Template from anything
Generate scan templates from a URL list, ZAP history, Burp history or HAR files.
Authorization Testing · Go
An automated authorization tester. Define a matrix of URLs, roles and credentials, then let Authz0 verify your access controls and surface unauthorized access.
Capabilities
Bring your own traffic — Authz0 turns URLs and existing proxy history into a repeatable access-control test.
Generate scan templates from a URL list, ZAP history, Burp history or HAR files.
Attach roles, headers and cookies per identity to model real access tiers.
Replays each URL across identities and flags unexpected authorized access.
A simple YAML authorization matrix keeps tests declarative and repeatable.
Test multiple authentication headers and cookies for the same endpoint.
macOS, Windows, Linux, Docker and GitHub Actions out of the box.
Quickstart
Illustrative workflow.
Add Authz0 to your pipeline and catch broken authorization.