Available now

Interceptor is available for Ubuntu.

Download the local-first desktop proxy for authorized security testing, replay, diagnostics, and reporting.

Download

Authorized web security testing

Interceptor

Interceptor is a desktop HTTP/HTTPS proxy for security testers, developers, and auditors who need controlled traffic capture, opt-in TLS interception, API surface modeling, HTTP/2 and HTTP/3 replay, hardened QPACK/MASQUE/WebTransport handling, ergonomic review tools, and evidence-ready reporting without sending project data to a cloud service.

Interceptor desktop workspace

A local-first HTTP and HTTPS testing proxy for capture, replay, diagnostics, findings, and reporting.

HTTP/HTTPSAPI SurfaceWebSocketReports
180+documented features
1.105.0current release
100%local-first workflow
99€per year

Major categories

A complete manual testing loop.

Interceptor combines capture, low-level diagnostics, inferred API modeling, replay, scanning, project organization, and reporting so a test can move from first request to final evidence without losing context.

01

Proxy & Capture

Capture HTTP and HTTPS traffic, handle CONNECT, keep upstream behavior visible, and control TLS interception explicitly.

02

Intercept & Edit

Pause requests or responses, edit raw messages, forward or drop, and keep user-visible modifications auditable.

03

Replay & Fuzz

Replay HTTP/1.1, HTTPS, HTTP/2, and h2c traffic, compare variants, track outcomes, and keep active work inside defined scope.

04

Storage & Search

Persist exchanges locally, search full text, spool large bodies, annotate traffic, and preserve project sessions.

05

Scanning & Findings

Generate passive findings and run a scope-gated active scanner with dozens of opt-in checks, OAST correlation, a gated intrusive mode, lifecycle state, and issues linked to evidence.

06

Project Workflow

Use project health, target scope, checklists, evidence boards, and reports to keep engagements organized.

07

Network Diagnostics

Inspect DNS, TCP, upstream proxy, TLS handshake, byte counters, close reasons, and chaining behavior.

08

Safety & Extensibility

Keep TLS MITM opt-in, CA handling manual, active tooling scope-aware, and extensions explicit.

09

Modern Protocols

Validate HTTP/3 frames, QPACK fields, MASQUE CONNECT-UDP, WebTransport, ECH, HTTPS/SVCB, Alt-Svc, and RFC coverage from one reference page.

10

Auto API Model

Infer normalized API routes from history, review request/response shape evidence, generate endpoint test checklists, diff model baselines, and launch safe workflows from modeled endpoints.

11

Review UI

Search, render, highlight, and line-number content in unified themed lists with zebra striping and scroll-stable live updates, rearrange request/response and History panels, switch themes, and persist project layouts.

Product boundary

Built for authorized environments.

TLS interception is opt-in. CA trust is never installed automatically. Active tooling is scope-aware. The product is intended for authorized security testing, application debugging, and internal traffic analysis.

View the full feature list

Start with traffic. Finish with evidence.

Use Interceptor to understand behavior, test hypotheses, compare variants, and produce a clean record of what was observed.

See pricing