Built for iPhone · Mac is next
Capture. Investigate. Prove.
Capture, inspect, investigate, replay, and experiment with real network traffic — directly on the device you're testing, with no separate machine required.
Why Hollowport
The entire debugging workflow runs on the device you're testing.
Charles and Proxyman are serious, capable tools. Hollowport takes a different approach: the on-device experience is the product itself. Built around a Network Extension and a single trusted certificate, Hollowport requires no separate device or desktop software for the iPhone workflow.
Once the certificate is trusted, supported traffic from Safari and native apps alike appears as individual requests — decrypted and readable, right on the phone where it actually happens.
Built around the device you're debugging
Hollowport runs its interception layer directly on the device, so the traffic you're investigating stays in the same environment where the problem occurs.
No Wi-Fi proxy configuration. No companion machine. No desktop process to keep running.
A look inside Hollowport
Every request, laid bare
Not a packet count or a connection log — the actual method, host, path, status, headers, and body, decrypted and readable, for every request your device makes.
Response headers
"error": "invalid_token",
"error_description": "Access token expired",
"expired_at": "2026-08-01T09:41:02Z"
}
The investigation workflow
Capture is just the beginning.
See the request. Inspect the response. Change the request. Send it again. Then go further.
Hollowport helps you organize the investigation itself — connecting problems to evidence, testing hypotheses through replay and experiments, comparing attempts, and preserving what you learned.
From capture to proof.
Capture
See the actual traffic, decrypted on-device.
Understand
Read the real headers and body — JSON, gRPC, protobuf, all decoded.
Investigate
Problems groups failures by cause; Investigate links the evidence to a finding.
Reproduce
Replay the request, edited or repeated, to see if it happens again.
Compare
See exactly what changed between two attempts, and what that explains.
Preserve
Keep the evidence — linked to the finding, exported, or both.
Capabilities
What's actually in the toolbox
See what your apps actually send.
HTTP/1.1 and HTTP/2, headers and bodies, GraphQL and gRPC, and decrypted WebSocket frames — every connection your device makes, decoded and readable.
Stop guessing why a request failed.
Problems groups failures by cause — DNS, TLS, HTTP errors, interception — and Investigate connects the evidence to a Confirmed or Possible finding, not just a status code.
Pause traffic before it leaves your device.
Catch a live request on a matching host, inspect it, edit it, or drop it — before it's ever forwarded.
Test the network you wish you had.
One-tap presets simulate a slow connection, a flaky backend, or an outright outage, so you can see how your app actually behaves.
Change the request. Send it again.
Edit a captured request and resend it, repeat it to check for flakiness, or compare two attempts side by side to see exactly what changed.
Chain requests into a real workflow.
Variables and secrets carry a value from one response into the next request — plus automated pass/fail checks against status, headers, or a JSON path, so a regression doesn't slip by quietly.
Who it's for
Built for people who debug the real world
iOS Developers
Debug API calls without leaving the device you're already testing on.
QA & Testers
Investigate failures that only happen on a real device, on a real network.
Security Researchers
Inspect exactly what an app sends over the wire, TLS included.
Solo & Indie Developers
A real traffic inspector without a lab setup or a second machine.
Privacy
Nothing you capture ever leaves your device
No account, no server
There's nothing to sign in to. Captured traffic is stored locally on the device and never uploaded to Hollowport or anyone else.
AI stays on-device
"Explain with AI" runs on Apple's on-device model only — never Apple's Private Cloud Compute, never a third-party service.
Gone when you remove it
Delete the app and your capture history, certificate, and settings go with it. Nothing lingers on a server, because there isn't one.
What Hollowport can't decrypt
Certificate-pinned traffic — banking apps, and Apple's own push notifications and iCloud Private Relay — is visible at the connection level but can't be decrypted. That's a platform limit no on-device tool gets around, stated plainly rather than glossed over.
Coming soon
Debug wherever the bug happens.
Hollowport is an iOS app for developers and QA — coming soon to the App Store. Leave your email and we'll let you know the moment it's live.