Burp Suite User Forum

Create new post

API Testing

Adetunji | Last updated: Mar 19, 2021 11:38AM UTC

Hi, I will need your help.I have a project that has to do with API pentest. How can Burp help me? I was given a url and token for the API . How can I connect to the API and test for vulnerability? Urgent please! Thank you

Uthman, PortSwigger Agent | Last updated: Mar 19, 2021 11:46AM UTC

Hi Adetunji,

Have you tried accessing the API in the embedded browser? Or via the Repeater with the appropriate authentication token/header added?

Jasmine | Last updated: Mar 22, 2021 04:46AM UTC

You can config Postman and BurpSuite with the same port, turn off intercept on BurpSuite, send request on Postman, BurpSuite will record all these request and display them on Site Trees. Then you active scan. Just try my guide and ask if it is not clear enough.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.