AK
All writing
September 20266 min read

Proxino: a self-hosted HTTPS inspector you can point anything at

Why I built an open-source alternative to Proxyman and Charles — live HTTPS capture, in-flight breakpoints, and gRPC/Protobuf decoding, bundled into one native app with nothing to install.

HTTPSflowsstreamliveClientphone · browser · scriptmitmproxy :8080TLS decryptProxino addonstore · passthroughbreakpoints · ws framesFastAPI :8081REST + WebSocketReact web UI127.0.0.1:8081~/.proxino/config.jsonlabels · rules · hostsHow Proxino sees a requestdecrypt · capture · stream live to the UI

"What is this app actually sending over the wire?" Whether it's a phone, a desktop app, a browser, or a background script, that stays a surprisingly hard question to answer — and the tools that answer it well tend to be paid and closed.

So I built an open one. Proxino is a free, MIT-licensed, self-hosted inspector for HTTP/HTTPS traffic from any client — a no-account, no-license-key alternative to Proxyman and Charles. Nothing leaves your machine.

Point anything at it

Run Proxino, set a client's proxy to it, trust its CA certificate once (there's a connect-device wizard with a QR code to make that painless), and you're watching traffic live — decrypted, grouped per client, ready to replay. It works the same against production traffic and in local development.

# point any client at Proxino's proxy (default :8080)
export HTTPS_PROXY=http://localhost:8080

An iOS or Android device, an emulator, a browser, a CLI, or the machine it runs on — each shows up as its own group, auto-named from its User-Agent.

What it gives you

  • Live capture with a real filter language, per-client grouping, and a timing waterfall. The filter DSL reads the way you'd hope: status:>=400 host:*.example.com path:/v2/*.
  • Breakpoints — pause a request or a response in flight, edit the headers, body or status, then continue or drop it.
  • Replay and edit-and-resend without touching the app that made the call — plus copy-as-cURL and HAR export.
  • Beyond REST — inspect WebSocket frames live and decode gRPC, Protobuf and MsgPack bodies.

Two design decisions I'm happy with

A breakpoint tool is only useful if it never becomes a liability. Two rules keep Proxino out of its own way:

  • Nothing pauses unless someone is watching. If no UI client is connected, breakpoints don't fire — so a forgotten rule can't silently stall traffic.
  • A paused flow auto-continues after 60 seconds. Even with the inspector open, a rule can never strand a client indefinitely.

The other one is about not breaking things it can't inspect. Certificate-pinned apps (think Instagram, the App Store) refuse a proxy's certificate by design. Rather than failing loudly, Proxino auto-detects pinning after two refused handshakes and forwards that host encrypted (passthrough) — so those apps keep working while everything else stays inspectable.

Under the hood

Proxino is designed and shipped end to end, and it owns the interesting parts — the passthrough logic, the in-flight breakpoints, and the live protocol decoding — while leaning on mitmproxy for the TLS core underneath.

  • A FastAPI service streams every flow to the browser over WebSocket.
  • A React + TypeScript app (Vite, Zustand) renders the inspector — the flow list, the filter parser, the response viewers.
  • The whole thing, Python backend included, is bundled with Rust (Tauri) into one self-contained native app for macOS, Windows and Linux. There's nothing for the user to install — no Python, no Node, no setup.

That last point mattered most to me. A developer tool that needs its own ten-minute setup before it earns its keep usually doesn't get used. Shipping the interception engine, the API, and the UI as a single double-clickable binary is what turns "I should inspect that" into something you actually do.

Try it

It's free and open source. No account, nothing phones home.

I'd genuinely like to hear how you inspect traffic today — and what Proxino is missing.

Abdulrahman Khalid
Abdulrahman Khalid

Senior backend engineer writing about distributed systems and applied AI. Get in touch →