---|---|---|
targetUrl | string | Yes | The URL to pentest |
tier | string | No | Depth tier: recon, standard, deep, or blitz (defaults to the credit's tier). standard/deep/blitz are shown in the product as Audit-Ready / Threat-Hunt / Adversarial-Depth |
repoUrl | string | No | GitHub repo URL for white box analysis |
creditId | string | No | Specific credit to consume (uses oldest available if omitted) |
notes | string | No | Optional notes for this pentest |
Response
{
"id": "uuid",
"targetUrl": "https://app.example.com",
"repoUrl": "https://github.com/org/repo",
"status": "queued",
"createdAt": "2026-02-16T00:00:00.000Z"
}From CI/CD
See CI/CD Integration for pipeline configurations.
Scheduling pentests
You can schedule pentests to run automatically - either as a one-off at a specific time or on a recurring basis.
One-off schedules
Run a pentest at a specific date and time. This is useful for coordinating with deployment windows or change management schedules.
Recurring schedules
Set up automatic pentests on a regular cadence:
| Frequency | Description |
|---|---|
| Daily | Runs every day at the scheduled time |
| Weekly | Runs once per week on the scheduled day |
| Biweekly | Runs every two weeks on the scheduled day |
| Monthly | Runs once per month on the scheduled date |
| Quarterly | Runs once every three months on the scheduled date |
How scheduled pentests consume credits
- When a scheduled pentest fires, it consumes one credit using FIFO order (oldest available credit is used first)
- If no credits are available when the schedule fires, the pentest is skipped and you receive an email notification so you can purchase more or adjust your schedules
- Skipped pentests are not retried automatically - the next run will occur at the next scheduled time
Managing schedules
You can create, pause, resume, and delete schedules from the dashboard or via the API (/api/schedules). Pausing a schedule prevents it from firing until you resume it. Deleting a schedule removes it permanently.
What happens during a pentest
- Queued - Pentest is created and credit is consumed
- Phase 1 - Applicable tools are launched as isolated containers in two waves: recon and non-web tools first, then web tools against the targets Port Scanner discovers
- Tool callbacks - Each tool reports results as it finishes
- Phase 2 - The Paladin AI agent swarm reasons over the Phase 1 data, runs its own tools, validates exploits, chains findings, and generates unified findings
- Complete - Findings, report, and attestation are available
Core Concepts
The key concepts behind TurboPentest - credits, domains, pentests, and findings - and how they fit together when you run and manage a pentest.
Black Box vs White Box
Understand black-box vs white-box pentesting in TurboPentest, what each covers, and when to connect GitHub source code for deeper white-box analysis.