Five parts, one session.

Capture a website or an Android app, work the traffic, and leave with a spec.

The whole thing, in five stops

Each stop is the real app. Click through, or let it play.

apiaxess
FileCaptureViewHelp
Go to surface, flow, endpoint or command⌘K
api.northwind-retail.ioLive control connected
Input · web domain

Web capture

Declare the target and your authorization, capture live traffic through the bundled browser, and see what was actually observed in an API surface.

Launch browser
TargetNOT STARTED
Web target
https://northwind-retail.io
Tick the authorization to start.
Active discoveryIDLE
Discovery typeDirectories / pathsWordlistSecLists common.txt · 4,751
Found paths land in the same session.
Intercept queue 0Diagnostics 0Control · reliable
No paused requestsWith intercept on, matching requests pause here until you forward, modify or drop them.
WEB CAPTUREsession:2l1a434f3f6b1aControlTelemetry127.0.0.1
  1. A throwaway Chromium, already routed through the proxy. Name the target and start.

    See this part →

Go deeper

What you are installing

Listens
127.0.0.1:7777 workbench · 127.0.0.1:8080 proxy
In the box
Its own Chromium for web capture, and ffuf for fast fuzzing
Add-ons
The analysis runtime (about 1.2 GB) and the Android target (about 1.3 GB), downloaded in the app when you click to get them
Stores
A local SQLite session file, plus your exports
License
Apache-2.0

Point it at an app. Read the API.