Skip to content

Your first capture on iPhone

With capture running and the certificate trusted, open any app that talks to a server: your own app, or a news or shopping app.

HTTPGlass has two tabs. Traffic is the live list, with the play button for starting and stopping capture. Settings holds the certificate, VPN, App Lock, rules and the Pro tools.

You can switch the list between Status and Type filters, and group it by domain once a screen full of ad and analytics hosts shows up next to your API calls.

Each row shows the method, path, status code and a content-type tag. Tap a row to open the detail: Overview, Request, Response and Code (cURL, Swift, Python, JavaScript, Kotlin), plus Cookies, GraphQL or WS when the transaction has something to show there. Bodies get a viewer that fits their type; see Body viewers.

The previous and next buttons at the top of the detail step through the list as you currently have it filtered and sorted, and keep the tab you’re on. On an iPad, or a large iPhone held sideways, the list and the detail sit side by side.

  • Check that Settings › Certificate reads Trusted, not just installed.
  • Some apps use certificate pinning and will never show decrypted content. See What HTTPGlass can’t see.
  • Force-quit and reopen the app you’re testing, so it opens fresh connections after the VPN came up.

Use the filter chips (All, Errors, GET, POST, 4xx, 5xx) or the search button in the bottom-right corner. Search covers URLs and headers, and the bodies of text responses.