Everything Hollowport can do
Grouped by what you're actually trying to do, not an alphabetical settings list.
iPhone
Everything below already runs, entirely on-device — no companion machine required for the iPhone workflow. Not yet publicly available; get notified at launch.
Mac
Capture directly on Mac with its own Network Extension, or pair with your iPhone to bring its live traffic into the same investigation workspace — replay, compare, and investigate on a bigger screen either way. Neither app is publicly available yet — both are launching together.
Capture
See what your apps actually send. Real HTTP/1.1, HTTP/2, and HTTP/3 traffic, decrypted and readable, on the device where it happens.
HTTPS Interception
A single trusted certificate decrypts HTTPS traffic from Safari and native apps alike, entirely on-device — no Wi-Fi proxy, no companion machine.
HTTP/1.1, HTTP/2 & HTTP/3
Full HTTP/1.1, HTTP/2, and real, end-to-end HTTP/3 (QUIC) capture on ordinary, non-pinned traffic. The boundary is certificate pinning, not protocol version.
WebSockets
Opt in per host to see individual frames, sent and received, the same way HTTP requests appear in Capture.
GraphQL & gRPC
GraphQL operations are recognized and decoded automatically; gRPC and raw Protocol Buffers get a readable field tree even with no .proto schema to work from.
Search & Filter
Narrow a live or completed capture by host, path, or method without losing your place in the request list.
Understand
Read a request the way it actually looks, not a wall of unformatted bytes.
Problems
Failures are classified and grouped by cause — HTTP errors, DNS/connection failures, upstream TLS, interception — instead of left as identical rows in a raw log.
AI Explanations
A plain-language read on a confusing failure, generated entirely by Apple's on-device model. Nothing about your traffic is sent anywhere to produce it.
Structured Bodies
Pretty-printed, collapsible JSON; automatic GraphQL and gRPC/protobuf decoding — the actual shape of the data, not a flat string to scroll through.
Investigate
Turn a failure into a finding you can actually support with evidence.
Investigations
Related failures are correlated into a single incident — timeline, affected endpoints, and whether it's ongoing or recovered. Individual findings underneath are split into Confirmed (directly measured) and Possible (evidence-grounded, but inferential), so a conclusion is never dressed up as a fact it isn't.
Replay & Replay ×N
Edit and resend any captured request — with a one-tap Remove Authentication action, a configurable delay, or a throttle profile scoped to that one send — or repeat it several times with Replay ×N to check whether the outcome, latency, and body actually stay consistent.
Compare
A structural diff between two requests that reads back what actually changed in plain language — "Remove Authentication," "Add Delay" — instead of a raw field list, plus a narrow, evidence-backed read, always hedged, never a guess, on whether your change explains the result.
Collections & Assertions
Chain requests together with variables and secrets, and attach assertions — status code, duration, response size, header, body content, or JSON path — that run automatically every time the Collection executes, so a regression doesn't slip by quietly.
Automate
Query and script against captured traffic yourself, entirely on-device, for the searches a fixed UI can't anticipate.
JavaScript Scripting
Write JavaScript against captured traffic through the Hollowport namespace — flows, headers, bodies, timing, gRPC and GraphQL fields — to search, filter, and summarize a capture in ways the built-in views don't.
29 Starter Templates
Ready-made scripts for the searches people actually reach for: failed and slow requests, repeated calls, JWTs and API keys, GraphQL errors, and more — duplicate one and adapt it instead of starting from a blank editor.
require() and Reusable Modules
Pull in a built-in helper — crypto, base64/hex encoding, JWT decoding, UUIDs, diffing — or one of your own saved scripts marked as a module, so common logic doesn't get copy-pasted between scripts.
On-Device, Read-Only
Scripts run against a snapshot of already-captured data with no network access, no filesystem access, and no way to modify live traffic — enforced by the runtime and covered by its own test suite, not just documented.
Control
Intervene in live traffic on purpose — pause it, automate a change, replace a response, or simulate a bad network — so you can test a hypothesis against real traffic instead of guessing how your app would behave. The four scale up in scope: a Breakpoint handles one request by hand, Rules and Mocking repeat a targeted change automatically, and Chaos tests resilience broadly.
Breakpoints
Pause a live request — or its response — on a matching host before it's delivered. Edit a request's method, path, query parameters, headers, or body; edit a response's status, headers, or body. Then forward it as edited, reset it back to exactly what was captured, or abort the exchange outright.
Rules
The same interventions, automated and repeatable — redirect, block, throttle, mock, or rewrite headers, matched by wildcard or full regex, applied every time without you tapping through it live.
Mocking
Replace a real response with one you control — a specific status, headers, and body — to test how your app behaves against a server state you can't otherwise produce on demand, like a 500 from a backend that's actually healthy. One tap turns any captured response into a starting point: Create Mock Rule from its detail view, then adjust exactly what comes back.
Network Chaos
One-tap presets — Poor Network, Offline API, Slow Backend, Server Errors, Auth Failure — for resilience testing without hand-building a Rule each time.
Export
Take a request, or a whole capture, out of Hollowport in the format you need next.
HAR Export
Export a full capture as a standard HTTP Archive, readable by browser dev tools and other proxy tools.
Copy as Code
Generate a ready-to-run cURL command or client-code snippet directly from a captured request.
Redaction
Credentials and personal data are stripped by default on every export and share — on unless you explicitly need the raw values.
Want the step-by-step on any of this?
Browse the Help center