Skip to content

Rule syntax

Every list that matches traffic — Block, Allow, No-Cache, SSL Proxying, Breakpoints, Map Local, Map Remote, Rewrite, Scripts, and Network Condition hosts — uses the same pattern syntax.

Pattern Matches
example.com The host, and its subdomains
*.example.com Subdomains only — * is a wildcard
example.com/api/* Any request under that path prefix
example.com/api/ Same as above — a trailing slash is shorthand for a prefix
example.com/api/users That exact path only
/analytics/* That path on any host

Paste a full URL and HTTPGlass strips the http:// or https:// scheme for you. Ports are never part of a pattern, and a query string is ignored unless the pattern itself contains one. Matching is case-insensitive.

Map Local, Map Remote, Rewrite, and Scripts rules can additionally be limited to one HTTP method.

Select Rules in the sidebar for the Block, Allow, SSL Proxying, and No-Cache lists. Changes apply to the running capture immediately.

  • Block stops a matching request before it reaches the server. A host-only pattern refuses the connection before it opens; a path pattern lets the connection through and cuts that one request. Blocked requests still show in the traffic table as Blocked, so you can see what was stopped. You can also block a host from a row’s or a domain’s right-click menu.
  • Allow, when it isn’t empty, restricts capture to the hosts on it. Everything else still connects normally, relayed without decryption or logging — which also means no certificate refusals from out-of-scope hosts.
  • A path-only Block pattern (/analytics/*) applies even to hosts that aren’t on the Allow list, since it’s checked per request rather than per host.

The hosts on this list are decrypted, whichever app connects to them. It sits alongside the apps you pick to debug — see Pick the app you’re debugging. Hosts you decrypt from a row, a domain, or the inspector are added here.

On Pro, Decrypt all HTTPS decrypts every host and is on by default; turn it off to decrypt only the hosts on the list and the apps you picked. Everything else still connects — it just shows as Encrypted, with no request detail. Useful for keeping a noisy SDK out of the way, or for an app that pins one host but not the one you care about.

Matching requests get Cache-Control: no-store forced onto the response, with If-None-Match, If-Modified-Since, ETag, Expires, and Last-Modified stripped — useful when you’re testing against an API that insists on serving a cached 304. Disable caching for everything applies it to every request.

Free includes one pattern each in the Block and Allow lists, one in each breakpoint list, and up to five hosts in the SSL Proxying list. Decrypt all HTTPS and No-Cache are Pro. If you have more saved entries than Free allows — after a Pro licence ends, say — they stay saved, but only the first ones are used until you upgrade or remove the rest. See Free vs Pro.