A throwaway browser, already routed through the proxy.
Name the site you're allowed to test and start. Every request lands in the session.
Start a capture
From nothing to live traffic.
apiaxess
Go to surface, flow, endpoint or command⌘K
api.northwind-retail.ioLive control connected
Input · web domain
Web capture
Declare the target and your authorization, capture live traffic through the bundled browser, and see what was actually observed in an API surface.
Launch browser
TargetNOT STARTED
Web target
https://northwind-retail.io
Tick the authorization to start.
Active discoveryIDLE
Discovery typeDirectories / pathsWordlistSecLists common.txt · 4,751
Found paths land in the same session.
Intercept queue 0Diagnostics 0Control · reliable
No paused requestsWith intercept on, matching requests pause here until you forward, modify or drop them.
WEB CAPTUREsession:2l1a434f3f6b1aControlTelemetry127.0.0.1
The site you are allowed to test. Its domain becomes your declared scope.
Read what it recorded
Every request the page made, labelled against your scope.
apiaxess
Go to surface, flow, endpoint or command⌘K
api.northwind-retail.ioLive control connected
MethodPathStMsSize
POST/v1/cart/items201
- host
- api.northwind-retail.io
- client
- Web capture
- scope
- In declared scope
- authorization
- Bearer eyJhbGciOi…Qm9
- content-type
- application/json
Intercept queue 0Diagnostics 0Control · reliable
No paused requestsWith intercept on, matching requests pause here until you forward, modify or drop them.
WORKBENCHsession:2l1a434f3f6b1aControlTelemetry127.0.0.1
HTTP/1.1, HTTP/2, WebSocket, SSE, gRPC-Web and GraphQL, in the order the page made them, with the response attached.
The details
- Profile
- A fresh Chromium profile per launch, deleted when the capture stops
- Certificate
- Trusted by the capture browser only, never your system store. How the CA works
- Recorded
- HTTP/1.1 and HTTP/2 requests in full; WebSocket frames in their own tab; SSE as a stream of events; gRPC-Web and GraphQL as named operations
- Not intercepted
- gRPC over cleartext HTTP/2 inside a CONNECT tunnel isn’t intercepted
- Imported
- HAR files, labelled against scope on import
$ apiaxess web northwind-retail.io --authorize --output ./session.json
--authorize affirms you have permission to test the target, and is required.