Help

Troubleshooting

Resolve common setup blockers, assessment launch issues, authentication problems, and finding workflow questions.

Last updated August 2, 2026
On this page

This page covers common issues that prevent applications from becoming ready or assessments from running correctly.

#Quick route for common blockers

Use this list when you know the symptom but not the product area.

#Application setup issues

#Domain verification is pending

Check that the DNS record is on the correct domain and has propagated. If verification fails, confirm the domain and TXT value have no typos, then wait and retry.

If an application says the domain is not verified, open Administration, expand the domain, and confirm the TXT record matches Tahr. Enter the domain name only.

A verified parent domain covers subdomains. For example, verifying example.com covers app.example.com and api.example.com.

#Application stays in draft

Open the application setup review step and read the blockers. Common causes are missing domain verification, incomplete authentication, or missing repository access. Resolve the first blocker, then review Application Setup.

#Authenticated testing cannot be saved

Confirm that the Login URL is a full public HTTP(S) URL where sign-in begins. The Authentication Check URL must be a full URL on the configured application or API origin and prove the user is logged in. Public third-party or custom identity-provider redirects can be intermediate steps, but do not use them as the final check. See Authenticated Testing.

Check that each test user has the required username, role, tenant, password or account reference, and second-factor configuration.

#Authentication issues

#Authentication Check URL always returns 200

Do not use a public homepage, health check, static asset, or generic API route as the authentication check URL. If the same response is returned before and after login, Tahr cannot use it to prove the session worked.

Use an endpoint that returns authenticated user-specific data, such as /me, /profile, /account, /api/me, /api/user, or /api/profile. The exact URL depends on your application, but the response must differ meaningfully between logged-out and logged-in requests.

If the application uses SSO or tenant selection after login, record that detail in Extra context for authentication and Sign-in automation.

#2FA setup fails

Confirm the second-factor method for each user. Mark users that do not need it accordingly.

For authenticator app codes, confirm the setup value is complete. For SMS codes, confirm the selected organization phone number is available. See Administration.

#Assessment launch issues

#Source-code analysis is unavailable

Confirm the application has a repository URL and that Integrations can reach the selected private repository and branch.

If the repository moved or permissions changed, update the integration and test the connection from Integrations.

#Assessment cannot start

Check that the application is ready and that the selected type matches its setup. Some types require authentication, repository access, API files, or mobile artifacts.

If the target is behind a WAF or allowlist, confirm Reserved IPs and launch options before retrying.

#New assessments are temporarily unavailable

New manual, CI/CD, or routine launches may be unavailable while existing assessments continue. Scheduled occurrences may be skipped or advanced; check the visible status and try again later.

#Credits or plan are unavailable

If Tahr reports insufficient credits or plan limitations, open Billing. Choose an available assessment or contact Tahr Support if the displayed capacity is unexpected.

#Provided routine templates are missing

Templates appear only when available assessment types are available for the selected application. Create a routine manually or resolve the readiness blocker shown by Tahr.

#Reserved IP cannot be released

Tahr blocks release when the IP is being used by an active assessment or routine, or is not in a releasable state. Wait for the work to finish, choose another IP when the release prompt offers that option, or try again after the status changes. See Administration.

#Assessment recovery

Check the visible status and message before retrying, and avoid duplicate active or queued launches. When offered, pause or resume the run; cancel it if the work must stop. Cancelling queued routine steps does not cancel an assessment that is currently active.

Use Retry cleanup only when the assessment finished but cleanup failed. Before retrying, resolve the visible readiness, credits, authentication, launch availability, or WAF/IP blocker. For manual IP selection, see Choose an IP and Running Assessments.

#Automation and integration issues

#Ticket status is not syncing

Open the finding and choose Refresh ticket status. Test the ticketing connection and confirm the external issue still exists. Update or reconnect it from Integrations if refresh continues to fail.

#Reauthentication is requested during an account change

Complete the reauthentication prompt for a sensitive account change. If it fails, cancel the change, sign in again, and retry once.

#Threat Modeling or application documents are unavailable

Threat Modeling needs repository access, and documents may be unavailable until the application draft is saved. Save the application, check readiness messages, and upload a supported document when the document area appears.

#CI/CD trigger does not work

Confirm the pipeline uses the current trigger token stored as a secret, and that the requested assessment type is allowed for CI/CD.

Avoid retry loops that repeatedly trigger assessments after a failure. Fix the setup issue first, then review Running Assessments.

#Routine uses the wrong source or recon output

Open the routine and check each step's input settings. Steps run in order, and same-run outputs are used first.

If configured, a step falls back to the latest saved source-code analysis or recon output when the current run has not produced it. Disable fallback to require fresh same-run output.

Put the producing step before the consumer. Use a dedicated non-production environment for every assessment; do not run production testing. See Routines.

#Findings look unexpected

Review application context, test-user permissions, and assessment scope. Unexpected access or missing setup context can make a finding look incorrect.

Use comments to capture review decisions so other teammates understand whether the finding is valid, accepted, duplicate, or not applicable.

#Contact Support

Use the in-app Support widget. Choose Bug for a product malfunction or Support for usage or access help. Include the active organization, application, assessment name or ID when visible, timestamp, visible error, concise steps, and only safe screenshots.

Never include passwords, tokens, TOTP or recovery secrets, test credentials, customer data, or private repository content. If organization Slack support is offered or pending, follow the visible status and do not repeatedly request it.

Image preview