Files
promptfoo--promptfoo/site/docs/red-team/troubleshooting/multi-turn-sessions.md
T
wehub-resource-sync 0d3cb498a3
CI / Shell Format Check (push) Has been cancelled
CI / Check Ruby (3.4) (push) Has been cancelled
CI / CI Config (push) Has been cancelled
CI / Test on Node ${{ matrix.node }} and ${{ matrix.os }}${{ matrix.shard && format(' (shard {0}/3)', matrix.shard) || '' }} (push) Has been cancelled
CI / Build on Node ${{ matrix.node }} (push) Has been cancelled
CI / Style Check (push) Has been cancelled
CI / Generate Assets (push) Has been cancelled
CI / Check Python (3.14) (push) Has been cancelled
CI / Check Python (3.9) (push) Has been cancelled
CI / Build Docs (push) Has been cancelled
CI / Code Scan Action (push) Has been cancelled
CI / Site tests (push) Has been cancelled
CI / webui tests (push) Has been cancelled
CI / Run Integration Tests (push) Has been cancelled
CI / Run Smoke Tests (push) Has been cancelled
CI / Go Tests (push) Has been cancelled
CI / Share Test (push) Has been cancelled
CI / Redteam (Production API) (push) Has been cancelled
CI / Redteam (Staging API) (push) Has been cancelled
CI / GitHub Actions Lint (push) Has been cancelled
CI / Check Ruby (3.0) (push) Has been cancelled
release-please / release-please (push) Has been cancelled
release-please / build (push) Has been cancelled
release-please / publish-npm (push) Has been cancelled
release-please / publish-npm-backfill (push) Has been cancelled
release-please / docker (push) Has been cancelled
release-please / publish-code-scan-action (push) Has been cancelled
release-please / attest-code-scan-action (push) Has been cancelled
Deploy local.promptfoo.app / Deploy to Cloudflare Pages (push) Has been cancelled
Test and Publish Multi-arch Docker Image / test (push) Has been cancelled
Test and Publish Multi-arch Docker Image / build-docker-and-push-digests (map[digest-suffix:linux-amd64 platform:linux/amd64 runner:ubuntu-latest]) (push) Has been cancelled
Test and Publish Multi-arch Docker Image / build-docker-and-push-digests (map[digest-suffix:linux-arm64 platform:linux/arm64 runner:ubuntu-24.04-arm]) (push) Has been cancelled
Test and Publish Multi-arch Docker Image / merge-docker-digests (push) Has been cancelled
Test and Publish Multi-arch Docker Image / Attest Multi-arch Image (push) Has been cancelled
Validate Renovate Config / Validate Renovate Configuration (push) Has been cancelled
chore: import upstream snapshot with attribution
2026-07-13 13:24:08 +08:00

1.8 KiB

sidebar_label, description
sidebar_label description
Multi-Turn Session Management Red team multi-turn conversation attacks by exploiting session management vulnerabilities to protect AI systems from context manipulation and unauthorized state access

Session Management

Session management is important for multi-turn strategies like Crescendo, GOAT, and Hydra. In these cases you want to make sure that the target system is able to maintain context between turns.

Use the default replay mode when the target expects the full conversation transcript in every request. Use stateful: true only when the target provider stores prior turns and expects just the newest message on each request.

For HTTP and WebSocket targets, there are two common ways sessions can be managed:

  1. Client Side Session
  2. Server Side Session

Client Side Session Management

If you are using a Promptfoo provider like HTTP or WebSocket, Promptfoo has a built-in function to generate a unique UUID for each test case. The UUID can then be used to maintain context between turns.

Follow the instructions in the Client Side Session Management docs.

Server Side Session Management

Promptfoo provides tools to extract the Session ID from the response and pass it to the next turn.

Follow the instructions in the Server Side Session Management docs.

OpenAI Agents SDK Sessions

If you are using the built-in JavaScript openai:agents:* provider, use the stateful red-team session pattern instead of the HTTP-specific patterns above.