Skip to content

Workflows ​

Workflows are reusable automation pipelines that process captured traffic, run active steps, or transform data - without requiring you to write standalone scripts.

Workflow Types ​

TypeTriggered byCommon use
PassiveNew captured trafficFlag interesting patterns, tag requests, create findings automatically.
ActiveManual runSend follow-up requests, chain actions, execute multi-step tests.
ConvertTest input, conversion actions, or Match & ReplaceTransform text or bytes, such as formatting JavaScript or normalizing JSON.

Passive workflows run continuously in the background. Active workflows run on demand against a selected set of requests.

The Workflow Canvas ​

Open Workflows and select a workflow to open its canvas.

  • Nodes appear in the center panel. Each node has typed input and output ports.
  • Connect an output port to an input port by clicking and dragging between them.
  • Click a node to open its configuration panel on the right.
  • The toolbar at the top contains the run, enable/disable, and import/export controls.

Node Types ​

NodeDescription
Start / EndEntry and exit nodes appropriate to the passive, active, or convert workflow type.
ConditionsIf / Else, If / Else JS, HTTPQL Match, Scope Match, String Contains, and Regex Match.
EncodingBase64, URL, Hex, and HTML encode/decode.
Formatting and hashesJSON Minify/Prettify, MD5, SHA-1, and SHA-256.
Text operationsTrim, Join, Split, Match & Replace, JQ Transform, and Grep Extract.
JavaScriptCustom logic using the workflow SDK; can read traffic, operate on files, and create findings.
IntegrationLog, Webhook, Invoke Workflow, Send Request, and Match & Replace Rule.

Use the node palette for the actual ports and configuration. Click a connection to work with that link rather than deleting a node to reconnect the graph. Save with Save or Ctrl+S (Command+S on macOS).

Sharing and Scope ​

Workflows are shared across projects in the same workspace by default. Enable Project-specific to keep a definition with its project. Shared definitions do not mean every project's traffic, results, or notes become shared. Export/import workflow JSON when moving to another workspace or installation.

Testing Before Live Use ​

Passive and active workflows have an HTTP test section with URL, raw Request, and raw Response fixtures. Enable the workflow, fill those fields, and click Test workflow. The test saves edits before executing. Fixture values are retained per workflow as you navigate away and back.

A convert workflow instead has Test input and output. Start with a small representative input, then test a realistically sized asset. A fixture does not make arbitrary JavaScript or Send Request nodes harmless: workflow code can still perform its configured actions.

JavaScript and Files ​

Workflow JavaScript supports the Ogma SDK and compatible fs/path imports. Use sdk.fs.readFile, writeFile, appendFile, exists, readDir, mkdir, and unlink for file operations, and sdk.path for platform-aware paths. These are Ogma helpers, not the entire Node.js standard library.

For an asset exporter, read response.getBody().toText(), choose a destination with sdk.path.join, create its parent directory, and check sdk.fs.exists if you do not want to overwrite an existing file. Review filesystem paths before execution: workflow filesystem helpers run on the Ogma host, unlike a plugin's private-directory sdk.fs. See plugin SDK for that distinct runtime.

Importing a Workflow ​

  1. Click Import in the Workflows toolbar.
  2. Select a JSON workflow file.
  3. The workflow opens in the canvas. Verify the node configuration before enabling it.
  4. Save the workflow.

Exported workflow JSON files can be shared between Ogma installations or stored in version control.

Running a Workflow on Captured History ​

Active workflows can be re-run against previously captured requests.

  1. Open the workflow.
  2. Click Run on history.
  3. In the scan history modal, enter an optional HTTPQL filter to limit which requests the workflow processes.
  4. Click Run.

Review the matching count and start the job. Progress and errors appear in the scan job and, when logging is enabled, its run history. Passive workflows offer Scan History and Re-run on request for retrospective processing.

For a few interesting assets, select one or more HTTP History rows, right-click, choose Send to Workflow, and select an enabled active workflow. This feeds the selected entries to it without changing its definition or processing the whole history.

The AI Assist button next to the scan history filter input generates a HTTPQL expression from a plain-language description.

Workflow Runs and Results ​

Enable Enable logging in workflow configuration when you need execution details. It applies to passive, active, and convert workflows, including Match & Replace conversions. When disabled, processing still runs but does not add run/step logs; re-enable it and repeat a test to diagnose an issue.

  • Click a run to see per-node step output.
  • Nodes that produced errors are highlighted.
  • Findings created during the run appear in the Findings view.
  • Variables extracted during the run are visible in the step detail panel.

Clear All removes the selected workflow's stored run history. Download logs before clearing them if you need to retain debugging evidence. Logging can store large outputs such as complete script bodies, so leave it off for high-volume conversions unless needed.

Enabling a Passive Workflow ​

  1. Open the workflow.
  2. Verify the canvas configuration is complete (no disconnected required ports).
  3. Toggle Enable in the toolbar.

Enabled passive workflows process new traffic automatically. Disable a workflow to pause it without deleting it.

Proprietary software. All rights reserved.