Demo Features Workflows API Pricing API Docs Download
HTTP/HTTPS debugging proxy Desktop app · Web dashboard · REST API

See the request.
Find the problem.

Inspect the HTTP/HTTPS traffic behind failed API calls and slow apps. Replay requests, mock responses and test poor connections in one workspace. Then automate repeatable checks with the built-in REST API. Starts free. No account required.

No account required · 1,000 requests/day free · Windows, macOS & Linux
ProxyCat / Traffic Inspector DESKTOP PREVIEW
ProxyCat desktop with compact numbered request rows and aligned method, status, URL, time, duration and size columns
Compact rows. One workspace.Desktop preview · sample traffic
60+
REST endpoints, one for every action in the app
8
Rewrite rule types, from map-local to status override
14
Network throttle presets, 3G to LTE
1,000/day
Free-tier captures, no account required

Follow a request all the way through.

Scan compact, numbered rows without losing your place. Select a request to see its status, timing and response content; open the full viewer for headers and the complete exchange.

Explore the interactive demo →
Request Inspector / Response 201 CREATED
ProxyCat desktop inspecting a numbered POST request with a 201 status, timing and JSON response
Request summary and response bodyDesktop preview · sample traffic

Change the input. See what happens.

Open a captured request as an editable draft. Change its URL, headers or body, then send it and inspect the response beside your input. Repeat the original when you need the same request bytes again.

Each send goes directly to the destination with TLS validation and creates a new numbered capture within your plan’s allowance. Proxy rewrite and throttle rules do not apply to these direct sends.

Try the guided examples →
Compose / Request & responseDESKTOP
ProxyCat desktop composer showing an editable POST request, JSON headers and body, and a formatted 201 response alongside it
Edit, send and inspect side by sideDesktop preview · sample traffic

Find what changed between failure and success.

Keep a request as your baseline, select the next attempt, and compare them side by side. See the method, URL, status, timing, headers and body differences without juggling two inspector windows.

Focus on changes only, or format JSON to remove formatting noise. Binary payloads show byte counts and hashes; incomplete captures are labelled, so a missing body never looks like a match.

Explore the sample traffic →
Compare / Before & afterDESKTOP
Native ProxyCat comparison of a failed order response and a successful retry, with aligned JSON differences
From a quantity error to a created orderDesktop preview · sample traffic

Test the slow connection before your users do.

Choose a network profile or set your own latency, response bandwidth and dropped-request rate. Disable HTTP caching and block cookies when you need a fresh, signed-out investigation.

Apply changes explicitly and reset them in one click. Forwarded requests pick up the new conditions; your old captures keep their original timings. Direct Compose sends bypass these controls.

Try the slow-network walkthrough →
Network / Choose the conditionsDESKTOP
ProxyCat desktop controls with a 3G profile, no caching and cookie blocking applied
Presets, custom values and a clear resetDesktop preview · sample traffic

Make the next response yours.

Turn a captured response into an editable mock. Its method, exact URL, status, safe response headers and body are already filled in. Change the result, save the draft, and enable it when you’re ready.

Existing rules stay editable. Text, binary and encoded response bytes are preserved; cookies and transport headers are excluded. Exact HTTPS mocks can answer even when the origin is offline.

Try a profile-response mock →
Mock response / Review before enablingDESKTOP
ProxyCat mock editor with an exact POST URL, editable JSON body and the rule disabled until explicitly enabled
A disabled draft, ready for your experimentDesktop preview · sample traffic

Pick up where you left off.

Name an investigation, keep it on your computer, and reopen it from the desktop library. Import or export a .pcsession file when you want to share the full capture. Opening a session asks before replacing your current traffic.

For a bug handoff, share selected requests as a browser report with notes and privacy controls. Your teammate can inspect the file offline without installing ProxyCat.

See what’s included in Pro →
Saved captures / Local libraryPRO
ProxyCat saved-capture dialog with a named investigation and open, delete, import and export controls
Keep, reopen and share investigationsDesktop preview · sample capture

Send the evidence. Keep the context.

Select the requests that explain a bug, add reproduction notes, and export one HTML file. The recipient can search, sort, and inspect headers and any included text bodies in a browser.

Query values and URL credentials are removed; most header values are hidden and bodies stay out by default. Review paths and notes before sharing. No cloud upload or recipient account required.

