> ## Documentation Index
> Fetch the complete documentation index at: https://docs.perfai.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Apps Without Public Sign-Up

> Perfai detects when it can't auto-create accounts and prompts you to supply two admin credentials — one per tenant — so security testing can proceed without any manual setup.

## Overview

Many enterprise and B2B apps don't have a public registration page. Accounts are provisioned by an admin, delivered through an invite link, or gated behind SSO. When Perfai can't auto-create test accounts it stops and asks you to provide credentials directly — then picks up exactly where it left off.

This page walks through the complete flow from URL submission to app mapping.

***

## Full walkthrough

<Steps>
  <Step title="Paste your app URL">
    Go to **New App**, paste your app's URL into the input field, and hit the arrow button. No configuration is needed.

    <Frame>
      <img className="docs-frame-img" src="https://mintcdn.com/perfai/K_J1iZD0uiJWM7ct/docs/images/uc-ps-01-new-app.png?fit=max&auto=format&n=K_J1iZD0uiJWM7ct&q=85&s=07d934ceb23cd1311d8889b90a886ac5" alt="Perfai — paste your app URL to start" width="1920" height="945" data-path="docs/images/uc-ps-01-new-app.png" />
    </Frame>

    Perfai works purely from the URL — no browser plugin, no code access, no pre-configuration required.
  </Step>

  <Step title="Confirm the task plan and start the agents">
    A **New app setup** modal appears listing the four tasks that will run automatically. Click **Continue**.

    <Frame>
      <img className="docs-frame-img" src="https://mintcdn.com/perfai/K_J1iZD0uiJWM7ct/docs/images/uc-ps-02-setup-modal.png?fit=max&auto=format&n=K_J1iZD0uiJWM7ct&q=85&s=bcca798fc73c74a2ae0bb0ee5c725196" alt="New app setup — four-task confirmation modal" width="1920" height="945" data-path="docs/images/uc-ps-02-setup-modal.png" />
    </Frame>

    | # | Task                    | Type       | What it does                                        |
    | - | ----------------------- | ---------- | --------------------------------------------------- |
    | 1 | Create Test Accounts    | One-time   | Creates two admin accounts from separate tenants    |
    | 2 | Discover & Create Roles | One-time   | Maps all permission roles in the app                |
    | 3 | App Mapping             | Continuous | Records every workflow, API, and data type          |
    | 4 | Security Testing        | Continuous | Runs thousands of cross-role and cross-tenant tests |

    <Note>
      **One-time** tasks run once to bootstrap your environment. **Continuous** tasks re-run automatically on every future scan.
    </Note>
  </Step>

  <Step title="Agent detects no sign-up path and asks how to proceed">
    The Vision Agent opens a cloud browser and attempts to auto-create accounts. When it can't find a public sign-up flow — no registration page, invite-only gating, or SSO wall — the **Create Test Accounts** task turns red and the agent surfaces three options.

    <Frame>
      <img className="docs-frame-img" src="https://mintcdn.com/perfai/K_J1iZD0uiJWM7ct/docs/images/uc-ps-03-options-prompt.png?fit=max&auto=format&n=K_J1iZD0uiJWM7ct&q=85&s=cc843c8f11f77cb8cf9ccfe579bd4197" alt="Vision Agent asking how to create test accounts — Yes, Manual, or Skip" width="1920" height="945" data-path="docs/images/uc-ps-03-options-prompt.png" />
    </Frame>

    | Option                                   | When to use                                                                                                |
    | ---------------------------------------- | ---------------------------------------------------------------------------------------------------------- |
    | **Yes** — provide a sign-up URL          | Your app has a registration page not linked from the homepage. Paste the direct URL and the agent retries. |
    | **Manual — I'll provide email/password** | You have pre-provisioned accounts ready to enter.                                                          |
    | **Skip — I'll add accounts later**       | You need time to provision accounts. Testing pauses until you return.                                      |

    Select **Manual — I'll provide email/password**.
  </Step>

  <Step title="Enter credentials for two admin accounts from separate tenants">
    The credential form appears. Enter email and password for both accounts, then click **Save Credentials**.

