Sign in

HTTP Toolkit

@httptoolkit.com
110 followers 2 following 55 posts

Beautiful & open-source tools to debug, test and develop with HTTP(S). 👨‍🔧 Built by @pimterry.fyi 🌐 httptoolkit.com 🦣 mastodon.social/@httptoolkit

PostsRepliesMedia
HTTP Toolkit @httptoolkit.com · 23/09/2026
If you're using custom system CAs on Android for TLS - whether that's for HTTPS debugging, ad blocking or local testing - there's trouble brewing. Let's talk about the latest Android 17 changes and how to keep things working:
httptoolkit.com
Android 17 enables certificate transparency, and breaks custom CAs
Do you want to know what your phone is sending & receiving? Nowadays, that means you need to control who it trusts. In modern connections everything sent &...
032
HTTP Toolkit @httptoolkit.com · 24/08/2026
Wow - Daoud Youssef on YouTube (www.youtube.com/@daoudyousse...) has just put out 5 (five!) separate intro videos for all sorts of different HTTP Toolkit use cases. If you want some help getting started, take a look: www.youtube.com/watch?v=vgQA...
youtube.com
05. Intercept android app via ADB and QRcode scan
on this video i have described how to intercept the traffic from Android apps via ADB and qrcode scan #httptoolkit #bugbounty #bugbountytips #infosec #proxy
021
Reposted by HTTP Toolkit
Mark Nottingham @mnot.net · 07/08/2026
What 120 million HTTP responses from Common Crawl reveal about how protocol extensions actually get deployed — and what that should tell us when we design new ones. mnot.net/blog/2026/linting_the_web
1154
HTTP Toolkit @httptoolkit.com · 16/07/2026
200ms in the life of an HTTP request: 200ms.thenodebook.com/
200ms.thenodebook.com
An interactive visualization that follows a single HTTP request through its entire ~200ms life — DNS, TCP, TLS, the kernel, Node's event loop, Postgres, and back
Scroll through the complete life of one HTTP request in real time — from a click in a coffee shop through DNS, TCP, TLS, the kernel, Node's event loop, and Postgres, back to the pixel. Time only passes when you move. 211 ms.
000
HTTP Toolkit @httptoolkit.com · 09/07/2026
Coming soon to an HTTP Toolkit near you...
000
HTTP Toolkit @httptoolkit.com · 30/06/2026
All free & open source. Visit the root page at testserver.host to see the full docs, or check out github.com/httptoolkit/... for the source and self-hosting instructions.
testserver.host
Testserver
Endpoints can be combined using double-dashes, e.g. expired--revoked--http2--tls-v1-2.{domain} will return an expired and revoked certificate, use TLSv1.2, and then negotiate HTTP/2 on the connection.
000
HTTP Toolkit @httptoolkit.com · 30/06/2026
(For extra fun, refresh the HTTP/2 page to see HTTP header compression in action: on my machine, the HEADERS frame drops from 499 bytes to 27 by magic)
100
HTTP Toolkit @httptoolkit.com · 30/06/2026
Ever wonder what HTTP/1 and HTTP/2 data looks like for the exact same request? http1.testserver.host/echo http2.testserver.host/echo HTTP/1 is a raw string, HTTP/2 includes parsed JSON per frame, with the raw data in the `payload_hex` field.
http2.testserver.host
GET /echo HTTP/1.1User-Agent: facebookplatform/1.0 (+http://developers.facebook.com)Accept-Encoding: identityAccept: */*Sentry-Trace: 07d6d9eb3f194845ae1c7a388a325401-597a1cc9bba94fd0Baggage: sentry-trace_id=07d6d9eb3f194845ae1c7a388a325401,sentry-sample_rand=0.694727,sentry-environment=production,sentry-release=b2607d563ea96b97afa74ec39e30840bb12e6e73,sentry-public_key=b2dd86967d3344d3bb083da197fca59fHost: http2.testserver.host
100
HTTP Toolkit @httptoolkit.com · 30/06/2026
And combine them too! revoked--tls-v1-2.testserver.host/ws/message/hello/message/goodbye/close A websocket server that only supports TLS v1.2 and uses a revoked certificate - once you connect, it sends hello, then sends goodbye, then closes the connection.