Open a sample investigation →
Share investigation / Choose what to sendPRO
ProxyCat sharing dialog with selected requests, reproduction notes, redacted URLs and optional body inclusion
From QA to a developer, with the evidence attachedWorking report · sample traffic
Point anything that can use an HTTP proxy at it
Browsers iOS / Android apps Node.js Python Go .NET curl Postman Playwright CI runners
HTTP/1.0 and 1.1 HTTPS decrypted with your own root CA Desktop app and standalone headless server
Try ProxyCat right here. No download, no account.
A simulated capture session built from sample traffic — nothing leaves your browser. Follow a debugging walkthrough or explore freely. Rules and throttles preview their effect on this sample session; they don’t change an existing capture in the desktop app. The console shows the equivalent local REST calls.
Ready · choose a walkthrough

Play a short walkthrough, or advance one step at a time.

Illustrative sample traffic · finite playback · pause or explore at any time · no network requests are sent

Explore the individual tools
Guided tour · 5 steps
    ProxyCat · Interactive Demo
    Proxy listening · 8888
    Inspector
    Select a request
     
    Rewrite rules /api/Tools/rewrite
    Throttle /api/Tools/throttle
    Filters /api/ProxyApi/filters
    API console every click is one curl
    0 calls

    TLS and mobile setup

    Keep upstream validation on by default, install the local CA only where you intend to inspect, and follow platform-specific mobile guidance.

    Validate upstream TLS
    Import existing certs (.p12 / .pfx)Cert Viewer
    Mobile onboardingiOS / Android

    Guided first launch

    The tour points at the live controls so new users can capture traffic, trust certificates, and open settings without hunting.

    Search and filter
    Step 2 of 5
    Use filters to narrow noisy sessions.
    From download to first captured request in 60 seconds.
    1

    Download & Run

    One binary. Double-click to launch. No installer, no Java runtime, no Docker required. The proxy starts automatically on port 8888.

    2

    Point Your Traffic

    Set localhost:8888 as your HTTP proxy. Works with browsers, mobile apps, React, Node, Python — anything that speaks HTTP.

    3

    See Everything. Automate Anything.

    Every request appears instantly in the desktop app. Then automate — create rewrite rules, throttle profiles, and filters via the REST API. No clicking required.

    Inspect, reproduce, and automate your HTTP workflows.
    Inspect the exchange in the workbench, keep the evidence, and turn the same setup into a repeatable test. Use the desktop for exploration and the REST API for automation.

    SSL/HTTPS Interception

    Inspect HTTP/HTTPS with your own local root CA. Guided desktop and mobile setup helps you configure clients that support proxying and trust the certificate.

    Rewrite Rules Engine

    Map Remote, Map Local, header inject/modify/remove, body find & replace, URL rewriting, status code overrides. All via API or GUI.

    Network Throttling

    14 built-in presets from 56K modem to 5G fiber. Custom latency, bandwidth caps, and packet loss simulation. Test edge cases instantly.

    Full-Text Search

    Use the full-text REST search to match URLs, headers and request/response bodies. The desktop’s fast view filters narrow traffic by URL, method and status.

    Replay & Compose

    Open a captured request as a draft, edit its URL, headers and body, or repeat its original bytes. Inspect the response beside your draft; new results join the numbered capture.

    Session Management

    A desktop library for named captures on Pro. Reopen investigations, exchange .pcsession files, or share selected requests and notes as an offline browser report. Recipients need no installation to review the report.

    HAR Export

    Export to standard HTTP Archive format. Import into Chrome DevTools, Lighthouse, or any HAR-compatible tool for further analysis.

    Slack Alerts & Notifications

    Get notified via Slack in real-time when specific patterns appear. Monitor for 5xx errors, slow responses, or custom conditions. Email notifications coming soon.

    API-First Architecture

    Core proxy workflows exposed via a clean REST API with OpenAPI docs. Script your proxy config in CI/CD, tests, or any language you use.

    Bring traffic into your AI workflow

    Use MCP to find failed calls, compare response times and spot large responses from your own AI client. Share capture metadata for this app session; keep headers and payloads in the inspector.

    See MCP examples →

    Four considered themes

    Graphite Dark, warm-paper Light, moss-green Forest and deep-blue Aqua. Switch in Settings; your workbench, dialogs and inspectors follow the same palette.

    Captures stay on your computer

    The account service handles sign-in and licensing. Your desktop captures and local CA stay on your machine. You choose what to export, share or expose to an MCP client.

