Professional

Getting started with Burp AT

  • Last updated: July 23, 2026

  • Read time: 2 Minutes

This page explains how to set up Burp AT and send your first prompts.

What you need

To use Burp AT, you need:

  • Burp Suite Professional 2026.7 or later.

  • A PortSwigger account with a valid Burp Suite Professional license associated.

  • AI credits on your account. For more information, see AI credits.

  • Outbound HTTPS access to ai.portswigger.net on port 443. For help with connectivity to PortSwigger's AI services, see Troubleshooting AI connectivity.

Opening Burp AT

To open Burp AT, click the Burp AT button in the top-right corner of Burp.

The first time you open Burp AT, Burp prompts you to sign in to your PortSwigger account. Sign in with the account your Burp Suite Professional license is registered to. You only need to sign in once, and logins expire after two weeks of inactivity.

Why you need to sign in to Burp AT

Burp AT keeps a persistent, private workspace for your data. Your tasks, goals, and findings are saved, enabling you to pick up where you left off. Because that data is sensitive and specific to you, we need you to authenticate when you access Burp AT.

Running your first task

Burp AT automatically creates a new task when you open it. To get started, send a prompt. Enter a description of what you want it to test or find in the message box and press the return key.

Burp AT is conversational. You can set its overall goal with your first prompt, then guide it with follow-up prompts: dig into a result, adjust what you asked for, or point it at something new.

For tips on writing effective prompts, see Prompting Burp AT effectively.

You can shape how Burp AT works by attaching context and configuring its level of autonomy:

  • Attach context. You can give Burp AT more to work from by attaching items from Burp, such as issues, HTTP history items, or site map nodes. The more relevant context you provide, the more focused and accurate its results. For information on adding context, see Tasks.

  • Set its autonomy. By default, Burp AT works independently but asks before high-impact or risky actions. You can set it to ask before every action, let it run autonomously, or set permissions tool by tool. For more information, see Configuring autonomy.

Once it's working, Burp AT plans an approach and carries it out using Burp's own tools. It records confirmed vulnerabilities as issues in Burp and logs its actions so you can verify its work.

More information