Skip to content

Pick the app you're debugging

You usually arrive with an app, not a list of hosts. HTTPGlass is built around that: pick the app, and it decrypts everything that app sends — its API, its CDN, its analytics — and shows only that app’s traffic.

For every connection to its proxy, HTTPGlass asks macOS which process opened it, then works out the app a person would name:

  • Helper processes roll up to their app. Chrome, Slack, and Electron apps do their networking in helper processes inside the app bundle; their requests show as the app.
  • System services report the app they work for. Safari’s traffic comes from a WebKit networking service, and shows as Safari.
  • Command-line tools are themselves. A request from curl or node shows as curl or node, not as the terminal that launched it.

The App column in the traffic table and the inspector’s Details tab show the result. A row with no app is usually a background process running as another user.

Any of these does the same thing:

  • The What are you debugging? grid a new window opens with, or the one All Traffic shows when everything arriving is encrypted
  • The app menu at the left of the toolbar — apps Sending Requests, then others that are Running, so you can pick an app before it sends anything
  • Right-click a row → Decrypt Everything from App
  • Select an Encrypted row, then Decrypt App in the inspector

HTTPGlass then:

  1. Adds the app to its list of apps to decrypt.
  2. Shows that app in the sidebar and filters the table to it.
  3. Starts capturing, if it wasn’t already.
  4. Closes the app’s open encrypted connections, so it reconnects and its traffic shows up decrypted straight away — no need to relaunch it.

A bar above the table names the app, counts its requests and hosts, and says whether it’s being decrypted. Stop Decrypting takes it off the list; its new connections pass through unread.

Selecting an app in the sidebar, or Show Only App from a row’s menu, filters the table to that app without changing what’s decrypted. If the app isn’t being decrypted yet, the bar above the table offers Decrypt Everything from App.

Sometimes a host is the right unit — a shared API that several apps call. Decrypt a single host from a row’s menu (Decrypt Only host), from a domain’s menu in the sidebar, or with Only decrypt this host in the inspector. Hosts are added to the SSL Proxying list under Rules; see Rule syntax.

  • Free decrypts one app at a time. Picking another app replaces the current one — no upgrade prompt, it’s the everyday case. Free also decrypts up to five hosts from the SSL Proxying list.
  • Pro decrypts any number of apps and hosts, and adds Decrypt all HTTPS under Rules, which is on by default.

See Free vs Pro.