Everything Hollowport can do

Grouped by what you're actually trying to do, not an alphabetical settings list.

iPhone

Everything below already runs, entirely on-device — no companion machine required for the iPhone workflow. Not yet publicly available; get notified at launch.

Mac

Capture directly on Mac with its own Network Extension, or pair with your iPhone to bring its live traffic into the same investigation workspace — replay, compare, and investigate on a bigger screen either way. Neither app is publicly available yet — both are launching together.

Capture

See what your apps actually send. Real HTTP/1.1, HTTP/2, and HTTP/3 traffic, decrypted and readable, on the device where it happens.

HTTPS Interception

A single trusted certificate decrypts HTTPS traffic from Safari and native apps alike, entirely on-device — no Wi-Fi proxy, no companion machine.

HTTP/1.1, HTTP/2 & HTTP/3

Full HTTP/1.1, HTTP/2, and real, end-to-end HTTP/3 (QUIC) capture on ordinary, non-pinned traffic. The boundary is certificate pinning, not protocol version.

WebSockets

Opt in per host to see individual frames, sent and received, the same way HTTP requests appear in Capture.

GraphQL & gRPC

GraphQL operations are recognized and decoded automatically; gRPC and raw Protocol Buffers get a readable field tree even with no .proto schema to work from.

Search & Filter

Narrow a live or completed capture by host, path, or method without losing your place in the request list.

Understand

Read a request the way it actually looks, not a wall of unformatted bytes.

Problems

Failures are classified and grouped by cause — HTTP errors, DNS/connection failures, upstream TLS, interception — instead of left as identical rows in a raw log.

AI Explanations

A plain-language read on a confusing failure, generated entirely by Apple's on-device model. Nothing about your traffic is sent anywhere to produce it.

Structured Bodies

Pretty-printed, collapsible JSON; automatic GraphQL and gRPC/protobuf decoding — the actual shape of the data, not a flat string to scroll through.

Investigate

Turn a failure into a finding you can actually support with evidence.

Investigations

Related failures are correlated into a single incident — timeline, affected endpoints, and whether it's ongoing or recovered. Individual findings underneath are split into Confirmed (directly measured) and Possible (evidence-grounded, but inferential), so a conclusion is never dressed up as a fact it isn't.

Replay & Replay ×N

Edit and resend any captured request — with a one-tap Remove Authentication action, a configurable delay, or a throttle profile scoped to that one send — or repeat it several times with Replay ×N to check whether the outcome, latency, and body actually stay consistent.

Compare

A structural diff between two requests that reads back what actually changed in plain language — "Remove Authentication," "Add Delay" — instead of a raw field list, plus a narrow, evidence-backed read, always hedged, never a guess, on whether your change explains the result.

Collections & Assertions

Chain requests together with variables and secrets, and attach assertions — status code, duration, response size, header, body content, or JSON path — that run automatically every time the Collection executes, so a regression doesn't slip by quietly.

Automate

Query and script against captured traffic yourself, entirely on-device, for the searches a fixed UI can't anticipate.

JavaScript Scripting

Write JavaScript against captured traffic through the Hollowport namespace — flows, headers, bodies, timing, gRPC and GraphQL fields — to search, filter, and summarize a capture in ways the built-in views don't.

29 Starter Templates

Ready-made scripts for the searches people actually reach for: failed and slow requests, repeated calls, JWTs and API keys, GraphQL errors, and more — duplicate one and adapt it instead of starting from a blank editor.

require() and Reusable Modules

Pull in a built-in helper — crypto, base64/hex encoding, JWT decoding, UUIDs, diffing — or one of your own saved scripts marked as a module, so common logic doesn't get copy-pasted between scripts.

On-Device, Read-Only

Scripts run against a snapshot of already-captured data with no network access, no filesystem access, and no way to modify live traffic — enforced by the runtime and covered by its own test suite, not just documented.

Control

Intervene in live traffic on purpose — pause it, automate a change, replace a response, or simulate a bad network — so you can test a hypothesis against real traffic instead of guessing how your app would behave. The four scale up in scope: a Breakpoint handles one request by hand, Rules and Mocking repeat a targeted change automatically, and Chaos tests resilience broadly.

Breakpoints

Pause a live request — or its response — on a matching host before it's delivered. Edit a request's method, path, query parameters, headers, or body; edit a response's status, headers, or body. Then forward it as edited, reset it back to exactly what was captured, or abort the exchange outright.

Rules

The same interventions, automated and repeatable — redirect, block, throttle, mock, or rewrite headers, matched by wildcard or full regex, applied every time without you tapping through it live.

Mocking

Replace a real response with one you control — a specific status, headers, and body — to test how your app behaves against a server state you can't otherwise produce on demand, like a 500 from a backend that's actually healthy. One tap turns any captured response into a starting point: Create Mock Rule from its detail view, then adjust exactly what comes back.

Network Chaos

One-tap presets — Poor Network, Offline API, Slow Backend, Server Errors, Auth Failure — for resilience testing without hand-building a Rule each time.

Export

Take a request, or a whole capture, out of Hollowport in the format you need next.

HAR Export

Export a full capture as a standard HTTP Archive, readable by browser dev tools and other proxy tools.

Copy as Code

Generate a ready-to-run cURL command or client-code snippet directly from a captured request.

Redaction

Credentials and personal data are stripped by default on every export and share — on unless you explicitly need the raw values.

Want the step-by-step on any of this?

Browse the Help center