Get started¶
OWTF is a browser-based workspace for authorized web security assessments. The supported installation runs the application with Docker Compose so the Python service, web application, PostgreSQL database, and external tool dependencies stay isolated from your host system.
The shortest path¶
- Install OWTF with Docker Compose.
- Open the web interface at
http://localhost:8019. - Create your first assessment.
- Use the troubleshooting guide if the stack does not become healthy.
What you need¶
- Git
- Docker Engine or Docker Desktop
- Docker Compose v2, available through the
docker composecommand - Enough memory and disk space for the application images and security tools
- Explicit authorization for every target you test
No host-level Python or Node.js installation is required for the supported end-user path.
Service addresses¶
| Service | Address | Purpose |
|---|---|---|
| Web interface | http://localhost:8019 |
Use OWTF in a browser |
| Backend API | http://localhost:8009 |
Application API used by the web interface |
| Intercepting proxy | localhost:8008 |
Route authorized HTTP and HTTPS traffic through OWTF |