The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

providing credentials for a web application which implements OAuth?

Nicholas | Last updated: Jun 15, 2020 02:58AM UTC

I'm attempting to live scan a web application which makes callouts to APIs which require an access token. Burp stops the scan and asks me for credentials with which it can make the call, but establishing a session requires an access token. How can I establish a session while scanning an application which makes OAuth-authenticated callouts to a server?

Michelle, PortSwigger Agent | Last updated: Jun 15, 2020 01:59PM UTC

Are you using Burp Suite Professional or Burp Suite Enterprise?

Andrey | Last updated: Nov 09, 2021 03:02PM UTC

Hi! Could you help me with the same problem? Is there any way to use Burp Professional with OAUTH 2.0?

Michelle, PortSwigger Agent | Last updated: Nov 10, 2021 11:56AM UTC