Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
burp-rest-api — REST/JSON API to the Burp Suite security tool. | Kitploit
Tools/GitHubGitHub/vmware-archive/burp-rest-api
Vulnerability ScannersWeb Proxies & InterceptionScripting & AutomationAPI Security TestingWeb SecurityPenetration TestingUtilities & FrameworksArchived
GitHubvmware-archive/burp-rest-api

burp-rest-api

REST/JSON API to the Burp Suite security tool.

View Repository
566115171 year agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

burp-rest-api

⚠️ WARNING: This project is no longer actively maintained.
While the repository will remain available for reference, no further updates, bug fixes, or support will be provided.

Overview

A REST/JSON API to the Burp Suite security tool.

Since the first commit back in 2016, burp-rest-api has been the default tool for BurpSuite-powered web scanning automation. Many security professionals and organizations have relied on this extension to orchestrate the work of Burp Spider and Scanner.

Getting Started

  1. Download the latest burp-rest-api JAR (e.g. burp-rest-api-2.3.2.jar) from the release page
  2. Place them within a directory having the original Burp Suite Professional JAR (e.g. burpsuite_pro_v2025.6.3.jar). Important: This is supposed to be the standalone JAR downloaded from https://portswigger.net/burp/releases. You should NOT use the burpsuite_pro.jar from a local Burp Suite installation
  3. Using Java 21, run burp-rest-api

On Linux, Mac:

java --add-opens=java.desktop/javax.swing=ALL-UNNAMED --add-opens=java.base/java.lang=ALL-UNNAMED -cp "burpsuite_pro.jar:burp-rest-api-2.3.2.jar" org.springframework.boot.loader.launch.JarLauncher

On Windows:

java --add-opens=java.desktop/javax.swing=ALL-UNNAMED --add-opens=java.base/java.lang=ALL-UNNAMED -cp "burpsuite_pro.jar;burp-rest-api-2.3.2.jar" org.springframework.boot.loader.launch.JarLauncher

Important!!!

  • Make sure to adjust the Burp Suite PRO and Burp Rest API JAR filenames
  • The standalone Burp Suite PRO JAR for ARM64 doesn't seem to contain the Burp Browser, hence spidering and scanning won't work. We would highly recommend to run this software on x86

Burp Suite Support and Limitations

burp-rest-api supports both the legacy Burp Suite Professional v1.7 and the newer Burp Suite Professional v2025.x. Since this project relies on Burp Extender API, the behaviour of certain functionalities might be slighlty different depending on the version of Burp. For example, the Burp Suite Scanner configuration in v2025.x is no longer customizable.

Configuration

By default, Burp is launched in headless mode with the Proxy running on port 8080/tcp (localhost only) and the REST endpoint running on 8090/tcp (localhost only).

To run Burp in UI mode from the command line, append the following argument:

    --headless.mode=false

To modify the server port on which the API is accessible, append the following argument:

    --server.port=8081

or

    --port=8081

You can also modify the server address, used for network address binding:

    --server.address=192.168.1.2

or

    --address=192.168.1.2

Command Line Arguments

The following command line arguments are used only by the extension to configure the run mode and port number.

--burp.jar=<filename.jar> : Loads the Burp jar dynamically, and expose it through REST APIs. This flag works on Java <= 1.8 only! Use the burp-rest-api.{sh,bat} script for newer java versions.

--burp.ext=<filename.{jar,rb,py} : Loads the given Burp extensions during application startup. This flag can be repeated.

--server.port=<port_number> : The REST API endpoint is available at the given port number. --port=<port_number> works as short hand argument.

--server.address=<network address> : Network address to which the REST API endpoint should bind. --address=<address_ip> works as short hand argument.

--apikey=<customApiKey> : Enables API key authentication to protect APIs at /burp/*. The customApiKey, if passed as an argument, must be included in every HTTP request as an additional header: "API-KEY: <customApiKey>".

--headless.mode=<true/false> : When set to false, runs Burp Suite in UI mode. Otherwise runs Burp Suite in headless mode. Default value: System Property (java.awt.headless)

Command line arguments passed to the executable burp-rest-api JAR are forwarded to the Burp Suite JAR. Hence, one may pass the following Burp Suite JAR command line arguments to the burp-rest-api JAR for the same functionality as if passing to the Burp Suite JAR directly.

--project-file=<filename> : Opens the specified Data Project File used for keeping the state of the tool. The file will be created as a new project if it doesn't exist already.

--config-file=<filename> : Opens the project using the options contained in the selected Project Configuration File. To load multiple project configurations, this argument can be passed more than once with different values.

--user-config-file=<filename> : Opens the project using the options contained in the selected User Configuration File. To load multiple user configurations, this argument can be passed more than once with different values.

For more information on Projects, refer to the Burp Suite documentation here and here. For scanner settings, please refer to the "Burp Suite Support and Limitations" section.

Default Burp Configuration

If the burp-rest-api JAR is launched without the --project-file, --config-file or --user-config-file arguments, then Burp Suite is launched with a temporary project file and some default configuration. The temporary project file gets created upon launch of Burp Suite, and gets deleted at the end of the run.

For the default configuration used to launch Burp Suite, please refer to the files burp-default-project-options.json and burp-default-user-options.json inside the JAR under the static folder.

HTTP API

Swagger is used to define API documentation. Once the JAR is launched, access the following resources for API docs and Swagger UI. Port 8090 is the default server port.

API Docs: http://localhost:8090/v3/api-docs

Swagger UI: http://localhost:8090/swagger-ui/index.html#

Client

This project also comes with a client (BurpClient.java) written in Java for use in other projects. Refer to the Integration Test file BurpClientIT.java for the usage of BurpClient.java.

Credits

This project is originally inspired from Resty-Burp, and is developed in partnership with Doyensec LLC.

Contributing

The burp-rest-api project team welcomes contributions from the community. If you wish to contribute code and you have not signed our contributor license agreement (CLA), our bot will update the issue when you open a Pull Request. For any questions about the CLA process, please refer to our CLA FAQ. For more detailed information, refer to CONTRIBUTING.md and FAQ.md.

Extension Development

The following section contains useful information to get started with the development of the extension.

Prerequisites

  • Java 21 x64
  • Gradle
  • Licensed Burp Suite Professional from: http://portswigger.net/burp/. Standalone JAR.

Build & Run

  1. Download the Professional edition of Burp Suite JAR
  2. The project can be run by directly launching the JAR created from building the project
  3. Create a lib folder under the project directory and place the Burp Suite JAR file into it and rename it to "burpsuite_pro.jar" in order to run the integration tests
Download Tool