v0.1.0 — the first build.
What this build does, and what is next.
What ships.
- Web capture
- Bundled, disposable Chromium through the local proxy, recording HTTP/1.1, HTTP/2, WebSocket, SSE, gRPC-Web and GraphQL
- Android
- Headless Android 13 target with the session CA in its system store and pinning handled. Drive it in the browser; its traffic is captured automatically. Rooted-device pairing from Android 7.0
- APK analysis
- APK, split APK and XAPK via apktool and jadx — base URLs, endpoints, gRPC and GraphQL operations
- Scope
- Labels every flow in scope, outside scope or undetermined; never blocks
- Workbench
- Live queue, request and response detail
- Intercept
- Hold, modify, forward or drop live requests
- Resend
- Byte-faithful raw editor, Pretty/Hex, history with restore, copy as curl
- Fuzz
- Four attack types, 17 payload types, grep-match and grep-extract, and pause and resume
- Discovery
- Subdomain and directory discovery (ffuf, bundled wordlists), with a request-count estimate and live progress
- Export
- OpenAPI 3.1, Postman v2.1, HAR 1.2 and a Python client, with per-fact provenance
- Import
- HAR, labelled against scope as it comes in
- Packaging
- Windows x64 .msi and portable zip · Debian/Ubuntu amd64 .deb · Scoop · SHA-256 checksums for every build
- License
- Apache-2.0, with LICENSE and NOTICE in every package
- Updates
- Daily check against apiaxess.dev, in-app notice, verified install (never mid-session); switch it off anytime
- Downloads
- Everything the app fetches comes from apiaxess.dev, hash-verified
What is coming.
None of this is in v0.1.0.
- macOS
- Next release
- Chocolatey
- Once approved
- Signing
- Signed installers, so SmartScreen stops warning
- arm64
- Apple Silicon and ARM Linux builds
How releases are recorded from here.
New builds are added here, each saying what changed and what it means for a session in progress.