    One proxy. Explore by hand or automate through the API.
    Start with the visual inspector, then use the REST API to repeat your setup in tests and scripts. Availability and limits depend on your plan.
    WorkflowIn the appThrough the API
    Inspect trafficBrowse requests, headers, bodies, and timingList captured requests and search traffic
    Change responsesCreate rewrite and mapping rulesConfigure rules from your scripts
    Test slow networksChoose a throttling presetApply repeatable network conditions
    Reproduce a requestReplay a capture or compose a requestSend requests from automated tests
    Share a captureSessions → Share reportExport selected requests and notes for offline browser review
    Already on Charles Proxy or Fiddler?
    Point your traffic to localhost:8888, install the root cert once, and your team is capturing HTTPS traffic. Import your Charles .p12 cert if you want to keep the same certificate chain.
    Try ProxyCat Free

    Ask about the traffic.
    Keep the full picture in ProxyCat.

    Connect your MCP-compatible AI client to the requests you capture locally. Ask it to find failures, compare status codes and timings, or highlight large responses. Open the request in ProxyCat when you need to inspect headers or payloads.

    • “Show the 5xx requests to api.example.com.”Narrow the capture by hostname and status range.
    • “Which captured requests took over a second?”Review request durations to find candidates for investigation.
    • “Compare the latest two POSTs to api.example.com.”Compare their status, timing and response size.
    MCP / SAMPLE CAPTURE METADATA
    “Show the failed POSTs to api.example.com.”
    Capture ID
    sample-042
    Host
    api.example.com
    Method / status
    POST / 503
    Duration
    1,240 ms
    Response size
    312 bytes
    Illustrative metadata returned by proxycat_list_requests. This is a sample, not a live AI response. The client can inspect an individual capture with proxycat_get_request and check capture state with proxycat_status.

    Connect in three steps

    1. Open Connect AI in ProxyCat and choose Enable for this session.
    2. Copy the generated client configuration into a client that supports local stdio MCP servers.
    3. Capture traffic, then ask your client about it. Choose Disconnect to revoke access.

    Access is off by default and ends when ProxyCat closes. MCP exposes hostnames, methods, status codes, timestamps, timings and byte counts. URL paths, queries, headers and bodies are omitted. Your AI client may send the shared metadata to its provider. MCP access is read-only; it cannot change rules or send requests.

    If you can write a curl command, you can automate your proxy.
    60+ REST API endpoints with interactive Scalar docs. Set up rewrite rules, filters, and throttling in your CI pipeline — no manual clicks, no config files, just HTTP.

    Core workflows, one curl away

    • 01 Create rewrite rules to redirect, mock, or modify any request in flight
    • 02 Toggle throttle presets to simulate any network condition globally
    • 03 Search captured traffic, export sessions, and pipe into your toolchain
    • 04 Compose and send custom requests — like Postman, from your terminal
    Start with localhost examples →
    Rewrite
    Throttle
    Search
    Filter
    # Serve a local mock instead of hitting production curl -X POST http://localhost:5050/api/Tools/rewrite \ -H "Content-Type: application/json" \ -d '{ "name": "Mock user API", "ruleType": "MapLocal", "urlPattern": "*/api/users*", "localFilePath": "./mocks/users.json", "localContentType": "application/json", "localStatusCode": 200 }' # Response { "id": "a3f1c9e0b2d4", "name": "Mock user API", ... }
    Start free. Upgrade when your workflow grows.
    No credit card. No account. Download and start debugging. Use Free for quick inspections. Pro adds unlimited daily capture, HAR exports, saved sessions and Slack alerts for investigations you need to repeat and share.

    Pay once. Keep your eligible version. Renew updates only when you want to.

    Free
    $0 / forever
    Core traffic debugging. No account required.
    • 1,000 requests / day
    • 10 filter rules
    • All 8 rewrite rule types
    • All 14 throttle presets
    • SSL / HTTPS interception
    • Full-text search & replay
    • Full REST API access
    • Read-only MCP for your AI workspace
    Enterprise
    Custom
    For teams buying Pro for multiple people or planning a larger rollout.
    • Everything in Pro
    • Unlimited stored requests
    • Negotiated volume discounts
    • Billing, device and deployment planning
    Grab your platform. Start debugging in 60 seconds.
    One binary. No installer, no dependencies, no Java runtime. Includes the desktop GUI, embedded server, REST API, and web dashboard. Extract it. Run it. Done.
    Windows
    x64
    Download .zip
    macOS
    Apple Silicon (M1/M2/M3)
    Download .tar.gz
    macOS
    Intel (x64)
    Download .tar.gz
    Linux
    x64
    Download .tar.gz
    Linux
    ARM64 / aarch64
    Download .tar.gz

    Docker / Headless / CI

    Docker release coming soon · headless server included with desktop downloads

    All downloads also include a standalone headless server binary in the server/ subfolder.

    A capture is the start of an investigation.

    Find the failed request

    Filter the sample capture to errors, select a request, and inspect its response body to see what went wrong.

