Charles and Fiddler work by running a proxy on a computer and pointing a phone at it. HTTPS Capture can work the other way round: your iPhone becomes the proxy. Another phone, a tablet, a smart TV box or a laptop on the same Wi-Fi sends its traffic through the iPhone, and you inspect it there. That helps when you are away from your desk, or when you want to test an Android build and an iOS build side by side.
Step 1: Turn on LAN Capture on the iPhone
- Open HTTPS Capture. On the Capture tab, turn on LAN Capture (“Proxy for other devices on the same Wi-Fi”).
- Start capture. The LAN proxy runs inside the capture tunnel, so it only listens while capture is running.
- The iPhone’s address appears, for example
192.168.1.23:8082. Tap the row to copy it.
Step 2: Point the other device at the iPhone
Enter the iPhone’s IP address and port as a manual HTTP proxy on the other device:
- Android: Settings → Wi-Fi → long-press or edit the network → Advanced → Proxy: Manual. Enter the host and port.
- iPad / another iPhone: Settings → Wi-Fi → ⓘ → Configure Proxy → Manual.
- macOS: System Settings → Network → Wi-Fi → Details → Proxies. Turn on both Web proxy (HTTP) and Secure web proxy (HTTPS).
- Windows: Settings → Network & internet → Proxy → Manual proxy setup.
Browse on the other device. Its requests now appear in HTTPS Capture next to the iPhone’s own traffic, and the same rules apply to both: Request Map, Rewrite, Breakpoints and Hosts.
Step 3: Decrypt HTTPS from the other device
Plain HTTP works right away. For HTTPS, the other device must trust HTTPS Capture’s CA too:
- On the iPhone, open MitM. Under Certificate Management, tap Export CA Certificate and choose PEM or DER (.cer).
- Send the file to the other device with AirDrop, email or a cloud drive.
- Install it as a trusted root certificate there. On macOS, open it in Keychain Access and set Always Trust. On Windows, import it under Trusted Root Certification Authorities. On Android, install it as a CA certificate in security settings.
Android note: since Android 7, apps only trust user-installed CAs if the app allows it, usually in debug builds. Chrome and your own debug builds will work; most store apps will not decrypt.
Troubleshooting
- Nothing appears: both devices must be on the same Wi-Fi, capture must be running on the iPhone, and some guest or office networks block devices from talking to each other.
- The address changed: if the iPhone joins another network, copy the new address and update the proxy.
- HTTPS shows certificate errors: the other device does not yet trust the exported CA, or you regenerated the CA after exporting it.
- When you stop capture on the iPhone, the LAN proxy stops too. Remove the proxy setting on the other device afterwards, or it will lose internet access.
Ready to try it?
HTTPS Capture · Capture and decrypt HTTPS traffic on iPhone
Free on the App Store