revoked.testserver.host
100
HTTP Toolkit @httptoolkit.com · 30/06/2026
Chainable endpoints? HTTP: testserver.host/info/123/delay/1/status/404 - return a 123 intermediate status, wait 1 second, then return a 404 TLS: incomplete-chain--expired--http2.testserver.host: give me an expired cert, missing the intermediate cert in the chain, and exclusively negotiate HTTP/2.
testserver.host
100
HTTP Toolkit @httptoolkit.com · 30/06/2026
End result: on my local machine & wifi, curl -kv expired.badssl.com/ takes more than a second, and httpbin.org/anything takes 2.2s. expired.testserver.host/anything takes about 150ms 🚀
httpbin.org
100
HTTP Toolkit @httptoolkit.com · 30/06/2026
Faster & more reliable? 1. Horizontal autoscaling & globally distributed: low latency everywhere, failover, easy to scale. 2. Cert issuance 100% automated, with ACME and a local CA (many badssl cases need manual setup, and so rot: failing due to expiry, not the real cause).
100
HTTP Toolkit @httptoolkit.com · 30/06/2026
Extras you say? * More endpoints, like /echo (echoes back raw HTTP), /encoding/zstd, and /error/reset * Websocket support * Faster & more reliable than either * Combining HTTP & TLS tests (give me an expired cert, then a 404 response) * Chainable endpoints, for both HTTP & TLS
100
HTTP Toolkit @httptoolkit.com · 30/06/2026
Have you seen testserver.host/? As part of building HTTP Toolkit I often need a remote servers for testing edge cases, so I've built one! Now fairly mature & stable. It's httpbin.org plus badssl.com plus lots of extras.
testserver.host
Testserver
Endpoints can be combined using double-dashes, e.g. expired--revoked--http2--tls-v1-2.{domain} will return an expired and revoked certificate, use TLSv1.2, and then negotiate HTTP/2 on the connection.
142
Reposted by HTTP Toolkit
James Snell @jasnell.me · 14/06/2026
Oh. After many long years... HTTP now officially has a standard QUERY method. Think: cacheable, idempotent GET that can carry a meaningful payload. We can now all stop bastardizing POST. auth48-transition.rfc-editor.org/authors/rfc1...
auth48-transition.rfc-editor.org
37114
Reposted by HTTP Toolkit
MDN Web Docs @developer.mozilla.org · 18/05/2026
Ever wish HTTP status codes were easier to remember? 🖼️ Check out this MDN cheatsheet that pairs each status code with an emoji to help you visualize what each one means, from 200 OK ✅ to 418 I’m a teapot 🫖 Check it out 👇
A colorful infographic titled “MDN HTTP Code Cheatsheet with Emojis.” It categorizes HTTP status codes using emoji-enhanced lists grouped by status code classes.
2474
HTTP Toolkit @httptoolkit.com · 14/05/2026
HTTP Toolkit can now automatically detect, parse & expose the EXIF metadata within intercepted images. Quickly inspect the secret metadata in images to understand when, where, and how they were captured, and plenty more; EXIF can hide a surprising amount! en.wikipedia.org/wiki/Exif
010
HTTP Toolkit @httptoolkit.com · 07/05/2026
Need a second opinion understanding your HTTP, or a quick first pass to find the good bits? HTTP Toolkit now has MCP support! Copy-paste setup for Claude Code and plenty more, so it just takes seconds to get your LLMs intercepting & inspecting HTTP all by themselves ✨
An HTTP Toolkit screenshot, showing a modal titled "Connect HTTP Toolkit to your LLM"
210
Reposted by HTTP Toolkit
Tim Perry @pimterry.fyi · 29/04/2026
I've been thinking about simonomi.dev/blog/color-c.... Whipped up a quick prototype for HTTP Toolkit's hex view - what do you think? Interesting and more useful than monochrome, or just visually noisy? See if you can guess what each file type is here - answers in the alt text 😀
A hex view with bytes coloured by value - in this case a favicon (lots of 00 at the start, then repeating patterns later).A hex view with bytes coloured by value - in this case HTML (lots of ascii values with similar colours, and quite a few symbols for the < > etc)A hex view with bytes coloured by value - in this case protobuf - a mix of ascii strings and very low 0X bytes.
