An interception tool should be able to account for itself.

Exactly what apiaxess holds, changes and sends — and the source to confirm it.

Generated per session, kept in memory, never installed for you.

Each session mints its own CA with a fresh key pair. The signing key is never written to disk or added to your system trust store, and it is gone when the session ends.

Scope
One CA per session, not one per install
Storage
In memory, for the life of the process
Subject
APIaxess ephemeral interception CA
Verification
Fingerprint printed at startup and served locally, for out-of-band checks during pairing

What leaves the machine, and when.

No telemetry and no licence call. apiaxess talks to one host, apiaxess.dev, for an optional daily update check that carries no identifiers, and for add-ons you choose to download. apiaxess.dev sits behind Cloudflare, which sees those requests like any website visit.

Updates
Optional. Once a day (and at startup), a plain request for apiaxess.dev/releases/latest.json with no identifiers; the version comparison happens on your machine. Switch it off in Settings or with APIAXESS_UPDATE_CHECK=0. The MSI upgrades in place; Scoop, Chocolatey and apt users get their one-line command instead. Every download is checked against its SHA-256 before it installs
Update signing
Signing for the update feed (ed25519) is built but not switched on at launch. Until it is, the checksums come from the same server as the files, so a compromised apiaxess.dev could serve a malicious build with matching hashes. We say so rather than hide it
Add-ons
The analysis runtime (about 1.2 GB) and the Android target (about 1.3 GB) aren’t in the installer. Each downloads from apiaxess.dev/assets/ only when you click to get it, installs for your user only, resumes if interrupted, and is checked against its SHA-256. Pre-downloaded or air-gapped? Point APIAXESS_ANDROID_TARGET at your copy
Cloudflare
apiaxess.dev is served through Cloudflare, a CDN, so Cloudflare sees those requests: your IP address, User-Agent and timing, as with any website you visit. They carry no APIaxess identifiers
Nowhere else
No other hosts. apiaxess never falls back to a mirror you didn’t choose
Windows installer only
Microsoft’s WebView2 runtime, if your machine doesn’t already have it
Telemetry
None. No analytics, no licence call, no usage reporting
Listeners
127.0.0.1:7777 and 127.0.0.1:8080, loopback by default
The one deliberate exception
serve --host can bind the workbench to a routable address — the one way the local-only default stops being true. See running it headless.

What is touched, and what is not.

Web capture: nothing
A launch flag on a throwaway profile. Nothing added to your OS or everyday browser.
Android target: the emulator, not you
The session CA goes into the disposable emulator’s system store. Your host’s is never modified.
On disk
A local SQLite session file and your exports. Scratch space is removed after each run; leftovers over a day old are swept.

Who can talk to the workbench.

Boundary
Loopback first — reached from the machine it runs on
Sockets
Origin and token checked before upgrading
Operator routes
Pairing and Android-target actions require the operator token on every call
Devices
A paired device gets its own token, separate from the operator’s
Session token
32 random bytes, generated per session and never written to disk

You do not have to take any of this on faith.

Apache-2.0 licensed. The certificate generation, proxy, scope model and export pipeline are all readable, and you can build the binary yourself.

The rules we hold ourselves to.

Name the protocol, not the buzzword
Live capture is HTTP/1.1, HTTP/2, WebSocket, SSE, gRPC-Web and GraphQL. New protocols get listed here when they ship.
Say where the data goes
One host, for updates you can switch off and add-ons you ask for. Any new outbound call is added to the list above before it ships.
Say what we change
Nothing on your host for web capture; the emulator’s trust store for Android.
Version every promise
This site describes v0.1.0. Anything ahead is labelled as next.

Point it at an app. Read the API.