Courier Control Tab
Connect Courier to Guard and configure capture and activity settings
Overview
The Control tab establishes Courier's connection to Guard and defines the context in which Burp data is synchronized. It also contains capture settings, connection metrics, and the Courier activity log.
Dashboard
The dashboard at the top of the Control tab summarizes the current session:
Guard connection — Shows whether Courier is disconnected, connecting, or connected.
Capture policy — Shows whether capture applies to all traffic or only Burp in-scope traffic.
Pending records — Shows records waiting to be synchronized.
Last upload — Shows when Courier last completed a successful upload.
Use these indicators to confirm that Courier is connected and processing data as expected.
Connection and Project Settings
Guard Environment
Keep Guard Production selected for the standard Guard service. Choose Custom... only when you have been given a different HTTPS Guard endpoint.
Custom endpoints must use HTTPS.
API Key ID and Secret
Courier authenticates to Guard with an API key ID and API key secret. Generate credentials using Authentication to Guard.
Enter the values exactly as provided. Guard displays the API key secret only once when the key is created.
Project
Enter the project name that should be associated with Courier uploads. Use the project name agreed upon for the authorized testing activity.
Target Application
Enter the HTTP or HTTPS URL of the application being tested. This identifies the application context associated with synchronized Burp data.
Tenant
To select a tenant:
Enter the Guard environment and API credentials.
Click Refresh accounts.
Select an authorized tenant from the list.
Courier only displays tenants accessible to the supplied credentials.
Connect to Guard
Confirm the Guard environment.
Enter the API key ID and secret.
Enter the project and target application.
Select the tenant when applicable.
Review the capture policy before connecting.
Click Connect.
Read the Courier data-upload disclosure.
Click Yes only if the described upload is appropriate for the authorized testing activity.
After Guard authenticates the credentials, the connection status changes to Connected and capture begins under the selected policy.
Capture Policy
Review these settings before connecting:
ML-Based Training
ML-based training is enabled by default. Disable it before connecting when captured data must not be included in training workflows.
Burp Target Scope
Enable Burp target scope to capture only requests that Burp considers in scope. Leave it disabled to capture eligible traffic regardless of Burp scope.
Use Burp scope help for guidance on the related Burp setting.
Proxy Data in Log
Enable Proxy data in log when additional Proxy capture information is needed for troubleshooting. Leave it disabled during normal use when the additional information is unnecessary.
Excluded Extensions
The Excluded extensions field is a comma-separated list of file extensions Courier should omit from capture. Edit the list and press Enter or move focus away from the field to apply the change.
Activity Log
The Activity area shows Courier connection, capture, synchronization, and error messages.
Available controls include:
Error, Info, and Debug log levels
Clear to clear the displayed activity
Open log folder to open Courier's local log location
Use Info for normal operation. Switch to Debug when investigating a problem, then review the output before sharing it because operational logs can contain sensitive context.
Disconnect Courier
Click Disconnect when you no longer want Courier to capture or synchronize data. Disconnecting also stops active Planner polling and active webflow recording.
Confirm that the header and dashboard show Disconnected before beginning unrelated Burp work.