The questions worth asking first.

Answers for apiaxess v0.1.0.

Why is the installer so large?

The 456 MB Windows installer and the 298 MB Linux package carry the app plus its own Chromium for web capture and ffuf for fast fuzzing, so web capture needs nothing else. The two heavy parts are add-ons you download from inside the app when you need them: the analysis runtime (about 1.2 GB) and the Android target (about 1.3 GB).

Windows SmartScreen warns when I run it. Should it?

Yes. The installers aren’t code-signed yet. Click More info → Run anyway, and verify the SHA-256 checksum on the download page if you want to be sure. The source is public too, so you can build it yourself.

How do I install it from the command line?

Windows: scoop install apiaxess/apiaxess (after adding the bucket). Debian/Ubuntu: sudo apt install ./apiaxess_0.1.0_amd64.deb.

Is there a macOS build?

Not yet. macOS is next, then arm64.

Does it phone home?

No telemetry and no licence call. apiaxess talks to one host, apiaxess.dev, for an optional daily update check that carries no identifiers (switch it off in Settings) and for add-ons you choose to download. apiaxess.dev sits behind Cloudflare, which sees those requests like any website visit. Listeners are loopback by default.

How do updates work?

If you leave the check on, apiaxess looks at apiaxess.dev once a day and tells you when a new version is out. On the MSI, Update downloads it, verifies the SHA-256 and upgrades in place; Scoop, Chocolatey and apt users get their one-line command instead. Switch the check off in Settings or with APIAXESS_UPDATE_CHECK=0.

Do I need an account?

No. No account, cloud workspace, sync or licence key.

How is this different from Burp or Caido?

Mobile: point it at an APK or the Android target and traffic arrives, with the certificate trusted and pinning handled. And Intruder-class fuzzing is free and unthrottled.

What does it actually capture?

HTTP/1.1, HTTP/2, WebSocket, Server-Sent Events, gRPC-Web and GraphQL, live. gRPC-Web operations are included in exports. APK analysis also recovers gRPC and GraphQL operations straight from the code.

Is it really free?

Yes, and open source under Apache-2.0. No paid tier, no seat count, nothing held back.

Can I run it on a server?

Yes, headless on a Linux host. Both listeners bind to loopback by default; read the headless guide before binding to anything routable.

Where does my session data live?

In a local SQLite file, plus your exports. Scratch space is deleted after each run. Nothing is uploaded.

The docs go further.

The quickstart gets you to a first captured flow, the trust model covers what apiaxess touches, and the CLI reference lists every flag.

Point it at an app. Read the API.