Skip to content

Request Sequencer ​

The Sequencer utility repeatedly sends one captured request, extracts a token from each response, and summarizes the collected values. It is not a multi-step login builder. For ordered requests, use Replay sequences; for reusable browser login flows, see MCP login journeys.

Collecting Tokens ​

  1. In HTTP History, right-click a request and choose Send to Sequencer.
  2. Check the selected method, host, and path in Sequencer.
  3. Choose an extraction source:
SourceWhat to enter
Set-Cookie headerThe cookie name, such as sessionid
Response headerThe header name, such as X-Auth-Token
Body (regex)A pattern with capture group 1, such as token=([A-Za-z0-9]+)
  1. Set Tokens to collect (5-200).
  2. Click Start Collection. This sends real requests to the target.

Use a request that generates a fresh value on each send. Repeating a request that returns the same session cookie does not measure the randomness of newly generated sessions. Avoid state-changing requests unless you intend to repeat their effects.

Reviewing Results ​

The analysis reports sample count, unique and duplicate values, token lengths, character sets, per-position variation, estimated entropy, and simple sequential patterns. Treat these as exploratory indicators, not proof that a token generator is secure or insecure. A small sample cannot establish cryptographic unpredictability.

Use Cancel to stop collection and Clear to reset the current results. Check collection errors before interpreting a partial sample.

Limits ​

The source request body is limited to 512 KiB. Body-regex extraction reads at most the first 512 KiB of each response; a token beyond that range will not be collected.

Proprietary software. All rights reserved.