Burp Suite's CA certificate is a fake digital ID that lets the tool intercept and read encrypted traffic on your own device for testing purposes

When you use Burp Suite — a security testing tool — to examine how a web application sends data, you run into a problem: modern websites encrypt everything between your browser and their server. Burp Suite sits in the middle to watch that traffic, but the encryption blocks it from seeing anything.

To solve this, Burp Suite creates its own Certificate Authority (CA) certificate. This is a fake digital ID that your device trusts. When you install it, your browser believes Burp Suite is a legitimate authority and lets it decrypt the traffic passing through. This only works on your own machine — the website never sees it, and your real connection to the website stays encrypted.

Think of it like this: you're standing between two people having a private conversation. They're speaking in a code you can't break. So you convince both of them that you're a trusted translator. Now they let you hear what they're saying, even though they still think they're talking privately to each other.

Key Takeaways

  • Burp Suite's CA certificate is only for testing your own applications or websites you have permission to test — installing it is not a security threat if you use it correctly.
  • The certificate only works on the device where you install it and only affects traffic routed through Burp Suite, not your normal browsing.
  • You should remove the certificate when you're done testing, because any tool on your device could theoretically use it to spy on your encrypted traffic.
  • This certificate is different from the real certificates that websites use — it's a testing tool, not something that makes Burp Suite a legitimate authority on the internet.

How the certificate actually works on your device

When you install Burp Suite's CA certificate into your browser or operating system, you're adding a file that says "trust this issuer." Your device now treats Burp Suite as a legitimate certificate authority, the same way it treats Verisign or DigiCert — the real companies that issue certificates for actual websites.

Here's the sequence: you open your browser and navigate to a website. Normally, your browser connects directly to that website's server, receives its real certificate, verifies it's legitimate, and then encrypts the conversation. But if you've configured your browser to route traffic through Burp Suite, the request goes to Burp Suite first. Burp Suite intercepts it, creates a fake certificate for that website on the fly, and signs it with the CA certificate you installed. Your browser sees a certificate signed by an authority it trusts and allows the connection. Burp Suite decrypts the traffic, lets you examine it, and then re-encrypts it before sending it to the real website.

The website itself never knows this happened. It receives an encrypted connection from what looks like a normal browser. The encryption between your browser and the website is still real — Burp Suite just has a copy of the key.

Why you need it for security testing

If you're testing a web application you built or own, you need to see what data is actually being sent. Modern applications send passwords, tokens, personal information, and API calls — all encrypted. Without Burp Suite's interception, you can't see whether your application is leaking data, sending credentials in the wrong format, or making unnecessary requests.

Security researchers and developers use this to find bugs before attackers do. You might discover that your login form is sending the password in plain text inside the encrypted connection, or that session tokens are predictable, or that the application trusts any certificate without checking it properly. These are real vulnerabilities that need fixing, and you can't find them without being able to read the traffic.

The CA certificate is the only way to make this work. Without it, your browser would reject Burp Suite's fake certificates and refuse to connect, making testing impossible.

The security risk of leaving it installed

Once Burp Suite's CA certificate is on your device, any program running on that device could theoretically use it to decrypt your traffic. If malware gets installed, or if you run untrusted software, it could create fake certificates for any website and intercept your connections without your knowledge. You wouldn't see any warning because your device already trusts the issuer.

This is why the certificate should be temporary. Install it when you need to test, then remove it when you're done. Most security professionals keep it installed only on a dedicated testing machine or virtual environment, not on their everyday computer.

The risk is real but manageable: the certificate only affects traffic routed through Burp Suite or through a proxy configured to use it. Your normal browsing, even if malware is present, won't automatically go through Burp Suite. But if an attacker knows the certificate is there, they could configure malware to use it.

How to install and remove the certificate safely

Burp Suite generates the CA certificate automatically when you first run it. To install it, you export the certificate from Burp Suite and import it into your browser's certificate store or your operating system's trusted root store, depending on how you want to use it.

In Burp Suite, go to the Proxy settings, find the CA Certificate option, and export it as a DER or PEM file. Then open your browser's certificate settings (in Chrome, this is Settings > Privacy and Security > Manage Certificates; in Firefox, it's Preferences > Privacy & Security > Certificates). Import the file into the Trusted Root Certification Authorities store. Your browser will now accept Burp Suite's fake certificates.

When you're finished testing, remove the certificate by going back to your certificate store and deleting it. This is important — don't leave it installed indefinitely. If you test regularly, you might keep it on a virtual machine dedicated to testing, but remove it from machines you use for everyday browsing and banking.

The difference between Burp Suite's certificate and real website certificates

A real website certificate is issued by a legitimate Certificate Authority like Let's Encrypt or Sectigo. These companies verify that the person requesting the certificate actually owns the domain. The certificate proves to your browser that you're talking to the real website, not an imposter.

Burp Suite's CA certificate is fake. It doesn't prove anything about the website you're connecting to. It only proves that you trust Burp Suite as an issuer. This is fine for testing your own application on your own machine, but it's the exact technique an attacker would use to spy on your traffic if they could get their fake certificate installed on your device.

This is why installing random CA certificates from the internet is dangerous. If someone tricks you into installing a certificate they created, they can intercept all your encrypted traffic on that device. Burp Suite's certificate is safe because you're installing it intentionally for testing purposes, but the principle is the same.

When you should and shouldn't use Burp Suite

Use Burp Suite to test applications you own or have explicit permission to test. This includes your own websites, internal company applications, or bug bounty programs where the company has invited security researchers to test. In these cases, installing the CA certificate is the right approach.

Do not use Burp Suite to intercept traffic from websites you don't own or don't have permission to test. This is illegal in most jurisdictions, even if you're just looking at your own traffic. The Computer Fraud and Abuse Act in the US and similar laws elsewhere make unauthorized access to computer systems a crime. "I was just testing" is not a legal defense.

Also don't install Burp Suite's certificate on shared devices or devices you don't fully control. If someone else uses the computer, they could unknowingly have their traffic intercepted by malware using the certificate you installed.

Frequently Asked Questions

Will websites know I'm using Burp Suite?

The website won't know Burp Suite is intercepting traffic. From the website's perspective, it's receiving a normal encrypted connection from a normal browser. However, if you're testing a website you don't own and the administrators are monitoring traffic patterns, they might notice unusual activity or repeated requests that look like testing.

Can I use Burp Suite without installing the CA certificate?

You can use Burp Suite for some tasks without it — like examining unencrypted traffic or testing APIs with tools that don't validate certificates. But for testing a modern website through a browser, you need the certificate installed. Without it, your browser will reject the connection.

Is it safe to install Burp Suite's certificate on my main computer?

It's safer to use a separate testing machine or virtual machine. If you must install it on your main computer, remove it as soon as you're done testing. The longer it stays installed, the longer a window exists for malware to use it.

What happens if I lose or forget the certificate password?

Burp Suite generates a new certificate each time you run it, so you can't really "lose" it. If you need a fresh start, uninstall the old certificate and Burp Suite will create a new one. The password is typically set during Burp Suite installation and is used to protect the certificate file itself, not to decrypt traffic.

Can I share Burp Suite's CA certificate with someone else?

Technically yes, but you shouldn't. If you share the certificate, anyone who installs it can intercept encrypted traffic on their device. For team testing, each person should generate their own certificate or use a shared testing environment where the certificate is already installed.