021
HTTP Toolkit @httptoolkit.com · 31/03/2026
What's perfect mirroring? Before, WebSockets were negotiated separately up & down stream. The data was the same but some handshake params could differ. We now take full low-level control of negotiation and link the two directly instead, to perfectly clone the full socket 👯
000
HTTP Toolkit @httptoolkit.com · 31/03/2026
The proxy inside HTTP Toolkit (github.com/httptoolkit/...) was just updated: 30%+ more throughput, lower latency, and perfect mirroring for WebSockets too. Live now in Mockttp for custom proxies, coming to an HTTP Toolkit near you later this week!
110
HTTP Toolkit @httptoolkit.com · 23/02/2026
Wouldn't it be nice if HTTP compression suddenly got 90% better for a whole bunch of common web scenarios? Dictionary Compression is here to save the day: httptoolkit.com/blog/diction...
httptoolkit.com
Dictionary Compression is finally here, and it's ridiculously good
Dictionary compression could completely change how applications send data over the web. It's recently gained broad support, and offers absurd real-world...
021
HTTP Toolkit @httptoolkit.com · 09/02/2026
Vitor Daniel reverse engineered & probed his university's mobile app API with HTTP Toolkit, discovered a vulnerable endpoint leaking private data, and successfully worked with them to patch the issue and secure the service. Great write-up! vitordaniel.is-a.dev/blog/como-eu...
vitordaniel.is-a.dev
Hackeei minha universidade e obtive acesso aos dados de todos os alunos
Um relato pessoal sobre como descobri e reportei uma vulnerabilidade crítica de segurança no sistema da UFRN
010
HTTP Toolkit @httptoolkit.com · 03/02/2026
It'd be easy to add more one-click filters to this menu - any suggestions for what you'd like to be able to quickly add?
000
HTTP Toolkit @httptoolkit.com · 03/02/2026
It's hard to find the needle in the haystack sometimes... You can now right-click any request in HTTP Toolkit to use its hostname as a filter, to quickly hide any host or show it exclusively, in one click right from the traffic itself 🪡
110
HTTP Toolkit @httptoolkit.com · 19/01/2026
Interested in how rate limiting can work to throttle HTTP clients effectively? Tony Finch has written some fascinating thoughts about the (relatively) new HTTP standard Rate Limit Header: dotat.at/@/2026-01-13...
dotat.at
HTTP RateLimit headers – Tony Finch
There is an IETF draft that aims to standardize RateLimit header fields for HTTP. A RateLimit header in a successful response can inform a client when it might expect to be throttled, so it can avoid 429 Too Many Requests errors. Servers can also include RateLimit headers in a 429 response to make the error more informative.
040
HTTP Toolkit @httptoolkit.com · 04/12/2025
Interested in debugging terminal & Docker network traffic with HTTP Toolkit? Take a skim through this quick intro from Learn Code Camp to get started: learncodecamp.net/terminal-htt...
learncodecamp.net
Debugging HTTP Traffic Like a Pro: HTTP Toolkit and Terminal Interception - Learn Code Camp
Debug HTTP traffic from your terminal with HTTP Toolkit. One-click interception for git, npm, curl & more. See exactly what CLI tools send and receive.
