Create Login Recording using Astra MCP

Last updated: September 28, 2026

Use Astra MCP to create and validate a login recording for your Astra scans.

For MCP setup instructions, see Set up Astra MCP.

Watch the Video

The video demonstrates how to create, validate, and upload a login recording using Astra MCP, including support for MFA, OTP, SSO, and complex login flows.

Before You Begin

Make sure you have:

  • Astra MCP configured in your IDE or LLM tool.

  • The application's login URL.

  • Valid login credentials.

  • Any additional credentials required by your authentication flow, such as a TOTP secret.

  • WAF or other bot protection disabled or configured to allow the recording/scanner session.


Create a Login Recording

Start a new chat in your IDE or LLM tool and describe how you log in to your application.

Astra MCP supports different types of login recordings depending on your authentication flow. Use the examples below as a starting point.

1. Username and Password Login

Use this when your application has a simple login form with a username, email, mobile number, and password.

Example prompt:

Create a login recording for my application.

Login URL: https://example.com/login
Username: testuser@example.com
Password: <your-password>

Log in using username and password.

Provide the actual login URL and credentials for your application.


2. Login with MFA / TOTP

Use this when your application requires username and password followed by a TOTP-based MFA code.

Provide the TOTP secret so Astra MCP can generate the OTP during the login flow.

Example prompt:

Create a custom login recording for my application with MFA.

Login URL: https://example.com/login
Username: testuser@example.com
Password: <your-password>
TOTP Secret: <your-totp-secret>

Login using username and password, then complete the TOTP MFA step.

Important: Provide the TOTP secret only when it is required to complete the authentication flow.


3. Login with SSO

Use this when your application uses an identity provider such as Google, Microsoft, Okta, or another SSO provider.

Specify the SSO provider and describe any additional steps required during authentication.

Example prompt:

Create a custom login recording for my application using Google SSO.

Login URL: https://example.com/login

Use the "Sign in with Google" option.
Google account: testuser@example.com
Password: <your-password>

Complete the Google SSO flow and confirm login.

For Microsoft SSO, Okta, or another provider, replace the provider details accordingly.


4. Login with Multiple Authentication Methods

If your application provides multiple login options, specify exactly which authentication method should be used.

For example, if the application supports both username/password and Google SSO:

Example prompt:

Create a login recording using username and password only.

Login URL: https://example.com/login
Username: testuser@example.com
Password: <your-password>

This prevents Astra MCP from selecting a different authentication method than the one you want to use.


5. Login with OTP

If your application uses a one-time password as part of the login flow, describe how the OTP is generated and provide the required information.

For example, if the OTP is generated using TOTP:

Example prompt:

Create a login recording with OTP authentication.

Login URL: https://example.com/login
Username: testuser@example.com
Password: <your-password>
TOTP Secret: <your-totp-secret>

After entering the username and password, enter the generated OTP.

If the OTP is sent by email or uses a different mechanism, describe that flow in the prompt.

Note: If your flow requires an OTP to be sent by email, use the testing account dast@getastra.com only.


6. Complex or Custom Login Flow

Some applications have additional steps, such as:

  • Selecting an organization.

  • Accepting a consent screen.

  • Entering an account identifier.

  • Completing multiple authentication steps.

Describe these steps in the prompt so Astra MCP can reproduce the complete flow.

Example prompt:

Create a custom login recording for my application.

Login URL: https://example.com/login
Username: testuser@example.com
Password: <your-password>
TOTP Secret: <your-totp-secret>

Login flow:
1. Enter the username.
2. Click "Continue".
3. Enter the password.
4. Click "Sign in".
5. Enter the TOTP code.
6. Select the "Production" organization.
7. Confirm that the dashboard is displayed.

Complete all steps and validate that the final session is authenticated.

What Happens After You Submit the Prompt?

Astra MCP will:

  1. Analyze the login flow you described.

  2. Create the login recording.

  3. Replay the recording against your application to validate it.

  4. Show the steps performed during the login flow.

  5. Provide the generated recording file and any relevant notes.

The process can take approximately 5–10 minutes, depending on the complexity of your login flow.

Review the generated steps and final notes. If Astra MCP reports any blockers or edge cases, resolve them before uploading the recording.


Upload the Recording to Astra

Once the recording has been successfully created and validated:

  1. Download the generated recording file.

  2. Open the relevant Astra target.

  3. Go to Target Setup → User Credentials → Login Recording.

  4. Upload the generated recording.

  5. Save the target configuration.

Note: Review the generated steps and final notes provided by MCP for any blockers or edge cases before uploading the recording.