Courier Control Tab

Connect Courier to Guard and configure capture and activity settings

Overview

The Control tab establishes Courier's connection to Guard and defines the context in which Burp data is synchronized. It also contains capture settings, connection metrics, and the Courier activity log.

Dashboard

The dashboard at the top of the Control tab summarizes the current session:

  • Guard connection — Shows whether Courier is disconnected, connecting, or connected.

  • Capture policy — Shows whether capture applies to all traffic or only Burp in-scope traffic.

  • Pending records — Shows records waiting to be synchronized.

  • Last upload — Shows when Courier last completed a successful upload.

Use these indicators to confirm that Courier is connected and processing data as expected.

Connection and Project Settings

Guard Environment

Keep Guard Production selected for the standard Guard service. Choose Custom... only when you have been given a different HTTPS Guard endpoint.

Custom endpoints must use HTTPS.

API Key ID and Secret

Courier authenticates to Guard with an API key ID and API key secret. Generate credentials using Authentication to Guard.

Enter the values exactly as provided. Guard displays the API key secret only once when the key is created.

Project

Enter the project name that should be associated with Courier uploads. Use the project name agreed upon for the authorized testing activity.

Target Application

Enter the HTTP or HTTPS URL of the application being tested. This identifies the application context associated with synchronized Burp data.

Tenant

To select a tenant:

  1. Enter the Guard environment and API credentials.

  2. Click Refresh accounts.

  3. Select an authorized tenant from the list.

Courier only displays tenants accessible to the supplied credentials.

Connect to Guard

  1. Confirm the Guard environment.

  2. Enter the API key ID and secret.

  3. Enter the project and target application.

  4. Select the tenant when applicable.

  5. Review the capture policy before connecting.

  1. Click Connect.

  2. Read the Courier data-upload disclosure.

  3. Click Yes only if the described upload is appropriate for the authorized testing activity.

After Guard authenticates the credentials, the connection status changes to Connected and capture begins under the selected policy.

Capture Policy

Review these settings before connecting:

ML-Based Training

ML-based training is enabled by default. Disable it before connecting when captured data must not be included in training workflows.

Burp Target Scope

Enable Burp target scope to capture only requests that Burp considers in scope. Leave it disabled to capture eligible traffic regardless of Burp scope.

Use Burp scope help for guidance on the related Burp setting.

Proxy Data in Log

Enable Proxy data in log when additional Proxy capture information is needed for troubleshooting. Leave it disabled during normal use when the additional information is unnecessary.

Excluded Extensions

The Excluded extensions field is a comma-separated list of file extensions Courier should omit from capture. Edit the list and press Enter or move focus away from the field to apply the change.

Activity Log

The Activity area shows Courier connection, capture, synchronization, and error messages.

Available controls include:

  • Error, Info, and Debug log levels

  • Clear to clear the displayed activity

  • Open log folder to open Courier's local log location

Use Info for normal operation. Switch to Debug when investigating a problem, then review the output before sharing it because operational logs can contain sensitive context.

Disconnect Courier

Click Disconnect when you no longer want Courier to capture or synchronize data. Disconnecting also stops active Planner polling and active webflow recording.

Confirm that the header and dashboard show Disconnected before beginning unrelated Burp work.