# PortSwigger

**Canonical:** https://apis.io/providers/portswigger/  
**Website:** https://portswigger.net  
**APIs profiled:** 5

PortSwigger is the UK-based security research company behind Burp Suite, the industry-standard web and API security testing platform used by penetration testers and enterprise AppSec teams worldwide. The platform is available as Burp Suite Community Edition (free), Burp Suite Professional (manual testing toolkit), and Burp Suite DAST (enterprise dynamic application security testing). Developers can automate and integrate with Burp Suite DAST via a GraphQL API and a REST API, both secured with API key authentication. PortSwigger also provides the Montoya extension API for building custom Burp Suite extensions and an official MCP Server extension that bridges Burp Suite with AI clients such as Claude Desktop.

## Kin Score — 40.0 / 100 (developing)

Scored 2026-08-21 under rubric 0.12.0. Trend: flat (+0.0 from 40.0).

| Facet | Score |
|---|---|
| Discoverability | 64.8 |
| Contract Quality | 52.2 |
| Governance | 0.0 |
| Contract Governance | 0.0 |
| Operational Transparency | 50.0 |
| Developer Ergonomics | 11.9 |
| Commercial Clarity | 57.9 |
| Access Clarity | 57.9 |

## Agent readiness — 18.4 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | no |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | no |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Freemium — onboarding: unknown, pricing: freemium, trial: no (confidence: medium).

## APIs (5)

- **Burp Suite DAST GraphQL API** — The primary API for integrating with Burp Suite DAST, recommended for all new integrations. Exposes the broadest range of functionality including managing sites, initiating and ...
- **Burp Suite DAST REST API** — A REST API for Burp Suite DAST that offers compatibility for users familiar with the Burp Suite Professional API. Supports initiating scans from CI/CD systems and failing builds...
- **Burp Suite Professional REST API** — A local REST API built into Burp Suite Professional that allows external tools to interact with the running Burp Suite instance. Accessible at a configurable local service URL a...
- **Burp Suite Montoya Extension API** — The Java-based extension API for building custom Burp Suite extensions (BApps). The Montoya API is the current standard for extension development, superseding the legacy Wiener ...
- **Burp Suite MCP Server** — An official Model Context Protocol (MCP) server extension for Burp Suite that bridges Burp Suite capabilities to AI clients such as Claude Desktop. Runs as an SSE server on loca...

## Security (2)

- **Portswigger Domain Security** — TLSv1.3 · DMARC
- **Portswigger Trust Center** — ISO 27001, GDPR

## Plans (1)

- **Portswigger Plans Pricing**

## Tags

Security, Web Security, Penetration Testing, DAST, API Security, Developer Tools

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/portswigger/). Scores are computed from the provider's own public artifacts under a published rubric.
