Endpointer
Probe endpoints with and without a credential to find which ones enforce auth, then seed the gated ones into the corpus Authorize replays across identities. (Pro)
Before you test access control you need to know which endpoints actually check auth, and which hand back data to anyone who asks. Endpointer takes a list of endpoint URLs, hits each one with and without a credential, and works out which are gated — then seeds them into the broken access control (BAC) corpus so Authorize can replay them across your identities. It is the input side of access-control testing, and it is Pro.

Feed endpoints
Paste the endpoint URLs you have collected — from JS files, a wordlist, your recon, or by hand.
Paste the endpoints
One URL per line in Endpoint URLs. Each line is probed on its own, and an invalid URL is skipped rather than failing the run.
Give a credential (optional)
To test gating, set Auth header name (defaults to
Authorization) and Auth header value —Bearer eyJ…for a token, orCookie/session=…for a session. Leave the value blank to seed the endpoints without a gating verdict.Keep Nerve enrichment on
Nerve enrichment is on by default. On top of the gating verdict it raises parameter-level signals on every seeded flow — covered below.
Run it
Click Feed → seed BAC. The report lists each endpoint with its no-auth status, with-auth status, gated verdict, and how many flows it seeded, plus running totals for flows seeded, auth-gated endpoints, and Nerve signals.
How it reads auth-gating
For each endpoint Endpointer sends a bare GET without the credential, then — when you supply one — a second GET with it, and compares the two responses.
The no-auth request came back 401 or 403. The endpoint enforces a gate, which is exactly where a missing object- or function-level check turns into IDOR or privilege escalation.
The credential turned a non-2xx into a 2xx. Same conclusion: the endpoint cares who is asking, so it is worth rotating across identities.
A 200 with and without the credential is marked public, not gated. That is the classic auth-optional leak — the endpoint serves data to anyone — and it surfaces in the BAC signals table as an auth-optional endpoint once both observations are in the corpus.
A status of 0 in the report means the request errored (host unreachable, TLS failure) rather than a real response.
What it seeds
Every successful probe becomes a flow in the corpus, tagged so you can find it
again. With a credential that is two flows per endpoint — the no-auth and the
with-auth observation — and both are kept on purpose, so Hugin can compare them
and raise the auth-optional signal. Filter History
on the endpointer and auth-gated tags to pull the seeded set back up.
Endpointer honours scope like every other tool: an out-of-scope URL is skipped, not probed. If an endpoint never shows up in the report, confirm it is in scope first.
Nerve parameter overlay
A status-code comparison tells you an endpoint is gated; it does not tell you which parameter to attack. Nerve enrichment fills that in. For every seeded flow, Hugin runs its parameter knowledge over the request and raises a BAC signal for any parameter that is known access-control surface — an IDOR object reference, a mass-assignment privilege field, or a debug / role-override param — so Authorize knows what to mutate.
Teach it your target's own parameters without waiting for an update: under Nerve
param overlay, add a parameter name, pick its category — IDOR, mass
assignment, or debug — and it raises a signal whenever a seeded flow carries
that param. Names match exactly and case-insensitively (tenantSlug → IDOR), and
the overlay persists across restarts.
BAC signals
The BAC signals table shows what the seed already turned up, with no full audit required. Hit Load signals — optionally filtered to one host — and each row gives the signal kind, the locator (the parameter, field, or path it points at), the endpoint, and the source: nerve for a parameter Hugin's built-in list or your overlay flagged, passive for one raised from response evidence. It is the fast read on whether an endpoint set is worth a full Authorize run.
Hand off to Authorize
Endpointer only profiles and seeds. The cross-identity replay — running each endpoint as admin, as user A, as user B, and comparing who gets what — happens in Authorize. The seeded flows and signals are already in the corpus, so open Authorize, pick your identities, and run the matrix; it rotates the gated endpoints across them.
The credential you paste here is a one-shot for the gating probe. For the full audit, back each identity with Macros and session rules so its token refreshes automatically and a long matrix run does not die on an expired session.
The gated-or-public call is only as honest as the token you feed it. Give a genuinely low-privilege credential — feed an admin token and every endpoint answers 200, so nothing looks gated and the whole map is wrong.