    <Frame>
      <img className="docs-frame-img" src="https://mintcdn.com/perfai/K_J1iZD0uiJWM7ct/docs/images/uc-ps-04-credential-form.png?fit=max&auto=format&n=K_J1iZD0uiJWM7ct&q=85&s=81a52f276a975f01bafe694da0ce54f4" alt="Credential form — Test Account 1 (Admin Tenant A) and Test Account 2 (Admin Tenant B)" width="1920" height="945" data-path="docs/images/uc-ps-04-credential-form.png" />
    </Frame>

    | Field                                | What to enter                                       |
    | ------------------------------------ | --------------------------------------------------- |
    | **Test Account 1** — Admin, Tenant A | Admin account for your first tenant                 |
    | **Test Account 2** — Admin, Tenant B | Admin account from a **different**, isolated tenant |

    <Warning>
      Both accounts must be admins from **different tenants**. Two accounts in the same tenant will cause all cross-tenant BOLA tests to return false negatives — you'll miss your most critical findings.
    </Warning>
  </Step>

  <Step title="Agent validates login and proceeds to app mapping">
    The Vision Agent immediately logs in as each account and verifies access using a live cloud browser session.

    <Frame>
      <img className="docs-frame-img" src="https://mintcdn.com/perfai/K_J1iZD0uiJWM7ct/docs/images/uc-ps-05-login-validation.png?fit=max&auto=format&n=K_J1iZD0uiJWM7ct&q=85&s=5923cdc06fdfa9181a656c8383694c6c" alt="Vision Agent logging in to validate both accounts" width="1920" height="945" data-path="docs/images/uc-ps-05-login-validation.png" />
    </Frame>

    Once both logins are confirmed, **App Mapping** starts automatically — no additional input needed. The agent navigates your entire app, recording every workflow, API endpoint, and data type it finds.

    <Frame>
      <img className="docs-frame-img" src="https://mintcdn.com/perfai/K_J1iZD0uiJWM7ct/docs/images/uc-ps-06-app-mapping.png?fit=max&auto=format&n=K_J1iZD0uiJWM7ct&q=85&s=4bbcd7e8e81449f722283904c578664c" alt="App mapping in progress — Vision Agent navigating the application" width="1920" height="945" data-path="docs/images/uc-ps-06-app-mapping.png" />
    </Frame>

    The left panel logs every step in real time:

    ```
    Verifying Login: Account 1...
    ACCOUNT_CREATION_COMPLETED
    App mapping has started. This process may take up to 10 minutes.
    Step 3: Attack Surface Mapping
    ```

    When mapping completes, the Security Agent begins running permission tests automatically. Findings appear in the **Overview** and **Security** tabs.
  </Step>
</Steps>

***

## After the walkthrough

Once both accounts are verified and the app is mapped, the full Perfai pipeline runs on its continuous schedule. You won't need to re-enter credentials — they are stored encrypted and reused on every subsequent scan.

| Task             | Frequency                                 |
| ---------------- | ----------------------------------------- |
| App mapping      | Continuous — re-maps as your app changes  |
| Security testing | Continuous — re-tests the updated surface |
| Full scan        | Nightly by default                        |

***

## Frequently asked questions

<AccordionGroup>
  <Accordion title="What if we use SSO and there's no password?">
    Perfai currently requires email/password credentials. For SSO-only apps, create a dedicated test account in your identity provider with password login enabled, or use a service account set up specifically for automated testing.
  </Accordion>

  <Accordion title="Do the accounts need to be real admin accounts?">
    Yes. Accounts with restricted permissions cause the Vision Agent to miss endpoints, producing incomplete attack surface coverage and fewer findings. Use the broadest admin role available in your test environment.
  </Accordion>

  <Accordion title="Can I use the same tenant for both accounts?">
    No. Cross-tenant isolation is what Perfai tests. Two accounts in the same tenant cannot produce BOLA or cross-tenant privilege escalation findings — the most critical vulnerability class Perfai detects.
  </Accordion>

  <Accordion title="Where are credentials stored?">
    Credentials are encrypted at rest and in transit. They are tied to your app record and used only when agents run. You can rotate or remove them any time from the app's **Settings** tab.
  </Accordion>

  <Accordion title="What if I skipped and want to add credentials later?">
    Open your app dashboard → **Tasks** → **Create Test Accounts** and click the task to re-open the credential form. After saving, trigger a new scan from **Actions** or wait for the next nightly run.
  </Accordion>
</AccordionGroup>
