Anthropic (API)
The Anthropic backend calls the native Anthropic Messages API (/v1/messages) directly — Claude models without a CLI wrapper. Unlike the Claude CLI backend (which shells out to the claude binary), this is a first-class HTTP backend: requests go through Burp's own Montoya HTTP stack, so all Anthropic traffic is visible in Proxy > HTTP history. Introduced in v0.9.0.
Requirements
An Anthropic API key (
sk-ant-…) from console.anthropic.com.
Setup
Open the AI Backend settings tab and select Anthropic as the Preferred Backend.
Enter your API key. It is encrypted at rest (AES-256-GCM,
ENC1:-prefixed) and never written to logs or exported settings.Set the Model — a free-form field, so you can use any current Anthropic model without an extension update. Defaults to a current Claude Sonnet alias (e.g.
claude-3-5-sonnet-20241022).Click Save, then Test connection to confirm the key and model are accepted.
Configuration
Preferred Backend
Anthropic
Anthropic API Key
sk-ant-… (stored AES-256-GCM encrypted)
Anthropic Model
free-form; default claude-3-5-sonnet-20241022
Base URL
https://api.anthropic.com (/v1/messages)
Timeout
30 s (raise for large prompts or slow links)
Notes
Proxy-visible by design. All requests to
api.anthropic.comroute throughMontoyaHttpTransport— not a vendored Anthropic SDK — so they respect Burp's upstream proxy, TLS, and logging and appear in Proxy > HTTP history like any other request (#69).Token counting. Anthropic's usage fields (input / output / cache-read / cache-write) are surfaced per request and feed the token-budget guardrails.
Encrypted key. The API key is encrypted with a per-install master key; the plaintext value never appears in logs or exported settings.
Scope (v0.9.0). Ships streaming (single-chunk, proxy-visible — the transport buffers the response, matching every other HTTP backend), token counting, model selection, and the encrypted key. Native tool-use and prompt caching are deferred to a future release.
Error Handling
A 400 response whose body mentions model surfaces a specific message — "Anthropic rejected the model ID — check Settings > Anthropic > Model" — instead of a generic error, so a model-name typo is obvious.
Retry Behavior
Like the other HTTP backends, Anthropic requests retry on transient network errors with bounded stepped backoff and are wrapped in the shared circuit breaker (5 consecutive failures open it for 30 s before a half-open probe). See Backends Overview → Retry Behavior.
Related Pages
Claude CLI — the CLI-based alternative
Last updated
