Professional

SpecOps, OpenAPI/Swagger Workbench

SpecOps ingests an OpenAPI or Swagger specification and builds a workbench for testing every documented endpoint. Specs can be loaded from a file, URL, or pasted directly, and the extension provides tooling for parameter management, authentication, custom headers, and bulk request execution.

Features

  • Import API specifications from a local file, a remote URL, or by pasting content directly into the extension.
  • Global parameter store with import and export support, proxy auto-fill, and automatic value generation.
  • Authentication profiles supporting API keys, Bearer tokens, JWT, Basic auth, and OAuth2.
  • Custom header rules with configurable scopes and overwrite control.
  • Endpoints workbench with request preview, bulk ping across all endpoints, and direct send to Repeater or Intruder.
  • Attack results panel with dedicated request and response viewers.
  • Multi-server mode to target every server entry defined in the loaded specification.

Usage

  1. Open the SpecOps tab that appears after the extension loads.
  2. Load your API specification by selecting a local file, entering a URL, or pasting the spec content into the import panel.
  3. Configure the global parameter store by adding, importing, or generating values for the parameters defined in the spec.
  4. Set up an authentication profile (API key, Bearer/JWT, Basic, or OAuth2) to apply credentials across requests.
  5. Define any custom header rules, specifying scope and whether existing headers should be overwritten.
  6. Browse the endpoints workbench, preview individual requests, or use bulk ping to probe all endpoints at once.
  7. Send selected endpoints to Repeater or Intruder for further testing, and review results in the attack results panel.
  8. If the spec defines multiple servers, enable multi-server mode to run requests against each defined server target.

Author

Author

rawatprince

Version

Version

1.4.2

Rating

Rating

Popularity

Popularity

Last updated

Last updated

27 August 2026

Estimated system impact

Estimated system impact

Overall impact: Empty

Memory
Empty
CPU
Empty
General
Empty
Scanner
Empty

You can install BApps directly within Burp, via the BApp Store feature in the Burp Extender tool. You can also download them from here, for offline installation into Burp.

You can view the source code for all BApp Store extensions on our GitHub page.

Follow @BApp_Store on Twitter to receive notifications of all BApp releases and updates.

Please note that extensions are written by third party users of Burp, and PortSwigger Web Security makes no warranty about their quality or usefulness for any particular purpose.

Go back to BappStore

Note:

Please note that extensions are written by third party users of Burp, and PortSwigger Web Security makes no warranty about their quality or usefulness for any particular purpose.