Skip to main content
Avoid using Momentic tests to log in with SSO. Providers like Google, Facebook, and GitHub use CAPTCHAs and bot detection to block automated browsers.
This page covers how to obtain credentials for specific login mechanisms. For where to put login steps (inline, in the before section, or a cached auth module) and which approach to choose, see Authentication strategies.

Username and password

The basic case: add a Type step for the username, a Type step for the password, and a Click on the submit button. Pull the values from environment variables ({{ env.TEST_USERNAME }}) rather than hard-coding credentials in the test file.
Prerequisites: Momentic must provision an email address.
Add a JavaScript step with the following content:
Use the step’s Save to environment variable option to save the link, e.g. as MAGIC_LINK. Then use a Navigate step with {{ env.MAGIC_LINK }} to finish logging in.

Email one-time password (OTP)

Prerequisites: Momentic must provision an email address.
Add a JavaScript step with the following content:
Use the step’s Save to environment variable option to save the code, e.g. as OTP_CODE. Then use a Type step with {{ env.OTP_CODE }} to enter the code and finish logging in.

SMS one-time password (OTP)

Prerequisites: Momentic must provision an SMS number.
Add a JavaScript step with the following content:
Use the step’s Save to environment variable option to save the code, e.g. as OTP_CODE. Then use a Type step with {{ env.OTP_CODE }} to enter the code and finish logging in.

Vercel Deployment Protection

Follow Vercel’s protection bypass for automation guide. Configure the bypass header in your test options.

IP allowlist

If your test environment restricts inbound traffic by IP, allowlist Momentic’s fixed egress IP for hosted runs: 34.106.239.183. On Azure-hosted deployments, allowlist both 52.177.232.247 and 20.14.51.42.