Proxino: a self-hosted HTTPS inspector you can point anything at
Why I built an open-source alternative to Proxyman and Charles — live HTTPS capture, in-flight breakpoints, and gRPC/Protobuf decoding, bundled into one native app with nothing to install.
"What is this app actually sending over the wire?" Whether it's a phone, a desktop app, a browser, or a background script, that stays a surprisingly hard question to answer — and the tools that answer it well tend to be paid and closed.
So I built an open one. Proxino is a free, MIT-licensed, self-hosted inspector for HTTP/HTTPS traffic from any client — a no-account, no-license-key alternative to Proxyman and Charles. Nothing leaves your machine.
Point anything at it
Run Proxino, set a client's proxy to it, trust its CA certificate once (there's a connect-device wizard with a QR code to make that painless), and you're watching traffic live — decrypted, grouped per client, ready to replay. It works the same against production traffic and in local development.
# point any client at Proxino's proxy (default :8080)
export HTTPS_PROXY=http://localhost:8080
An iOS or Android device, an emulator, a browser, a CLI, or the machine it runs on — each shows up as its own group, auto-named from its User-Agent.
What it gives you
- Live capture with a real filter language, per-client grouping, and a timing waterfall. The filter DSL reads the way you'd hope:
status:>=400 host:*.example.com path:/v2/*. - Breakpoints — pause a request or a response in flight, edit the headers, body or status, then continue or drop it.
- Replay and edit-and-resend without touching the app that made the call — plus copy-as-cURL and HAR export.
- Beyond REST — inspect WebSocket frames live and decode gRPC, Protobuf and MsgPack bodies.
Two design decisions I'm happy with
A breakpoint tool is only useful if it never becomes a liability. Two rules keep Proxino out of its own way:
- Nothing pauses unless someone is watching. If no UI client is connected, breakpoints don't fire — so a forgotten rule can't silently stall traffic.
- A paused flow auto-continues after 60 seconds. Even with the inspector open, a rule can never strand a client indefinitely.
The other one is about not breaking things it can't inspect. Certificate-pinned apps (think Instagram, the App Store) refuse a proxy's certificate by design. Rather than failing loudly, Proxino auto-detects pinning after two refused handshakes and forwards that host encrypted (passthrough) — so those apps keep working while everything else stays inspectable.
Under the hood
Proxino is designed and shipped end to end, and it owns the interesting parts — the passthrough logic, the in-flight breakpoints, and the live protocol decoding — while leaning on mitmproxy for the TLS core underneath.
- A FastAPI service streams every flow to the browser over WebSocket.
- A React + TypeScript app (Vite, Zustand) renders the inspector — the flow list, the filter parser, the response viewers.
- The whole thing, Python backend included, is bundled with Rust (Tauri) into one self-contained native app for macOS, Windows and Linux. There's nothing for the user to install — no Python, no Node, no setup.
That last point mattered most to me. A developer tool that needs its own ten-minute setup before it earns its keep usually doesn't get used. Shipping the interception engine, the API, and the UI as a single double-clickable binary is what turns "I should inspect that" into something you actually do.
Try it
It's free and open source. No account, nothing phones home.
- Live site: anthibo.github.io/proxino
- Source (MIT): github.com/anthibo/proxino
I'd genuinely like to hear how you inspect traffic today — and what Proxino is missing.

Senior backend engineer writing about distributed systems and applied AI. Get in touch →