# Burp Suite MCP server

> Drive Burp Suite from AI clients through an extension that exposes Burp over MCP, with an SSE endpoint and a bundled stdio proxy.

- Listing: https://mcp.tc/i/burp-suite
- Connect: this is a local (stdio) server; install it on your machine (see Install). The listing link is a page, not an MCP endpoint.
- Type: local (stdio)
- Auth: no API key needed
- Category: [Security & Compliance](https://mcp.tc/c/security)
- Vendor: PortSwigger
- Homepage: <https://portswigger.net/bappstore/9952290f04ed4f628e624d0aa9dccebc>
- Repository: <https://github.com/PortSwigger/mcp-server>

## About

A Burp Suite extension that exposes Burp to MCP clients. Once loaded, an AI assistant can work with Burp from a chat, for example proxy history, Repeater and scanner issues. An optional setting lets the server expose tools that edit Burp configuration.

The extension runs inside Burp and serves SSE at http://127.0.0.1:9876 by default. Host and port are set in the MCP tab. For clients that only support stdio, a packaged proxy jar forwards requests to the SSE server. The extension has an installer that configures Claude Desktop. Java is required. No API key is needed.

## What it can do

- Connect Burp Suite to MCP clients over SSE or a stdio proxy
- Work with Burp from an AI assistant, including proxy history and Repeater
- Review scanner issues from the chat
- Optionally enable tools that edit Burp configuration
- Install into Claude Desktop with the built-in installer

## Example prompts

- "Show the most recent requests in my Burp proxy history."
- "Send this request to Repeater and change the id parameter."
- "List the scanner issues Burp has found so far."
- "Summarize the high severity findings in this Burp project."

## Install

### Claude Code

1. Run this in a terminal, in your project folder:

```bash
claude mcp add --transport stdio burp-suite -- java -jar mcp-proxy-all.jar --sse-url http://127.0.0.1:9876
```

2. Start Claude Code and type `/mcp`. **burp-suite** should show as connected.

Add `--scope user` to make it available in every project.

### Claude Desktop

1. Open **Settings → Developer → Edit Config**. It opens `claude_desktop_config.json`. Add:

`claude_desktop_config.json`:

```json
{
  "mcpServers": {
    "burp-suite": {
      "command": "java",
      "args": [
        "-jar",
        "mcp-proxy-all.jar",
        "--sse-url",
        "http://127.0.0.1:9876"
      ]
    }
  }
}
```

2. Save the file and restart Claude Desktop.

The file lives in `~/Library/Application Support/Claude/` on macOS and `%APPDATA%\Claude\` on Windows.

### Cursor

[Add to Cursor](<https://cursor.com/install-mcp?name=burp-suite&config=eyJjb21tYW5kIjoiamF2YSIsImFyZ3MiOlsiLWphciIsIm1jcC1wcm94eS1hbGwuamFyIiwiLS1zc2UtdXJsIiwiaHR0cDovLzEyNy4wLjAuMTo5ODc2Il19>) (opens Cursor)

Or add it by hand to `~/.cursor/mcp.json` (all projects) or `.cursor/mcp.json` (this project):

`mcp.json`:

```json
{
  "mcpServers": {
    "burp-suite": {
      "command": "java",
      "args": [
        "-jar",
        "mcp-proxy-all.jar",
        "--sse-url",
        "http://127.0.0.1:9876"
      ]
    }
  }
}
```

### VS Code

[Install in VS Code](<https://vscode.dev/redirect/mcp/install?name=burp-suite&config=%7B%22type%22%3A%22stdio%22%2C%22command%22%3A%22java%22%2C%22args%22%3A%5B%22-jar%22%2C%22mcp-proxy-all.jar%22%2C%22--sse-url%22%2C%22http%3A%2F%2F127.0.0.1%3A9876%22%5D%7D>) (opens VS Code)

Or from a terminal:

```bash
code --add-mcp '{"name":"burp-suite","type":"stdio","command":"java","args":["-jar","mcp-proxy-all.jar","--sse-url","http://127.0.0.1:9876"]}'
```

Or commit it to the repo in `.vscode/mcp.json`:

`.vscode/mcp.json`:

```json
{
  "servers": {
    "burp-suite": {
      "type": "stdio",
      "command": "java",
      "args": [
        "-jar",
        "mcp-proxy-all.jar",
        "--sse-url",
        "http://127.0.0.1:9876"
      ]
    }
  }
}
```

### Devin Desktop

1. Add it to `~/.config/devin/mcp_config.json` (macOS and Linux) or `%APPDATA%\devin\mcp_config.json` (Windows):

`mcp_config.json`:

```json
{
  "mcpServers": {
    "burp-suite": {
      "command": "java",
      "args": [
        "-jar",
        "mcp-proxy-all.jar",
        "--sse-url",
        "http://127.0.0.1:9876"
      ]
    }
  }
}
```

2. Refresh the MCP server list in Cascade.

Devin Desktop is the new name for Windsurf.

### Codex

```bash
codex mcp add burp-suite -- java -jar mcp-proxy-all.jar --sse-url http://127.0.0.1:9876
```

Or edit `~/.codex/config.toml` directly:

`config.toml`:

```toml
[mcp_servers.burp-suite]
command = "java"
args = ["-jar", "mcp-proxy-all.jar", "--sse-url", "http://127.0.0.1:9876"]
```

### Gemini CLI

```bash
gemini mcp add burp-suite java -- -jar mcp-proxy-all.jar --sse-url http://127.0.0.1:9876
```

This adds it to the current project. Add `-s user` to use it everywhere.

### Any client

Most clients that start local servers accept this shape:

```json
{
  "mcpServers": {
    "burp-suite": {
      "command": "java",
      "args": [
        "-jar",
        "mcp-proxy-all.jar",
        "--sse-url",
        "http://127.0.0.1:9876"
      ]
    }
  }
}
```

Zed puts servers under `context_servers` in its settings, with the same `command`, `args` and `env` fields.

## Details

- Last checked: 2026-10-03
- Listed: 2026-10-03
- Updated: 2026-10-03

---
Source: https://mcp.tc/i/burp-suite (mcp.tc is an independent directory, not affiliated with this server's publisher). Corrections: https://mcp.tc/report
