Request and response
Method, URL, headers, status, timing; decoded for display only.
httpmon · Go CLI
Wrap a proxy-aware command. Read its traffic live. Response unchanged.
Host: proxy.golang.org · Accept: */* · User-Agent: curl/8.5.0
Content-Type: text/plain; charset=UTF-8 · Content-Length: 91
v1.3.0 v1.0.2 v1.0.0 v1.1.1 v1.4.1 … Method, URL, headers, status, timing; decoded for display only.
The command gets its response unchanged.
Trailers carried through; gRPC status decoded.
A local MITM proxy gives its address and a temporary CA to one child process.
Put httpmon before a proxy-aware command. It listens on 127.0.0.1 only; no system proxy changes.
Proxy address and ephemeral CA live in that command’s environment.
NDJSON, HAR 1.2, or a recording, to replay or share.
Sep 29, 2026
--record and --harContent-Length is no longer marked truncated just because the cons…Requires Go 1.24+. Pre-built binaries are on the Releases page.
Install
go install github.com/hxddh/https-traffic-inspector@latest Wrap a command and watch its traffic
httpmon curl https://api.github.com/users/octocat curl, aws, Python, Node, or any other proxy-aware command. Only that child process gets the proxy address and temporary CA; your system proxy and global network settings stay as they are. Go programs skip the proxy for loopback targets, Node’s built-in fetch needs Node 22.21 or 24, and JVM tools are not configured automatically.
Yes. HTTPS is decrypted locally. HTTP/2 is negotiated with the command and the upstream separately; gRPC calls show their status from the trailers, and their bodies are summarised, not decoded. For wss:// and ws:// the upgrade handshake is logged, then frames are spliced in both directions.
Yes. Headers, cookies, query parameters, and response bodies may contain credentials or business data. Capture and replay only in authorized environments, and handle NDJSON, HAR, and recording files as sensitive logs.
When those logs and traces are already in a Pi chat, diagnose them with StorageOps.
httpmon