Sign in

Tim Perry

@pimterry.fyi
768 followers 762 following 210 posts

Founder of httptoolkit.com (@httptoolkit.com), Node.js core collaborator, tech speaker, drummer, mountain biker and dad. 🇬🇧/🇨🇦 living in 🇪🇸

PostsRepliesMedia
Tim Perry @pimterry.fyi · 01/10/2026
I released github.com/pimterry/log... back in 2013. IE6 & 7 had no console.log, others had inconsistent (even intermittently available!) APIs, and basics like real log levels were impossible. Very cool to see Node discussing a fully featured built-in logger, 13 years later. We've come a long way ❤️
Node:logger outline on a slide at the Node collaborator summit
161
Tim Perry @pimterry.fyi · 29/09/2026
Node.js going to the moon at @nodeconf.eu 📈
251
Tim Perry @pimterry.fyi · 29/04/2026
I've been thinking about simonomi.dev/blog/color-c.... Whipped up a quick prototype for HTTP Toolkit's hex view - what do you think? Interesting and more useful than monochrome, or just visually noisy? See if you can guess what each file type is here - answers in the alt text 😀
A hex view with bytes coloured by value - in this case a favicon (lots of 00 at the start, then repeating patterns later).A hex view with bytes coloured by value - in this case HTML (lots of ascii values with similar colours, and quite a few symbols for the < > etc)A hex view with bytes coloured by value - in this case protobuf - a mix of ascii strings and very low 0X bytes.
021
Tim Perry @pimterry.fyi · 05/04/2026
Damn I got this as well! Just assumed it was spam and ignored this (and the LinkedIn follow up) turns out I dodged a bullet 😅
OpenFort slack invite
0142
Tim Perry @pimterry.fyi · 19/03/2026
I've been playing around with agent-powered HTTP debugging -there's a lot of potential here... Even just with minimal data, Claude gets a really good understanding of flows very quickly, amazing for exploring. A quick summary of overall traffic & state flow across ~160 requests & responses:
Claude output:

Summary of the state flow

  Edge launches (no state)
      │
      ├─→ Bing qbox (cookieless) ──→ Bing sets MUID + 9 others
      │
      ├─→ SmartScreen (token in Authorization header, no cookies)
      │
      └─→ GET reddit.com
           │ 301 → www.reddit.com (no cookies set on redirect)
           │
           └─→ GET www.reddit.com
                │ Sets: loid, session_tracker, csrf_token, token_v2, csv, edgebucket
                │
                ├─→ POST /svc/shreddit/events  ← sends all 6 cookies back
                │   └─ response refreshes session_tracker
                │
                ├─→ POST /svc/shreddit/graphql  ← sends all 6 cookies (with updated session_tracker)
                │   └─ response refreshes session_tracker again
                │
                ├─→ GET /svc/shreddit/feeds/popular-feed  ← sends all 6 cookies
                │   └─ response refreshes session_tracker again
                │
                ├─→ POST alb.reddit.com/track  ← NO cookies (cross-subdomain, no-cors)
                │
                └─→ GET www.redditstatic.com/*  ← NO cookies (CDN, different domain)

  The key insight is that Reddit bootstraps the entire anonymous session in a single response — one page load sets up identity (loid), session tracking, CSRF protection, an auth JWT, A/B bucketing, and a
  cookie format version — and then every subsequent same-origin request carries all of that state forward, with session_tracker being the only one that gets continuously rotated.
202
Tim Perry @pimterry.fyi · 04/03/2026
Wow, I sure am glad we have such diversity in the CSS world and that AIs consider all of the options fairly, instead of hypothetically being hyper focused on any specific library.
Which UI styling approach do you prefer?

  1. Tailwind + shadcn/ui (Recommended)
     Tailwind for utility CSS + shadcn/ui (Radix-based) for accessible, customizable components. Best native feel
     with full control.
  2. Tailwind + Radix UI
     Tailwind for styling + raw Radix primitives. More manual work but maximum flexibility.
  3. Ionic + Tailwind
     Ionic provides native-quality components and transitions out of the box. Heavier but purpose-built for
     Capacitor apps.
120
Tim Perry @pimterry.fyi · 09/12/2025
My AI code generation has decided it can generate an inline private key pair by itself, and I think we might be in trouble...
Node.js code that loads TLS & crypto, starts defining a KEY variable with BEGIN PRIVATE KEY, and then loops on the same 'random' string forever...
010
Tim Perry @pimterry.fyi · 16/10/2025
Security wise, I think that means nothing's accessible without access to both the physical key (=personally rob me) _and_ BitW login (=know the password or get yubikey+active session). Hopefully this is hit-me-with-a-wrench-security equivalent, I think?
100
Tim Perry @pimterry.fyi · 28/02/2025
Publish a new site, and within 2 seconds loads of people will immediately jump in to help you test the security! It takes a village, so great to see people so committed to helping new websites to check for good security & deployment practices like this 😆
A series of log lines saying "Handling request to..." and paths like "/.env.local", "/www/.git/config", and other probably-sensitive URLs
1213
Tim Perry @pimterry.fyi · 19/12/2024
In the end I have doubled down on this (slightly silly) watercolour map live-wallpaper project! Very happy with it so far, the maps are gorgeous and it's super nice having it slowly change as you travel about. Any Android users want to help with testing? DM me your email and I'll set you up.
WallMapp marketing image - lots of pretty mapsBeautiful map of veniceA lovely map of the Big AppleYet another map (this time showing Berlin)
130
Tim Perry @pimterry.fyi · 18/12/2024
Wake up babe, a new date format just dropped
Upgrade your plan or wait until -4712-01-01 (???) to continue using Copilot
000
Tim Perry @pimterry.fyi · 02/12/2024
Whipped up a quick Android app over the weekend: a live Android wallpaper of the beautiful Stamen Watercolour maps of your current location. Mostly just for my use, but would anybody else be interested in this? Might publish it properly, if it'd be popular. Let me know if you want to help test it!
130
Tim Perry @pimterry.fyi · 25/11/2024
All now done! Laptop upgraded to Ryzen (notably faster, quieter & much better battery life) and I have a new server up & running that neatly fits on top of the mac mini that's under my monitor stand in the office (please pretend to ignore the horrible mess of surrounding cables and tech detritus)
Original laptop plus new parts galoreOpening up the current laptop to look at the initial componentsThe original mainboard now living inside its new caseThe mainboard in its case living underneath my monitor stand, on top of a mac mini (with the original laptop running happily, sitting just to the right).
110
Tim Perry @pimterry.fyi · 21/11/2024
Looks deprecated - if you run it (npm v10.2.4) it warns you not to use it:
110
Tim Perry @pimterry.fyi · 07/11/2024
And why is CI broken now? For the HTTP Toolkit desktop app build, seriously 99% of the time, this is the answer:
A prompt requesting that you accept the new Apple Developer Program License Agreement
120