# ── Fuzzer Config: OAuth2 client credentials -> API endpoint ────────────── # # Placeholders: # {{FUZZ}} — replaced with each payload from your wordlist # {{AUTH}} — bearer token (auto-filled after auth step) # {{KEY}} — any key from your vars file ({{TOKEN}}, {{USERNAME}}, etc.) name: "OAuth2 API Fuzz" auth: url: "https://auth.example.com/oauth2/token" # method: POST # default # headers: # Authorization: "Basic {{CLIENT_CREDS}}" # Content-Type: "application/x-www-form-urlencoded" # body: "grant_type=client_credentials" # default token_field: "access_token" cache: 280 request: url: "https://api.example.com/v1/query" method: POST headers: Authorization: "Bearer {{AUTH}}" Content-Type: "application/json" body: '{"prompt": "{{FUZZ}}"}' fuzz_encoding: json settings: skip_tls_verify: false timeout: 30 delay: 0 # proxy: "http://127.0.0.1:8080"