Burp Suite User Forum

Create new post

providing credentials for a web application which implements OAuth?

Nicholas | Last updated: Jun 15, 2020 02:58AM UTC

I'm attempting to live scan a web application which makes callouts to APIs which require an access token. Burp stops the scan and asks me for credentials with which it can make the call, but establishing a session requires an access token. How can I establish a session while scanning an application which makes OAuth-authenticated callouts to a server?

Michelle, PortSwigger Agent | Last updated: Jun 15, 2020 01:59PM UTC

Are you using Burp Suite Professional or Burp Suite Enterprise?

Andrey | Last updated: Nov 09, 2021 03:02PM UTC

Hi! Could you help me with the same problem? Is there any way to use Burp Professional with OAUTH 2.0?

Michelle, PortSwigger Agent | Last updated: Nov 10, 2021 11:56AM UTC

To help us get a better understanding of what you need to do, can you email us with a few more details on the site you're trying to test, your current setup in Burp, and where you're hitting issues with the authentication, please? If you can send that over to support@portswigger.net along with the version of Burp you're using, we'll take a closer look and be in touch.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.