What is HTTPGlass
HTTPGlass is an HTTP and HTTPS debugging proxy for macOS. It captures the requests your apps and command-line tools send and the responses they get back, decrypts HTTPS so you can read it, and gives you tools to filter, search, repeat, and — on Pro — change that traffic on its way through.
How it works
Section titled “How it works”- A local proxy. HTTPGlass runs a proxy inside the app, listening only on
127.0.0.1(port9191unless that port is taken). - Your Mac’s proxy settings. While you capture, HTTPGlass points the HTTP and HTTPS proxy of each network service at that port, and puts the previous settings back when you stop or quit. See How capture works.
- A root certificate made on your Mac. HTTPGlass generates its own root certificate the first time it needs one and, once you’ve trusted it, signs a certificate for each site it reads. The private key never leaves your Mac. See Root certificate.
- The app behind each request. HTTPGlass works out which process opened each connection
and rolls helper processes up to their app, so a request from Chrome’s network helper shows
as Chrome and a request from
curlshows ascurl.
Nothing is sent to a separate machine. Captured traffic, the certificate’s private key, and
your rules stay in ~/Library/Application Support/HTTPGlass.
App-first
Section titled “App-first”Most proxies ask you to decide which hosts to decrypt. HTTPGlass starts from the question you arrived with: which app are you debugging? Pick it, and HTTPGlass decrypts everything that app sends, on every host, and shows only its traffic. See Pick the app you’re debugging.
What you can do with it
Section titled “What you can do with it”- Watch every request and response as it happens, by app, by domain, or all together
- Read JSON, XML, HTML, form, cookie, image, and binary bodies with a viewer that fits each
- Search across URLs, headers, and bodies
- Copy a request as cURL, repeat it, or generate Swift, Python, JavaScript, or Kotlin from it
- Export selected requests as a HAR file
- Pause a request or response on a breakpoint and edit it before it continues
- Block or allow matching hosts or paths, or force them uncached (No-Cache is Pro)
- Serve a canned response instead of hitting the real backend (Pro)
- Send matching requests to a staging server or a different path (Pro)
- Rewrite headers, bodies, status codes, and query parameters automatically (Pro)
- Run your own JavaScript against requests and responses (Pro)
- Throttle connections to 3G, GPRS, or custom bandwidth and latency (Pro)
- Install HTTPGlass
- What HTTPGlass can’t see — read this before you assume something is broken
