Request Sequencer
The Sequencer utility repeatedly sends one captured request, extracts a token from each response, and summarizes the collected values. It is not a multi-step login builder. For ordered requests, use Replay sequences; for reusable browser login flows, see MCP login journeys.
Collecting Tokens
- In HTTP History, right-click a request and choose Send to Sequencer.
- Check the selected method, host, and path in Sequencer.
- Choose an extraction source:
| Source | What to enter |
|---|---|
| Set-Cookie header | The cookie name, such as sessionid |
| Response header | The header name, such as X-Auth-Token |
| Body (regex) | A pattern with capture group 1, such as token=([A-Za-z0-9]+) |
- Set Tokens to collect (5-200).
- Click Start Collection. This sends real requests to the target.
Use a request that generates a fresh value on each send. Repeating a request that returns the same session cookie does not measure the randomness of newly generated sessions. Avoid state-changing requests unless you intend to repeat their effects.
Reviewing Results
The analysis reports sample count, unique and duplicate values, token lengths, character sets, per-position variation, estimated entropy, and simple sequential patterns. Treat these as exploratory indicators, not proof that a token generator is secure or insecure. A small sample cannot establish cryptographic unpredictability.
Use Cancel to stop collection and Clear to reset the current results. Check collection errors before interpreting a partial sample.
Limits
The source request body is limited to 512 KiB. Body-regex extraction reads at most the first 512 KiB of each response; a token beyond that range will not be collected.