The request list
Capture shows requests as they happen, most recent at the top: method, host and path, status code, and duration. Successful responses are colored distinctly from errors, so a scan down the list tells you where to look before you tap anything.
Search and filter
Use the search field to narrow the list by host, path, or method. Search matches what's actually retained — see the note on retention below for what that means during a very long capture.
Opening a request
Tap any row for the full detail view: request and response headers in order, a pretty-printed and collapsible JSON tree for structured bodies, and automatic decoding for GraphQL operations and gRPC/protobuf payloads. From here you can also jump straight to Replay, export, or Explain with AI for a plain-language read on a confusing response.
Pinned and unreadable traffic
Certificate-pinned traffic — banking apps, and Apple's own push notifications and iCloud Private Relay — shows up in the list at the connection level (host, timing, that it happened) but the body stays unreadable. That's a platform limitation every interception tool shares, not something Hollowport can bypass. It's labeled distinctly from an ordinary decryption problem so you're not left wondering whether your certificate setup is broken. See Capabilities & Limitations for how this compares to HTTP/3, DNS-over-HTTPS, and DNS-over-TLS.
Retention on long captures
Hollowport keeps a bounded, recent window of full request detail in memory for responsiveness, rather than holding an unlimited capture. On a very long session, older bodies may be released while metadata for the request — that it happened, when, and its outcome — is kept. If you need to guarantee nothing is lost during a long test, export as you go — see Exporting Data.