Skip to content

Install the root certificate

HTTPS decryption needs a certificate your Mac trusts. HTTPGlass generates its own root certificate on your Mac — the private key never leaves it — and asks macOS to trust it. This is the same step every HTTPS debugging proxy needs; it’s how TLS is designed to work.

  1. Select Certificate in the sidebar (under Setup), or use step 1 of the Setup Assistant.
  2. Click Install & Trust.
  3. macOS asks you to authorize a change to your certificate trust settings. Confirm it.
  4. The status should read Trusted.

That’s the whole process: no Keychain Access, no files to double-click. If you cancel the authorization prompt, nothing changes and you can click Install & Trust again.

  • The certificate, named HTTPGlass CA, is added to your login keychain and trusted as a root for your user account only. Nothing goes into the System keychain, and other user accounts on the Mac are unaffected.
  • The private key is not in the keychain. It’s a file in ~/Library/Application Support/HTTPGlass that only your user account can read. Keeping it out of the keychain means an app update never has to ask for your password to read it.
  • The root is generated per install. A different Mac, or a fresh user account, gets its own.
Status Meaning
Trusted HTTPS can be read
Installed but not trusted The certificate exists but macOS doesn’t trust it. HTTPS passes through unread; click Install & Trust again
Not created yet HTTPGlass hasn’t generated a root yet; Install & Trust creates one

While you’re capturing with an untrusted root, the traffic view shows a banner saying so, and HTTPS rows are marked Untrusted rather than being mistaken for certificate pinning.

Safari, Chrome, and most command-line tools use the macOS trust settings and need nothing more. Firefox, Java, and some runtimes (Node.js, Python) keep their own list of trusted certificates and won’t accept HTTPGlass’s root until you add it there too — see Command-line tools and other trust stores.

  • It only lets HTTPGlass, on your Mac, read traffic that passes through its own local proxy. It isn’t sent anywhere.
  • HTTPGlass only decrypts what you ask it to: the app you pick, hosts you add, or everything if you turn that on (Pro). Everything else passes through encrypted.
  • Some traffic still won’t decrypt — see What HTTPGlass can’t see.

On the Certificate screen, click Remove Certificate. HTTPGlass removes the trust setting and then the certificate from your keychain. macOS asks you to authorize it.

If you’re uninstalling HTTPGlass, remove the certificate first, then delete the app and the ~/Library/Application Support/HTTPGlass folder, which holds the private key, captured traffic, and your rules.