Traffic at a glance

A desktop HTTP/HTTPS proxy for debugging your own APIs, web sites, and mobile apps.

Built for developers, QA, and security teams.

An alternative to Charles Proxy, Fiddler, and Proxyman. Free during beta.

See requests from your own app, browser, or test device

Inspect HTTP and HTTPS after you install your own local certificate

Modify responses to test your own app without changing its code

See for yourselftap to explore

Capturing
192.168.1.1:7070
api.anyflow.io
tasks.taskit.dev

2
Anyflow2
Taskit1

1
telemetry.example.net
Method5 selected
Status3 selected
Schemehttps
Host
Path
#
Method
Status
URL
Time
7
DELETE
204
https://api.anyflow.io/api/v2/photos/1201
14:32:05.712
9ms
6
GET
304
https://cdn.anyflow.io/assets/logo-dark.svg
14:32:05.203
2ms
5
POST
201
https://api.anyflow.io/api/v2/photos/upload
14:32:04.089
142ms
4
PUT
403
https://tasks.taskit.dev/api/tasks/97/assign
14:32:03.551
31ms
3
GET
200
https://api.anyflow.io/api/v2/photos?page=1&limit=20
14:32:02.014
14ms
2
PATCH
200
https://tasks.taskit.dev/api/tasks/42/status
14:32:01.340
18ms
1
GET
200
https://telemetry.example.net/v1/collect?event=page_view
14:32:01.127
54ms
No flow selected
Select a flow from the list to inspect
See for yourselfSee for yourself

Benefits

Debug faster

Find why a login fails, why CORS breaks, or why a request takes 8 seconds. See headers, cookies, query params, and responses

Easier testing

Test your app or website with different data. Switch endpoints, substitute response content and status codes

Easier analysis

Catch hidden redirects and unexpected third-party requests without reverse engineering

Features

HTTPS Decryption

Inspect your own encrypted traffic by installing a local root certificate:

  • You install the certificate yourself — Solpuga never installs it silently
  • Without an installed certificate, HTTPS is not decrypted
  • You can remove the certificate at any time
Solpuga CA
Issued01/15/2026Expires01/15/2028

Capture traffic from phones and tablets

Connect your own iPhone/Android device or an emulator you develop and test on:

  • Inspect API calls from your own apps
  • Debug WebViews and in-app browsers
  • The proxy is set manually on the device, and certificate trust is confirmed there when needed
  • No root or jailbreak required — just a Wi-Fi proxy

Two-level filtering

Focus on what matters

  • Technical: filter by host, status, or method, and pin important requests
  • Visual: key elements are highlighted in different colors for easier interface navigation

Network response mocking

Create rules that intercept requests by URL and apply changes on the fly:

  • Redirect to a different host
  • Modify headers or payloads
  • Return a mocked response instantly

Breakpoints

Pause a request before it reaches the server or a response before it returns to the client. Inspect and edit on the fly:

  • Edit URL, method, headers, or body
  • Set conditional breakpoints by host, path, or status code
  • Step through requests one at a time to reproduce tricky bugs

One proxy. Three platforms.

Supports Apple Silicon, Windows 10/11, and Ubuntu via AppImage

Works anywhere you can set an HTTP proxy
macOS
Windows
Linux

Your traffic stays on your machine.

Session and rules are stored locally. No cloud sync. No analytics on your traffic data

FAQ

What is Solpuga?
Solpuga is a desktop HTTP and HTTPS debugging proxy for macOS, Windows, and Ubuntu. It lets developers, QA engineers, and testing specialists inspect and modify network traffic from their own browsers, mobile apps, and devices they have lawful access to.
Is Solpuga free?
Solpuga is free during the beta period. Download it for macOS, Windows, or Ubuntu and start debugging right away — no account or license key required.
Does it work with HTTPS?
Yes. You can inspect HTTPS traffic by installing a local root certificate for MITM decryption. This is entirely optional — you decide which traffic to decrypt, and you can remove the certificate at any time.
Is it safe?
The proxy runs locally on your machine: captured data stays on your device and nothing is sent to external servers. HTTPS is decrypted only after you install a local certificate yourself; you decide which traffic to decrypt, and you can remove the certificate at any time. You remain responsible for whose traffic you debug.
What must Solpuga not be used for?
Solpuga is a tool for debugging your own systems. It must not be used to intercept the traffic of third parties without their consent, to bypass protection on services that are not yours, to covertly monitor other people’s devices, or to reach resources restricted by the law of the Russian Federation.
Who may use Solpuga?
The owner of the computer, on their own machine; an employee, within their employer’s policy; a contractor, under an agreement to test a specific system. In every case you must have lawful access to the system whose traffic you debug.
Can I use it with iOS / Android devices?
Yes. Point your device's Wi-Fi proxy setting to Solpuga's address, then install and trust the Solpuga root certificate on the device. On Android, you can also configure a proxy over USB. Steps vary by OS version.
What protocols does Solpuga support?
Solpuga supports HTTP/1.1 and HTTPS. It can intercept both plaintext and encrypted traffic, giving you full visibility into request and response headers, bodies, and timing. Server-Sent Events (text/event-stream) are supported as well: streaming responses are captured and shown event by event as they arrive, so you can debug SSE-based APIs without waiting for the connection to close.
Can I use Solpuga for API testing?
Yes. You can intercept live API requests, inspect their headers and payloads, modify responses on the fly, and return mocked data — all without changing your application code.

Have questions or
suggestions?

Reach out — we'd love to hear from you.

Product RadarProduct RadarSolpuga - HTTP Traffic, Fully Visible. | Product HuntSolpuga - HTTP Traffic, Fully Visible. | Product Hunt