docs

Community and Pro

What runs free in Community, what Pro adds, and how the account and offline grace work.

Hugin runs in Community by default, with no account and no token. Community is not a demo — the core hunting loop is all here.

What's in Community (free)

The Proxy, the Scanner (active and passive checks), Intruder, Sequencer, the Repeater, and the Decoder. You can intercept, scan, fuzz, replay, and decode without paying.

What Pro adds

Pro turns on the heavier and automation-facing tooling:

Automation and AI

The MCP server (driving Hugin from an AI agent), Workflows, and the Intelligence aggregator.

Advanced offence

RatRace (race conditions), the built-in Browser, vurl, Nerve, Authorize / BAC, and the Scanner's out-of-band confirmation and custom checks.

Extend and scale

Lua extensions, Synaps WASM modules, team collaboration, mobile analysis, the WebSocket client, and multi-project workspaces.

Pricing is on the pricing page — one tier, one price.

The account

Set your account ID once:

hugin account set HGN-XXXXXXXX-XXXXXXXX-XXXXXXXX

Hugin checks it against the licence server and caches a signed token. hugin account show re-verifies; hugin account clear drops back to Community. A new account starts a 30-day trial that grants Pro.

The account manages your licence, not your work — flows, findings, and traffic stay on your machine. If the licence server is unreachable, Hugin keeps your tier from the cached token for a 72-hour offline grace window, then falls back to Community.

Install it first in installation.

Last updated 2026-06-07.