Changelog
Release notes
What changed in each version, newest first.
HTTPGlass for iPhone and iPad
First release on the App Store
- Capture and decrypt HTTPS on the device itself through a local VPN tunnel, with no Mac and no cable. HTTP/1.1 and HTTP/2, with gzip, deflate, Brotli and chunked bodies decoded.
- Traffic list with filters and full-text search, body viewers (JSON, XML, HTML, forms, cookies, images, hex), GraphQL and WebSocket inspectors, sessions, HAR export, and code generation for cURL, Swift, Python, JavaScript and Kotlin.
- Breakpoints, Map Local, Map Remote, Rewrite, JavaScript scripting, Network Condition throttling, and Compose and replay.
- Block, Allow and SSL Proxying lists, No-Cache rules, App Lock with Face ID, Touch ID or passcode, and iPad split view.
- Optional, opt-in analytics and crash reports that never include captured traffic.
HTTPGlass for Mac
Pick the app you are debugging
- The window opens by asking which app you are debugging. One click starts capturing, decrypts every host that app talks to, and shows only its traffic. The chosen app stays in the toolbar.
- HTTP/2 stays HTTP/2 when the app and the server both speak it. Hosts with a Map Local, Rewrite, script, or breakpoint rule use HTTP/1.1 so the rule can apply.
- Request and response side by side, with the inspector beside the table or under it (⌥⌘I).
- Filter by HTTP method. macOS background services and undecrypted connections are hidden by default, with a count and a switch to show them.
- Clearer explanations for rows that could not be read: not decrypted, root not trusted, pinned, or an app with its own certificate store.
- Fixed a stall where one slow connection could hold up others. The default proxy port is now 9191.
Sidebar and Clear fixes
- Clicking a rule editor, Sessions, or Certificate in the sidebar now opens it. Before, the window stayed on the traffic table.
- Clear removes captured traffic even when capture is stopped.
See which app made each request
- Every row shows the icon and name of the app that made it. Helper processes count as their app, Safari traffic is labelled Safari, and command-line tools keep their own name.
- An Apps section in the sidebar, Show Only This App in the row menu, and the app and bundle identifier in the inspector.
- Fixed HTTPS not being decrypted while the screen was locked.
Free decrypts five hosts, and unreadable rows explain themselves
- Free now decrypts up to five hosts instead of one.
- Selecting an encrypted row says why it could not be read, with a button to decrypt it.
- Decrypting a host past the Free limit now says so, instead of appearing to do nothing.
- Installing the certificate removes older HTTPGlass roots, and the window warns you when capture is running with an untrusted root.
Fix for the 1.0.0 proxy loop
- HTTPGlass’s own connections to servers no longer follow the system proxy back into HTTPGlass. In 1.0.0 that loop filled the table with CONNECT rows and stopped other apps from reaching the internet.
First Mac release (withdrawn)
- Local HTTP/HTTPS proxy with the system proxy set while capturing and restored on stop, on quit, or at the next launch after a crash.
- Root certificate created on your Mac and trusted for your user account, a setup assistant, the traffic table and inspector, and the rule editors: Block, Allow, No-Cache, Breakpoints, Map Local, Map Remote, Rewrite, Scripts, and Network Condition.
- Pro licences through Stripe, and update checks.
- Withdrawn the same day because of the proxy loop fixed in 1.0.1. Use a later version.