Deployment: Invicti Platform on-demand, Invicti Platform on-premises
Target definition
Before Invicti Platform can scan a website, API, or web application for vulnerabilities, you add it as a target. This document explains what a target is, the asset types you can choose, and how targets count toward your license - so you can plan your coverage and keep license usage predictable.
A target can be almost any web asset, including websites, APIs, web applications, servers, and network devices. Typically, each domain or web application uses one target license.

Target types
When you add a target, you select its asset type, which determines how Invicti scans it:
- Webapp: A website or web application. Invicti crawls the target in a browser to discover links and pages, then scans what it finds.
- API-only target (asset type API): An API endpoint that Invicti scans only against the operations defined in its API specification. Invicti doesn't crawl the target in a browser, and any endpoints or links discovered outside the specification are ignored. Creating API-only targets requires the API discovery add-on.
- Because an API-only target isn't crawled like a website, some of its scan, authentication, and configuration options differ from a webapp target. For more information about these differences, refer to the Targets overview document.
- To add an API-only target and provide its specification file, refer to add an API target. For more information about API scanning, refer to the Overview of scanning APIs and API types and specification formats documents.
Licensing rules for targets
When determining how targets are counted for licensing, the following rules apply:
For more information about managing your license usage and viewing FQDN consumption, refer to License management.
localhostand127.0.0.1consume 1 licensed targetexample.comandwww.example.comtogether consume 1 licensed target- The protocol (
httpvs.https) doesn't affect target count and consumes 1 licensed target - Subdomains are considered separate targets: for example,
www.example.comandapi.example.comconsume 2 licensed targets - Different paths within the same domain consume 1 licensed target: for example,
example.comandexample.com/blog/ - Different ports for the same domain consume 1 licensed target: for example,
example.com:8080andexample.com:8888 - Invicti test sites with Demo status (visible in the Settings > License > Licensed FQDNs used drawer) don't consume any target licenses; for example,
vulnweb.com
Target variations and licensing
Target variations refer to different configurations of the same FQDN. You can create multiple variations such as:
http://example.comhttps://example.comhttp://www.example.comhttps://www.example.comhttp://example.com/bloghttp://example.com:888http://example.com:777
All these variations use only one licensed FQDN.
Important licensing behavior:
- Invicti doesn't immediately count targets against your license when you add them
- You can remove a target without penalty if you make a mistake in the address
- Invicti counts a target as licensed only after you scan it
Subdomain licensing rules
Invicti counts each subdomain as a separate FQDN, with the exception of www:
http://www.example.comandhttp://api.example.comuse 2 licensed targetsinvicti.com:80andinvicti.com:443count as 1 licensed targetinvicti.com/homeandinvicti.com/sitecount as 1 licensed target
Need help?
Invicti Support team is ready to provide you with technical help. Go to Help Center