Burp Suite User Forum

Create new post

Authenticated API Scan

Niall | Last updated: Apr 11, 2024 04:10PM UTC

How can I perform an authenticated API scan using the new API scanning functionality? I am uploading the OpenAPI schema file, which is parsed correctly. However, there is no option to define a bearer token or similar authentication header. If this is not currently possible, will it be implemented in the future?

Syed, PortSwigger Agent | Last updated: Apr 12, 2024 09:05AM UTC

Hi Niall,

The new API functionality lets you upload your API specs directly into Burp. However, it does not yet allow you to set the authentication. We are already working on it, and it will be available in the stable release sooner than you think, it might take a few weeks, though. Keep your eyes out for the update; it will be exciting for all of our API customers.

Thanks again for being a Burp Pro user.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.