Skip to content

What HTTPGlass can't see

Being honest about this up front saves a lot of confused bug reports.

Some apps check that the certificate presented to them matches a specific one they ship with, instead of trusting whatever the Mac trusts. That’s certificate pinning, and it’s designed specifically to defeat tools like HTTPGlass, Charles, and Proxyman.

When an app refuses HTTPGlass’s certificate while the root is trusted, the row reads Pinned and the domain gets an orange warning in the sidebar. HTTPGlass then passes that host through untouched, so the app keeps working — HTTPGlass just can’t read it. No proxy can read pinned traffic without a build of the app with pinning turned off.

Before concluding an app pins, rule out the two look-alikes:

  • An untrusted root. If your Mac doesn’t trust the HTTPGlass root, every app refuses it. Those rows read Untrusted, not Pinned. See Certificate not trusted.
  • A client with its own trust store. Firefox, Java, Node.js, Python, and some builds of curl don’t read the macOS trust settings. They refuse a trusted root exactly like a pinning app would, and one setting fixes it. See Command-line tools and other trust stores.

Some of macOS’s own background services refuse any certificate but Apple’s, the same way a pinning app does. If you see Apple hosts marked Pinned, that’s expected, not a sign anything is broken. All Traffic hides macOS background services by default; the noise filter in the filter bar brings them back.

HTTPGlass sees what’s sent through its proxy. A program that ignores the system proxy settings and doesn’t have a proxy configured some other way connects directly, and never shows up. See Command-line tools and other trust stores for the common ones.

HTTPGlass is an HTTP and HTTPS proxy. Traffic that doesn’t go through an HTTP proxy — UDP, game networking protocols, custom binary protocols over their own sockets — isn’t seen. A connection made through the proxy that turns out not to carry HTTP is passed through as-is, and the inspector labels it Not HTTP.