    Explore the traffic inspector →

    Try a different response

    Toggle a demo rewrite rule and compare the result. Watch the equivalent API call appear alongside the capture.

    Try a rewrite rule →

    Take the evidence with you

    Preview and export the sample session as HAR, then use the same workflow with your own captures in ProxyCat.

    Preview a HAR export →

    A debugging tool you can keep.

    Pro is a one-time license for one person on up to three devices, with 12 months of updates included. Your last eligible version stays Pro without renewal. The $49 launch offer runs for 60 days after public downloads open; the regular price is $69.

    View Pro availability →
    Everything you're wondering, answered.

    Is the free tier actually free, or is this a "free trial"?

    Actually free. No time limit, no credit card, no account required. Download the binary and use it forever. The free tier includes all core features — SSL interception, all rewrite types, all 14 throttle presets, full-text search, replay, compose, and full REST API access. The free tier is limited to 1,000 captured requests/day and 10 filter rules; HAR export, session save/load, and Slack alerts are Pro features.

    What happens when my included updates end?

    Your eligible purchased version keeps its Pro features permanently. New releases dated after your update cutoff need an optional $39 renewal, which adds 12 months from your current cutoff or the renewal date, whichever is later. There is no automatic renewal. One license covers one person and three device activations; teammates need their own licenses. Start with Free to evaluate the core workflow.

    Why use an API-driven proxy?

    ProxyCat combines a visual traffic inspector with 60+ REST API endpoints. Inspect requests in the app, then script your filters, rewrite rules, and throttling for repeatable tests. Self-contained downloads include the runtime, and headless mode supports automation without opening the desktop app.

    How do I switch from Charles Proxy?

    Download the binary, run it, set your browser or device proxy to localhost:8888, and install the root certificate once. If you're using Charles certificates in your app, you can import your existing .p12 file via the Cert Viewer. Your filters and rewrite rules are JSON — version-control them from day one.

    What about mitmproxy? I'm used to scripting my proxy.

    mitmproxy's Python addon system is powerful but forces you to write and maintain proxy code in a specific runtime. ProxyCat exposes everything via a clean REST API — use any language, any tool, any CI platform. Run rewrite rules in your test suite with two curl commands. No Python environment to manage, no addon reload cycle. Every desktop download also includes a standalone headless server; a public Docker release is planned.

    Can I use it in my CI/CD pipeline?

    Absolutely. Every download includes a headless server binary you can run without a GUI. A public Docker image is planned. Set up rewrite rules, filters, and throttle profiles with curl commands in your pipeline scripts. Teams use it to mock external APIs in integration tests and simulate network failures. Pro features on a server (HAR export, unlimited captures) come from a licence you create on your account page — Use Pro on a server or in CI — and pass as PROXYCAT_LICENSE. Each server or CI job uses one of the three device activations included with that individual user's license. A perpetual license keeps eligible releases in Pro permanently; reissue it after renewing updates to include the new cutoff.

    Does it work with HTTPS / mobile apps?

    ProxyCat generates a local root CA on first launch. Configure the device’s HTTP proxy and install and trust that CA for HTTPS inspection. Desktop browsers and Android/iOS clients that honor the proxy and trust the CA are supported; certificate-pinned apps and clients that ignore system proxy settings need app-specific configuration. Guided setup explains the platform steps.

    What happens when I hit the free tier limits?

    At 1,000 captured requests in a day, new requests stop being captured but the proxy keeps forwarding traffic normally — nothing breaks. Your existing captures, search, and REST API all keep working, and the counter resets at midnight UTC. No forced upgrades, no nag screens. Upgrade to Pro when (and if) you need unlimited.

    Can my team share proxy configurations?

    Yes. Rewrite rules and filter sets are plain JSON on every plan — read them from the API or version-control the files in your data directory alongside your test suites. Pro includes full .pcsession file exchange and selected-request HTML reports for offline browser review. Reports hide most header values and all query values; bodies are optional and aren't automatically redacted. There is no hosted workspace or access-controlled sharing link yet. Pro licenses cover one person each; contact sales for negotiated volume pricing if you're buying for a team.

    Your HTTP traffic shouldn't be a black box.

    Inspect what your app sends, change what comes back, and reproduce the bug. Start with the free tier. No account or credit card required.

    About ProxyCat

    A Shadow Moon Labs product. Inspect, reproduce, and automate HTTP traffic.

    For authorized testing and debugging of systems you own or have permission to test. Captures may include sensitive data; review them before sharing.

    Use is governed by our Terms of Service and Privacy Policy, including license terms and warranty limitations.

    © Shadow Moon Labs. All rights reserved. Third-party components retain their respective licenses.