The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Use a different Authentication Method and NOT the 'Detected' One during API Scan

Sandy | Last updated: Sep 10, 2024 01:53PM UTC

Tool: Burpsuite Professional License (Latest major/Minor version) Scan Scenario: Web API scan with authentication using Bearer token and NOT api Key. What Tester did so far: After uploading API definition successfully, they reached Authentication tab where The tab shows an already ‘Detected ‘ Authentication method of ‘API Key’ type. ‘API Key’ type is not what we want unless we are confused with terminologies and aliases of some kind. When we use Detected one and give a valid token, requests are failing - by large - returning 401. We need to add a New Bearer Authentication and want to delete ‘Detected’ one. However on the GUI, Delete is disabled for that. Questions: Q1. How can I delete ‘Detected’ one and add what I need to?

Dominyque, PortSwigger Agent | Last updated: Sep 11, 2024 08:04AM UTC