000
HTTP Toolkit @httptoolkit.com · 27/11/2025
As if this weren't exciting enough already, I've also just sent this out to the mailing list and written up a whole summary of what's new in HTTP Toolkit recently, and what could be coming up next! Take a look: http-toolkit.mailcoach.app/webview/camp...
http-toolkit.mailcoach.app
Black Friday, big new features, and the next steps for HTTP Toolkit
000
HTTP Toolkit @httptoolkit.com · 27/11/2025
It's that time of year again, and so as the prophecy foretold, there must be a new HTTP Toolkit Black Friday deal 💸 This year it's **50% off forever** on all HTTP Toolkit Pro annual subscriptions, from now till Tuesday, with code BLACKFRIDAY25. Happy Thanksgiving/shopping week!
110
HTTP Toolkit @httptoolkit.com · 24/11/2025
Big milestone: HTTP Toolkit just crossed one million downloads! 🚀 Honestly I didn't think it'd ever get this far, I'm blown away. A huge thanks to all the users, contributors & supporters over the years ❤️. Onwards!
021
HTTP Toolkit @httptoolkit.com · 12/11/2025
Have suggestions about what else should be added? Get in touch: github.com/httptoolkit/...
000
HTTP Toolkit @httptoolkit.com · 12/11/2025
If you like turning HTTP into code, you'll be excited to hear that HTTP Toolkit can now export requests as ready-to-use code for: - Rust's Reqwest library - Ruby's Faraday library - Crystal's built-in APIs - Spring RestClient on the JVM Plus plenty of other fixes & tweaks to improve other cases.
111
HTTP Toolkit @httptoolkit.com · 28/10/2025
And as ever, this is all #opensource - if you want to do the same thing elsewhere there's a new standalone JS library just for this: github.com/httptoolkit/...
020
HTTP Toolkit @httptoolkit.com · 28/10/2025
Want to quickly get a curl request into HTTP Toolkit's Send tool, to start tweaking & testing parameters? If you paste curl commands directly into the Send page URL bar, it'll now automatically parse it and fill out all the fields for you ✨
110
HTTP Toolkit @httptoolkit.com · 27/10/2025
The best feature requests are the ones where the feature is already live 😀 github.com/httptoolkit/... Did you know you can breakpoint requests & responses in live traffic with HTTP Toolkit, to modify them, inject a response or simulate errors?
github.com
Add breakpoint-style debugging for app traffic · Issue #805 · httptoolkit/httptoolkit
It would be amazing if HTTP Toolkit could include a feature similar to browser DevTools breakpoints, but for app network requests. Right now, HTTP Toolkit lets you intercept, view, and mock request...
020
HTTP Toolkit @httptoolkit.com · 14/10/2025
Have ideas about other multi-step rules you'd like to see? Get in touch: github.com/httptoolkit/...
000
HTTP Toolkit @httptoolkit.com · 14/10/2025
Multi-step HTTP rules are now live! 🪜 As the first new steps, you can now add custom delays during processing to simulate latency, and attach request and/or response webhooks to rules to fire data out from HTTP Toolkit for matched traffic. More to come soon!
110
HTTP Toolkit @httptoolkit.com · 09/10/2025
Another year of paying #opensource maintainers for their hard work 🦾 alongside the rest of the OpenSourcePledge.com businesses, and to celebrate: we're back up on the NASDAQ tower in Times Square!
0102
HTTP Toolkit @httptoolkit.com · 07/10/2025
Reverse engineering can be intimidating, but modern tools are fantastic, and it's honestly easier than it sounds to get started digging into app's internals and changing their their behaviour. Take a look at the HTTP Toolkit guide for a quick intro: httptoolkit.com/blog/android...
httptoolkit.com
Reverse engineering & modifying Android apps with JADX & Frida
I get a lot of emails from users who want to know exactly what their favourite Android app is doing, and want to tweak and change how that works for...
000
HTTP Toolkit @httptoolkit.com · 02/10/2025
That means you can use HTTP Toolkit to easily capture, read & modify HTTP at the application level, and simultaneously examine the underlying packets at the same time, with automatic decryption so you can see everything (like which TLS handshake is which 403 response).
