Deployment: Invicti Platform on-demand, Invicti Platform on-premises
Add a target
In Invicti Platform, an asset can be either a target or a project. This document guides you through adding a new target, configuring its details, and preparing it for accurate and secure scanning. You can add targets - websites, web applications, or APIs - either from the Website discovery page or directly from the Targets page. If you want to create multiple targets, refer to the linked document.
Add a website target
- Select Inventory > Targets from the left-side menu.
- Select Create new target.

- Under What type of asset is this?, select Webapp.
- Enter a name and the URL of the target. The URL mustn't contain any whitespace or spaces, as this causes a warning message to appear. If you add a space before or after the URL, Invicti automatically removes it.
- By default, new targets use the Invicti Cloud Agent, which can scan any publicly available site without additional configuration. Select the agent that best matches your scan environment and security requirements.
- Invicti Cloud agent (default): This is Invicti’s managed cloud-based agent, suitable for scanning publicly accessible websites. It requires no setup and is ideal for most internet-facing applications.
- Internal agent: You can also use your own installed scan agent to scan internal or restricted environments not accessible from the public internet.
- Optionally, assign the target to an environment (for example, development, staging, production) to help organize and manage scans. If no environment is selected, Not specified is used by default. Environments are defined in Settings > Environments and must be created there before use.
- Select a parent application to group the target with related assets. Applications serve as central units for managing vulnerabilities and improving analysis across connected targets.
- Select a collection to organize the target based on business context or custom criteria. Collections support tailored security management and reporting.
- Add tags to further group and filter targets. Submit each tag by pressing Enter after typing. Tags assist with quick identification, categorization, and filtering in reports and views.

- Click Create target.

Before running your first scan, make sure to read our authorized target scan policy. To get started safely with the Invicti Platform, you can use our testing website, which allows you to explore scanning features without using your own FQDNs or affecting live environments.
- The Targets page is updated with your new target.
Once you set up your target, you can run the first scan.
Add an API target
When you select API as the asset type, the Add new target form shows API-specific fields: a specification file input and API details. Use this procedure to add an API target in Invicti Platform.
-
Select Inventory > Targets from the left-side menu.
-
Click Add new target.
-
Enter a Name for the target.
-
Under What type of asset is this?, select API.
-
Optionally, under Specification details, provide an API specification file using one of the following options:
- Link from URL: Enter the URL where the specification file is hosted. Use this option when the file is regularly updated, so Invicti always uses the latest version.
- Choose file: Upload a local specification file.
For supported API types and specification formats, refer to the API types and specification formats document.
-
Under API details, enter the API base URL - the root URL of your API (for example,
https://example.com/api/v1). -
Select the Agent. The cloud agent is selected by default. If you have internal agents installed, you can select one to scan APIs that aren't publicly accessible.
-
Optionally, select the Environment to classify the target (for example, development, staging, or production). If no environment is selected, Not specified is used by default. Environments are defined in Settings > Environments.
-
Optionally, select a Parent application to group the target with related assets.
-
Optionally, select a Collection to organize the target by business context.
-
Optionally, add Tags for filtering and categorization. Submit each tag by pressing Enter.


- Click Add target to create the target, or Add and configure to create it and immediately open the target's configuration page.
Before running your first scan, make sure to read our authorized target scan policy. To get started safely with the Invicti Platform, you can use our testing website, which allows you to explore scanning features without using your own FQDNs or affecting live environments.
- The Targets page is updated with your new target.
Once you set up your target, you can run the first scan.
Need help?
Invicti Support team is ready to provide you with technical help. Go to Help Center