Inspecting traffic
The traffic table
Section titled “The traffic table”Every captured request is a row. Click a column header to sort; right-click the header to show,
hide, or reorder columns. Available columns: #, App, Status, Method, Host,
Path, Protocol (h2, h1.1, ws), Type, Size, Time, and Started. Times
over one second are orange, over three seconds red.
Follow (the arrow at the right of the filter bar) keeps the newest row in view as traffic arrives. It switches off when you select a row, so the table doesn’t jump while you’re reading.
What the sidebar shows
Section titled “What the sidebar shows”- All Traffic — everything, minus the rows the noise filter hides (below).
- Apps — one entry per app that has made requests, with its count. See Pick the app you’re debugging.
- Domains — one entry per host. The icon says whether its HTTPS was read: a closed padlock for decrypted, an open padlock for passed through unread, an orange warning for a host that refused HTTPGlass’s certificate, a globe for plain HTTP. Right-click a domain to decrypt it, copy its host name, or block it.
Selecting an app or a domain shows all of its rows; the noise filter only applies to All Traffic.
Filters and search
Section titled “Filters and search”The filter bar above the table has:
- Search (⌘F) — matches URLs, request and response headers, and text bodies (JSON, XML, HTML, forms, JavaScript, plain text) on both sides — the first 256 KB of each.
- Status — any, errors (failed or 400 and above), 4xx, or 5xx.
- Method — GET, POST, PUT, PATCH, DELETE, HEAD, or OPTIONS.
- Type — JSON, GraphQL, form, JS, CSS, image, document, and more.
- Noise filter — on All Traffic, hides HTTPS connections that weren’t decrypted and macOS background services (iCloud, Spotlight, software update and other system daemons). Both are on by default. The number beside the button is how many rows are hidden; click it to switch either off.
The inspector
Section titled “The inspector”Select one row. The top of the inspector shows the method and URL, the status, the protocol, the total time, the response size, and the app. If a rule touched the request — Map Local, Map Remote, Rewrite, a script, or a breakpoint — a line underneath says which.
Below that, the request and the response are on screen together, each with its own tabs:
| Request tabs | Response tabs |
|---|---|
| Headers | Body |
| Query — the URL’s query parameters | Headers |
| Body | Cookies — from Set-Cookie headers |
Cookies — from the Cookie header |
WebSocket — every frame, for an upgraded connection |
| GraphQL — operation, query, variables, and any errors | Details — app, bundle ID or path, addresses, timing, sizes |
| Code — the request as cURL, Swift, Python, JavaScript, or Kotlin |
Tabs only appear when there’s something in them. The tab you last used is remembered, so
clicking down the table keeps you on the same view of each row. Header, query, and cookie
tables can be sorted, and right-clicking copies a value, a Name: value line, or all of them.
Bodies get a viewer that fits their content type — see Body viewers.
For a connection HTTPGlass didn’t read, the inspector explains why instead: not decrypted, refused because the root isn’t trusted, refused because the app pins its certificate, or not HTTP at all — with the button that fixes it, where there is one.
Acting on a request
Section titled “Acting on a request”From the ⋯ menu in the inspector, or by right-clicking a row:
- Copy URL
- Copy as cURL — a
curlcommand with the method, headers, and body - Repeat Request — sends the same request again. It goes through HTTPGlass like anything else, so it appears as a new row. Double-clicking a row never repeats it.
- Show Only App / Show Only host — filter to that app or domain
- Decrypt Everything from App / Decrypt Only host — for an encrypted row
- Block host — adds the host to the Block List
- Export as HAR… — saves the selected rows as a HAR file, which browsers’ developer tools and other HTTP tools can open. Select several rows to export them together.
Sessions and clearing
Section titled “Sessions and clearing”Each time you start capturing begins a new session. Sessions in the sidebar lists them, newest first, with their request counts; you can rename or delete one.
Clear in the toolbar, or Capture → Clear Capture (⌘K), deletes all captured traffic, whether or not you’re capturing.
