Skip to main content
Mo needs access to your site to test it. Provide credentials for pages behind a login, and configure your test environment to let Mo’s browser through any firewall or deployment protection.

Ways to give access

Give sign-in credentials

Include a test account and sign-in instructions in your brief or send them in the session chat. Name the sign-in URL, the account’s role, and any extra steps needed to reach the area you want tested. If a login page blocks the requested work and you have not provided credentials, Mo asks you for them before continuing. Each web sub-agent starts with a fresh browser context. Mo supplies authentication instructions for the assigned work:
  • With a username and password, Mo passes those credentials to each agent that needs them.
  • With one-time codes or MFA, Mo signs in once, saves the browser authentication state inside the session sandbox, and each agent loads that state instead of signing in again.
Mo instructs its agents to keep passwords, tokens, and saved authentication state out of public test and report fields. Browser recordings can capture information visible during sign-in. Use dedicated test accounts and review evidence before sharing it.

Allow the egress IP

Add Mo’s hosted browser egress IP to your test environment’s firewall allowlist. For a field that accepts a single IP address, copy:
For an allowlist that accepts CIDR notation, copy:

Set a user agent string

If your test environment allows traffic by user agent, tell Mo to use the string your rule expects. For example, add this instruction to your brief:
Configure your test environment to allow that same value:
Mo uses a Chrome user agent by default, and the string is a custom value it sets on request. Other clients can copy a user agent, so it does not authenticate Mo’s traffic.

Connect a local or private target

Use a tunnel to reach an app on your machine or private network. Keep the target URL in your brief, and provide sign-in credentials if the app requires them.

Use an accessible address or change access settings

Give Mo a public or test URL it can open, or change your test environment’s firewall and deployment protection settings to permit its browser. If your hosting provider supports a bypass token, provide the token and its required HTTP header in the session chat. After you provide access, tell Mo to retry the target. An accessible URL still needs a test account if the flows you want tested require sign-in.