An interception tool should be able to account for itself.
Exactly what apiaxess holds, changes and sends — and the source to confirm it.
Generated per session, kept in memory, never installed for you.
Each session mints its own CA with a fresh key pair. The signing key is never written to disk or added to your system trust store, and it is gone when the session ends.
- Scope
- One CA per session, not one per install
- Storage
- In memory, for the life of the process
- Subject
APIaxess ephemeral interception CA- Verification
- Fingerprint printed at startup and served locally, for out-of-band checks during pairing
What leaves the machine, and when.
No telemetry and no licence call. apiaxess talks to one host, apiaxess.dev, for an optional daily update check that carries no identifiers, and for add-ons you choose to download. apiaxess.dev sits behind Cloudflare, which sees those requests like any website visit.
- Updates
- Optional. Once a day (and at startup), a plain request for
apiaxess.dev/releases/latest.jsonwith no identifiers; the version comparison happens on your machine. Switch it off in Settings or withAPIAXESS_UPDATE_CHECK=0. The MSI upgrades in place; Scoop, Chocolatey and apt users get their one-line command instead. Every download is checked against its SHA-256 before it installs - Update signing
- Signing for the update feed (ed25519) is built but not switched on at launch. Until it is, the checksums come from the same server as the files, so a compromised apiaxess.dev could serve a malicious build with matching hashes. We say so rather than hide it
- Add-ons
- The analysis runtime (about 1.2 GB) and the Android target (about 1.3 GB) aren’t in the installer. Each downloads from
apiaxess.dev/assets/only when you click to get it, installs for your user only, resumes if interrupted, and is checked against its SHA-256. Pre-downloaded or air-gapped? PointAPIAXESS_ANDROID_TARGETat your copy - Cloudflare
- apiaxess.dev is served through Cloudflare, a CDN, so Cloudflare sees those requests: your IP address, User-Agent and timing, as with any website you visit. They carry no APIaxess identifiers
- Nowhere else
- No other hosts. apiaxess never falls back to a mirror you didn’t choose
- Windows installer only
- Microsoft’s WebView2 runtime, if your machine doesn’t already have it
- Telemetry
- None. No analytics, no licence call, no usage reporting
- Listeners
127.0.0.1:7777and127.0.0.1:8080, loopback by default
The one deliberate exception
serve --host can bind the workbench to a routable address — the one way the local-only default stops being true. See running it headless.What is touched, and what is not.
Web capture: nothing
A launch flag on a throwaway profile. Nothing added to your OS or everyday browser.
Android target: the emulator, not you
The session CA goes into the disposable emulator’s system store. Your host’s is never modified.
On disk
A local SQLite session file and your exports. Scratch space is removed after each run; leftovers over a day old are swept.
Who can talk to the workbench.
- Boundary
- Loopback first — reached from the machine it runs on
- Sockets
- Origin and token checked before upgrading
- Operator routes
- Pairing and Android-target actions require the operator token on every call
- Devices
- A paired device gets its own token, separate from the operator’s
- Session token
- 32 random bytes, generated per session and never written to disk
You do not have to take any of this on faith.
Apache-2.0 licensed. The certificate generation, proxy, scope model and export pipeline are all readable, and you can build the binary yourself.
The rules we hold ourselves to.
Name the protocol, not the buzzword
Live capture is HTTP/1.1, HTTP/2, WebSocket, SSE, gRPC-Web and GraphQL. New protocols get listed here when they ship.
Say where the data goes
One host, for updates you can switch off and add-ons you ask for. Any new outbound call is added to the list above before it ships.
Say what we change
Nothing on your host for web capture; the emulator’s trust store for Android.
Version every promise
This site describes v0.1.0. Anything ahead is labelled as next.