Inputs and Credentials
Inputs
Declare run parameters with input name: type. A default makes the input optional; a supplied value takes precedence. A missing required input fails the run.
input endpoint: url
input attempts: int = 3
input mode: enum(fast, deep) = fast
input targets: list<host> Use target types such as host, url, cidr, address, and port for target parameters. Use str, int, bool, or json for other values. See Types for collection and record examples.
Credentials
cred name: type references a credential by name. Configure its value in the workspace rather than putting the secret in source. The credential must be available to the run; a missing credential is an error.
input endpoint: url
cred api: bearer
response = http.get(endpoint, headers={ Authorization: `Bearer ${api.token}` })
out(response.status) Credential types expose these fields (? means optional):
bearer:token;apikey:key.basic:username,password.headerandcookie:name,value.ssh_key:private_key,public_key?,passphrase?.aws:access_key_id,secret_access_key,session_token?.wallet:private_key;rpc:url,api_key?.
Credential values are masked in supported displays, but requests still use the real secret. Avoid printing credentials, copying them into findings, or sending them to endpoints you do not trust. Review output and artifacts before sharing.