Skip to content

Install the root certificate on iOS

HTTPS decryption needs a certificate your device trusts. HTTPGlass generates one on the device, and its private key never leaves it. You then trust it in two iOS steps. Every HTTPS debugging tool works this way, because that is how TLS is designed to work.

In HTTPGlass, go to Settings › Certificate and tap Open install page in Safari. The app generates the certificate the first time you open this screen.

While capture is running, the same page is also served at http://http.debugger/. That isn’t a real domain. HTTPGlass’s local tunnel answers it, and it only resolves while the VPN is connected.

Tap Allow when Safari asks to download a configuration profile, then go to iOS Settings › Profile Downloaded › Install, enter your passcode, and tap Install again on the warning screen.

A downloaded profile isn’t yet trusted for websites. iOS keeps that as a separate switch on purpose.

Go to Settings › General › About › Certificate Trust Settings and turn on the toggle next to HTTPGlass CA.

Back in HTTPGlass, open Settings › Certificate and tap Re-check trust. The status should read Trusted. Open an app that uses HTTPS and decrypted requests start appearing in the traffic list.

  • It lets HTTPGlass, on your device, read traffic that passes through its own local tunnel. It isn’t sent anywhere and doesn’t give any other app or website access to anything.
  • Some traffic still won’t decrypt. See What HTTPGlass can’t see for certificate-pinned apps and Apple’s own system services.
  • You can remove the trust at any time from Certificate Trust Settings, or delete the profile from Settings › General › VPN & Device Management.
  • Regenerate CA in the same screen creates a new certificate. You then redo steps 2 and 3.