Rules

Block, Allow, and No-Cache rules

Pattern-match a host, a folder, or a single request to block it, limit capture to it, or force fresh responses.

HTTPGlass for Mac: the traffic table with requests from several apps, and a JSON response open in the inspector

Three rule lists, one pattern syntax shared across all of them:

  • Block refuses a matching request. A host-only pattern refuses the connection before it opens; a folder or request pattern lets the connection through and cuts only that request. Blocked requests still show up in the table, marked as blocked, so you can see what was stopped.
  • Allow, when it isn’t empty, limits capture to the hosts on the list. Everything else still connects normally; it just isn’t captured.
  • No-Cache forces fresh responses on matching hosts, for when an endpoint keeps answering with a cached 304.

Patterns work at the host level (api.example.com), a folder (api.example.com/v2/*), or a single exact request. See the rule syntax reference for the full table.

To block a host without opening the rules, right-click a row or a domain in the sidebar and choose Block.

Free and Pro

Free includes one Block pattern and one Allow pattern. No-Cache and unlimited patterns are Pro. If a subscription lapses, your extra patterns stay saved; only the first of each is used until you upgrade or remove the rest.

Pattern examples

All three lists read patterns the same way:

  • example.com matches the host and its subdomains
  • *.example.com matches subdomains only
  • example.com/api/* matches any request under that path prefix. A trailing slash, as in example.com/api/, is shorthand for the same thing
  • example.com/api/users matches that exact path only
  • /analytics/* matches that path on any host

Paste a full URL and HTTPGlass strips the http:// or https:// for you. Ports are never part of a pattern, a query string is ignored unless the pattern contains one, and matching is case-insensitive.

A typical debugging session

An SDK in your app keeps calling an analytics endpoint and the noise hides the requests you care about. Add /analytics/* to Block. It applies on any host, and each blocked request still shows in the table marked as blocked, so you can confirm it was stopped.

To look at one backend only, add its host to Allow. Everything else still connects normally, without being decrypted or logged, so hosts outside the list can’t cause certificate refusals. A path-only Block pattern still applies to hosts that aren’t on the Allow list, because it is checked per request.

If an endpoint keeps answering with a cached 304, add its host to No-Cache (Pro). HTTPGlass forces Cache-Control: no-store onto the response and strips If-None-Match, If-Modified-Since, ETag, Expires, and Last-Modified. Disable caching for everything applies it to every request. Changes to these lists apply to the running capture immediately.

Read the docs →