The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Configure authorization headers to test REST API endpoints

AYOUB | Last updated: Jul 31, 2023 12:44PM UTC

Hello, I have a project where i should automate pentests on REST APIs so using the BURP REST API with python i gave it the URLs with its endpoints and started the scanning but i noticed that in all requests sent it does not add the authorization header with a JWT for example and test with its parameters is there a configuration i am missing ? is it even feasable or should i give it real requests with all the headers then scan based on them?

Michelle, PortSwigger Agent | Last updated: Jul 31, 2023 03:08PM UTC