Install the root certificate
HTTPS decryption needs a certificate your Mac trusts. HTTPGlass generates its own root certificate on your Mac — the private key never leaves it — and asks macOS to trust it. This is the same step every HTTPS debugging proxy needs; it’s how TLS is designed to work.
Install and trust
Section titled “Install and trust”- Select Certificate in the sidebar (under Setup), or use step 1 of the Setup Assistant.
- Click Install & Trust.
- macOS asks you to authorize a change to your certificate trust settings. Confirm it.
- The status should read Trusted.
That’s the whole process: no Keychain Access, no files to double-click. If you cancel the authorization prompt, nothing changes and you can click Install & Trust again.
What it changes
Section titled “What it changes”- The certificate, named HTTPGlass CA, is added to your login keychain and trusted as a root for your user account only. Nothing goes into the System keychain, and other user accounts on the Mac are unaffected.
- The private key is not in the keychain. It’s a file in
~/Library/Application Support/HTTPGlassthat only your user account can read. Keeping it out of the keychain means an app update never has to ask for your password to read it. - The root is generated per install. A different Mac, or a fresh user account, gets its own.
What the status means
Section titled “What the status means”| Status | Meaning |
|---|---|
| Trusted | HTTPS can be read |
| Installed but not trusted | The certificate exists but macOS doesn’t trust it. HTTPS passes through unread; click Install & Trust again |
| Not created yet | HTTPGlass hasn’t generated a root yet; Install & Trust creates one |
While you’re capturing with an untrusted root, the traffic view shows a banner saying so, and HTTPS rows are marked Untrusted rather than being mistaken for certificate pinning.
Which apps this covers
Section titled “Which apps this covers”Safari, Chrome, and most command-line tools use the macOS trust settings and need nothing more. Firefox, Java, and some runtimes (Node.js, Python) keep their own list of trusted certificates and won’t accept HTTPGlass’s root until you add it there too — see Command-line tools and other trust stores.
What this certificate can and can’t do
Section titled “What this certificate can and can’t do”- It only lets HTTPGlass, on your Mac, read traffic that passes through its own local proxy. It isn’t sent anywhere.
- HTTPGlass only decrypts what you ask it to: the app you pick, hosts you add, or everything if you turn that on (Pro). Everything else passes through encrypted.
- Some traffic still won’t decrypt — see What HTTPGlass can’t see.
Removing it
Section titled “Removing it”On the Certificate screen, click Remove Certificate. HTTPGlass removes the trust setting and then the certificate from your keychain. macOS asks you to authorize it.
If you’re uninstalling HTTPGlass, remove the certificate first, then delete the app and the
~/Library/Application Support/HTTPGlass folder, which holds the private key, captured
traffic, and your rules.
