A throwaway browser, already routed through the proxy.

Name the site you're allowed to test and start. Every request lands in the session.

Start a capture

From nothing to live traffic.

apiaxess
FileCaptureViewHelp
Go to surface, flow, endpoint or command⌘K
api.northwind-retail.ioLive control connected
Input · web domain

Web capture

Declare the target and your authorization, capture live traffic through the bundled browser, and see what was actually observed in an API surface.

Launch browser
TargetNOT STARTED
Web target
https://northwind-retail.io
Tick the authorization to start.
Active discoveryIDLE
Discovery typeDirectories / pathsWordlistSecLists common.txt · 4,751
Found paths land in the same session.
Intercept queue 0Diagnostics 0Control · reliable
No paused requestsWith intercept on, matching requests pause here until you forward, modify or drop them.
WEB CAPTUREsession:2l1a434f3f6b1aControlTelemetry127.0.0.1
  1. The site you are allowed to test. Its domain becomes your declared scope.

Read what it recorded

Every request the page made, labelled against your scope.

apiaxess
FileCaptureViewHelp
Go to surface, flow, endpoint or command⌘K
api.northwind-retail.ioLive control connected
Intercept matching requestsAny method Any status filter: host, path, method, status1,204 flows
MethodPathStMsSize
POST/v1/cart/items201
host
api.northwind-retail.io
client
Web capture
scope
In declared scope
authorization
Bearer eyJhbGciOi…Qm9
content-type
application/json
Intercept queue 0Diagnostics 0Control · reliable
No paused requestsWith intercept on, matching requests pause here until you forward, modify or drop them.
WORKBENCHsession:2l1a434f3f6b1aControlTelemetry127.0.0.1
  1. HTTP/1.1, HTTP/2, WebSocket, SSE, gRPC-Web and GraphQL, in the order the page made them, with the response attached.

The details

Profile
A fresh Chromium profile per launch, deleted when the capture stops
Certificate
Trusted by the capture browser only, never your system store. How the CA works
Recorded
HTTP/1.1 and HTTP/2 requests in full; WebSocket frames in their own tab; SSE as a stream of events; gRPC-Web and GraphQL as named operations
Not intercepted
gRPC over cleartext HTTP/2 inside a CONNECT tunnel isn’t intercepted
Imported
HAR files, labelled against scope on import
or from the command line
$ apiaxess web northwind-retail.io --authorize --output ./session.json

--authorize affirms you have permission to test the target, and is required.

Point it at an app. Read the API.