Rule syntax
Every list that matches traffic — Block, Allow, No-Cache, SSL Proxying, Breakpoints, Map Local, Map Remote, Rewrite, Scripts, and Network Condition hosts — uses the same pattern syntax.
| Pattern | Matches |
|---|---|
example.com |
The host, and its subdomains |
*.example.com |
Subdomains only — * is a wildcard |
example.com/api/* |
Any request under that path prefix |
example.com/api/ |
Same as above — a trailing slash is shorthand for a prefix |
example.com/api/users |
That exact path only |
/analytics/* |
That path on any host |
Paste a full URL and HTTPGlass strips the http:// or https:// scheme for you. Ports are
never part of a pattern, and a query string is ignored unless the pattern itself contains one.
Matching is case-insensitive.
Map Local, Map Remote, Rewrite, and Scripts rules can additionally be limited to one HTTP method.
The Rules screen
Section titled “The Rules screen”Select Rules in the sidebar for the Block, Allow, SSL Proxying, and No-Cache lists. Changes apply to the running capture immediately.
Block and Allow
Section titled “Block and Allow”- Block stops a matching request before it reaches the server. A host-only pattern refuses the connection before it opens; a path pattern lets the connection through and cuts that one request. Blocked requests still show in the traffic table as Blocked, so you can see what was stopped. You can also block a host from a row’s or a domain’s right-click menu.
- Allow, when it isn’t empty, restricts capture to the hosts on it. Everything else still connects normally, relayed without decryption or logging — which also means no certificate refusals from out-of-scope hosts.
- A path-only Block pattern (
/analytics/*) applies even to hosts that aren’t on the Allow list, since it’s checked per request rather than per host.
SSL Proxying
Section titled “SSL Proxying”The hosts on this list are decrypted, whichever app connects to them. It sits alongside the apps you pick to debug — see Pick the app you’re debugging. Hosts you decrypt from a row, a domain, or the inspector are added here.
On Pro, Decrypt all HTTPS decrypts every host and is on by default; turn it off to decrypt only the hosts on the list and the apps you picked. Everything else still connects — it just shows as Encrypted, with no request detail. Useful for keeping a noisy SDK out of the way, or for an app that pins one host but not the one you care about.
No-Cache (Pro)
Section titled “No-Cache (Pro)”Matching requests get Cache-Control: no-store forced onto the response, with
If-None-Match, If-Modified-Since, ETag, Expires, and Last-Modified stripped — useful
when you’re testing against an API that insists on serving a cached 304. Disable caching for
everything applies it to every request.
Free tier
Section titled “Free tier”Free includes one pattern each in the Block and Allow lists, one in each breakpoint list, and up to five hosts in the SSL Proxying list. Decrypt all HTTPS and No-Cache are Pro. If you have more saved entries than Free allows — after a Pro licence ends, say — they stay saved, but only the first ones are used until you upgrade or remove the rest. See Free vs Pro.
