---
title: "Running a Pentest"
description: "Start a TurboPentest pentest from the dashboard or API - enter a target URL, optionally add a GitHub repo for white-box analysis, and launch the scan."
canonical: https://turbopentest.com/docs/pentesting/running-a-pentest
source: "TurboPentest Docs"
---

# Running a Pentest

## From the dashboard

1. Go to [New Pentest](https://turbopentest.com/pentests/new)
2. Enter your target URL (e.g. `https://app.example.com`)
3. Optionally add a GitHub repository URL for white box analysis
4. Click **Start Pentest**

The pentest will consume one credit and begin immediately. You will be redirected to the results page where you can watch tool progress in real time.

## From the API

```bash title="Terminal"
curl -X POST https://turbopentest.com/api/pentests \
  -H "Authorization: Bearer $TURBOPENTEST_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "targetUrl": "https://app.example.com",
    "repoUrl": "https://github.com/org/repo"
  }'
```

### Request body

| Field | Type | Required | Description |
|-------|------|----------|-------------|
| `targetUrl` | string | Yes | The URL to pentest |
| `tier` | string | No | Depth tier: `recon`, `standard`, `deep`, or `blitz` (defaults to the credit's tier). `standard`/`deep`/`blitz` are shown in the product as Audit-Ready / Threat-Hunt / Adversarial-Depth |
| `repoUrl` | string | No | GitHub repo URL for white box analysis |
| `creditId` | string | No | Specific credit to consume (uses oldest available if omitted) |
| `notes` | string | No | Optional notes for this pentest |

### Response

```json title="Response"
{
  "id": "uuid",
  "targetUrl": "https://app.example.com",
  "repoUrl": "https://github.com/org/repo",
  "status": "queued",
  "createdAt": "2026-02-16T00:00:00.000Z"
}
```

## From CI/CD

See [CI/CD Integration](/docs/integrations/cicd) for pipeline configurations.

## Scheduling pentests

You can schedule pentests to run automatically - either as a one-off at a specific time or on a recurring basis.

### One-off schedules

Run a pentest at a specific date and time. This is useful for coordinating with deployment windows or change management schedules.

### Recurring schedules

Set up automatic pentests on a regular cadence:

| Frequency | Description |
|-----------|-------------|
| Daily | Runs every day at the scheduled time |
| Weekly | Runs once per week on the scheduled day |
| Biweekly | Runs every two weeks on the scheduled day |
| Monthly | Runs once per month on the scheduled date |
| Quarterly | Runs once every three months on the scheduled date |

### How scheduled pentests consume credits

- When a scheduled pentest fires, it consumes one credit using **FIFO order** (oldest available credit is used first)
- If no credits are available when the schedule fires, the pentest is **skipped** and you receive an email notification so you can purchase more or adjust your schedules
- Skipped pentests are not retried automatically - the next run will occur at the next scheduled time

### Managing schedules

You can create, pause, resume, and delete schedules from the dashboard or via the API (`/api/schedules`). Pausing a schedule prevents it from firing until you resume it. Deleting a schedule removes it permanently.

## What happens during a pentest

1. **Queued** - Pentest is created and credit is consumed
2. **Phase 1** - Applicable tools are launched as isolated containers in two waves: recon and non-web tools first, then web tools against the targets Port Scanner discovers
3. **Tool callbacks** - Each tool reports results as it finishes
4. **Phase 2** - The Paladin AI agent swarm reasons over the Phase 1 data, runs its own tools, validates exploits, chains findings, and generates unified findings
5. **Complete** - Findings, report, and attestation are available