000
HTTP Toolkit @httptoolkit.com · 02/10/2025
Want to dig into traffic byte-by-byte, to read your TLS handshakes and TCP packets directly? With the new support for keylog files in the Pro settings, you can now integrate HTTP Toolkit into tools like Wireshark 🦈
100
Reposted by HTTP Toolkit
Ayuda Efectiva @ayudaefectiva.bsky.social · 23/09/2025
¡Enhorabuena a @httptoolkit.com por obtener el Sello Ayuda Efectiva como empresa de alto impacto! La empresa ha donado al menos un 0,7% de sus ingresos a los programas benéficos más efectivos. 🏅 Página de certificación e impacto: ayudaefectiva.org/empresa/http...
011
HTTP Toolkit @httptoolkit.com · 21/08/2025
Redirecting traffic? HTTP Toolkit transform rules just gained a long list of new options, including arbitrary regex match & replace logic, precisely targeted for every URL component - fully combinable with all the other existing request & response transforms.
000
Reposted by HTTP Toolkit
Tim Perry @pimterry.fyi · 24/07/2025
I've been doing some ridiculously neat reverse engineering recently. Check this out: github.com/httptoolkit/... That code is modifying functions inside Flutter apps, without debug info, by *fingerprinting known chunks of assembly* for each CPU architecture, and then scanning memory to find them 🤯
github.com
111
HTTP Toolkit @httptoolkit.com · 17/06/2025
Check out the full Mockttp v4.0.0 release notes here: github.com/httptoolkit/...
github.com
Release v4.0.0 · httptoolkit/mockttp
import * as mockttp from 'mockttp'; const https = await mockttp.generateCACertificate(); const server = getLocal({ https }); server.forPost() .forHostname("example.com") .delay(500) .thenRe...
000
HTTP Toolkit @httptoolkit.com · 17/06/2025
Want to script your own MitM proxy? You can use HTTP Toolkit's internals standalone via Mockttp, a JS library to build HTTP, WebSocket & TLS intercepting proxies: github.com/httptoolkit/... v4 just went live: advanced URL regex rewriting, delay mixins, and non-HTTP proxying too 🚀
github.com
GitHub - httptoolkit/mockttp: Powerful friendly HTTP mock server & proxy library
Powerful friendly HTTP mock server & proxy library - httptoolkit/mockttp
120
Reposted by HTTP Toolkit
wraptile @wraptile.fosstodon.org.ap.brid.gy · 21/05/2025
Having a rooted android device with man-in-the-middle http capture using #httpToolkit is so much fun. It's crazy how much evil shit the apps are up to 🤯 httptoolkit.com ALWAYS use the website instead of the app if possible. #android #infosec
httptoolkit.com
Intercept, debug & build with HTTP
Beautiful, cross-platform & open-source tools for debugging, testing and building with HTTP(S), on Windows, Linux & Mac.
023
Reposted by HTTP Toolkit
James Snell @jasnell.me · 22/05/2025
It's been a long time coming but the http QUERY method spec is nearly done www.ietf.org/archive/id/d...
ietf.org
The HTTP QUERY Method
This specification defines a new HTTP method, QUERY, as a safe, idempotent request method that can carry request content.
23010
HTTP Toolkit @httptoolkit.com · 11/04/2025
Some major performance updates have gone live this week 🚀 With a big internal redesign, memory usage just dropped 40%, and processing input got up to 50x (!) faster. A nice drop in CPU while intercepting, but a huge boost when you load a HAR of 100s of thousands of requests.
020
HTTP Toolkit @httptoolkit.com · 31/03/2025
I can see a blip in the CDN logs, which seems to have just affected some specific regions, but only briefly. I've manually flushed all CDN caches to reset it just in case, but I can't see any issues elsewhere now. If it's still not working for you it's most likely local caching of some sort.
010