httpmon · Go CLI

See the HTTP traffic.

Wrap a proxy-aware command. Read its traffic live. Response unchanged.

GoMIT v1.4.1 (Sep 29, 2026) local proxyHTTP / HTTPS / HTTP/2 / gRPC / WebSocketNDJSON / HAR

httpmon v1.4.1 · captured output captured
$ httpmon curl -sS https://proxy.golang.org/github.com/hxddh/https-traffic-inspector/@v/list
REQUEST #1 GET https://proxy.golang.org:443/github.com/hxddh/https-traffic-inspector/@v/list

Host: proxy.golang.org · Accept: */* · User-Agent: curl/8.5.0

RESPONSE #1 HTTP/2.0 200 OK (3.21s)

Content-Type: text/plain; charset=UTF-8 · Content-Length: 91

v1.3.0 v1.0.2 v1.0.0 v1.1.1 v1.4.1 …
local HTTPS inspectionoriginal response stream stays with the command

The traffic, beside the command.

Request and response

Method, URL, headers, status, timing; decoded for display only.

Original stream

The command gets its response unchanged.

HTTP/2 and gRPC

Trailers carried through; gRPC status decoded.

Only the wrapped process is configured.

A local MITM proxy gives its address and a temporary CA to one child process.

  1. 1

    Start locally

    Put httpmon before a proxy-aware command. It listens on 127.0.0.1 only; no system proxy changes.

  2. 2

    Configure one child

    Proxy address and ephemeral CA live in that command’s environment.

  3. 3

    Save when needed

    NDJSON, HAR 1.2, or a recording, to replay or share.

Sep 29, 2026

What’s new in v1.4.1.

  • An exchange could vanish from the output, --record and --har
  • A body that delivered its whole declared Content-Length is no longer marked truncated just because the cons…
  • On exit, httpmon waits (up to 3s) for exchanges still being relayed, so the wrapped command's last request is…

Get started

Requires Go 1.24+. Pre-built binaries are on the Releases page.

  1. Install

    go install github.com/hxddh/https-traffic-inspector@latest
  2. Wrap a command and watch its traffic

    httpmon curl https://api.github.com/users/octocat

FAQ

Which commands can it wrap?

curl, aws, Python, Node, or any other proxy-aware command. Only that child process gets the proxy address and temporary CA; your system proxy and global network settings stay as they are. Go programs skip the proxy for loopback targets, Node’s built-in fetch needs Node 22.21 or 24, and JVM tools are not configured automatically.

Does it handle HTTPS, HTTP/2, and WebSocket?

Yes. HTTPS is decrypted locally. HTTP/2 is negotiated with the command and the upstream separately; gRPC calls show their status from the trailers, and their bodies are summarised, not decoded. For wss:// and ws:// the upgrade handshake is logged, then frames are spliced in both directions.

Can recordings hold secrets?

Yes. Headers, cookies, query parameters, and response bodies may contain credentials or business data. Capture and replay only in authorized environments, and handle NDJSON, HAR, and recording files as sensitive logs.

What if the logs are already in Pi?

When those logs and traces are already in a Pi chat, diagnose them with StorageOps.

httpmon