The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

How do I "Include an API definition as part of the Burp Scanner launch process"?

Timothy | Last updated: May 19, 2023 05:03PM UTC

On the tin, it says that I can now, "Include an API definition as part of the Burp Scanner launch process. Burp Scanner will use this API definition to seed its scan - enhancing its ability to scan APIs and microservices." Can I get an example of how this works in the latest, stable Burp Suite Professional? I've got my OpenAPI 3 YAML definition file on hand...but, no clue how I tell Burp to digest it. Documentation is either lacking or very well hidden...

Michelle, PortSwigger Agent | Last updated: May 22, 2023 12:15PM UTC

Hi When you start a scan, Burp Scanner will attempt to scan any API definitions it encounters as part of its regular crawling activity. You also have the option of providing the URL of the API definition explicitly when launching a scan. Where is your API definition hosted? If you would like to send us some screenshots showing your scan setup, feel free to email them to support@portswigger.net.

Timothy | Last updated: May 22, 2023 02:31PM UTC

Ah, I see: the ability to read in a locally provided API definition file is still forthcoming. Any ETA when that will be a feature? Thanks!

Michelle, PortSwigger Agent | Last updated: May 23, 2023 10:03AM UTC