Authz0

A command-line tool that tests web applications for authorization flaws using URL and role templates.

Read the Authz0 documentation

Alternatives

About Authz0

Authz0 checks whether different roles and credentials can access URLs they should not. It stores URLs, roles and credentials in YAML templates, which can be generated or edited before scanning.

The tool can use multiple authentication headers and cookies, and can create templates from HAR files or saved ZAP and Burp history. It supports macOS, Windows and Linux, and can also run in Docker or GitHub Actions.

Strengths

  • Tests access across URLs, roles and credentials
  • Can create templates from HAR, ZAP and Burp history
  • Supports multiple authentication headers and cookies

Limitations

  • Requires test URLs and role credentials to be configured
  • Intended for authorized testing

Details

Pricing
FreeFree and open source under the MIT license.
License
MIT
Developer
hahwul
Platforms
Windows, macOS, Linux, Command line
How it runs
Downloadable app
Best suited for
Security testers checking access controls in web applications they are authorized to assess
Last verified
Added
Provenance
Selected from the Homebrew formula

Report a wrong fact or a dead link on this listing