Sometimes you just need to call an API from your phone. You might want to check an endpoint while away from your desk, try a request a colleague sent as a cURL command, or repeat a request you just captured with one value changed. The Requests tab in HTTPS Capture is a small API client, like Postman, built into the same app you use for capturing.
Build a request
- Open the Requests tab and tap New Request.
- Choose the method (GET, POST, PUT, PATCH, DELETE…) and enter the URL.
- Add parameters. They are URL-encoded and appended to the URL when the request is sent.
- Add headers.
Host,Content-Lengthand connection headers are handled for you. - Set Auth to Basic (username and password) or Bearer (token).
- Choose a body: None, Raw, JSON (with a Format JSON button), URL Encoded, or Multipart Form Data.
- Tap Send.
The response shows the status code, timing, headers and a body preview with JSON highlighting. Each send is stored in that request’s history, so you can look back at earlier responses.
Import a cURL command
Someone shared curl -X POST https://api.example.com/items -H "Authorization: Bearer …" -d '{"name":"test"}'? Copy it, then on the Requests tab choose Import from cURL and tap Paste from Clipboard. HTTPS Capture parses the command on the device and fills in the method, URL, headers and body for you to review before saving or sending.
The reverse works too: Copy as cURL turns any saved request into a command you can paste into a terminal.
Resend a captured request
This is where capture and API testing come together. In a capture session, touch and hold any request:
- Resend: send it again exactly as captured.
- Edit & Send: open it as an editable request on the Requests tab, change a header, parameter or body field, and send it.
You can do the same from the request detail menu. It’s the fastest way to answer “what happens if I change this one value?”
Organize your requests
- Search by name, method, host or URL, and sort the list.
- Swipe right on a request to resend it. Touch and hold to Duplicate, Copy as cURL or Delete.
- Give requests clear names. Unnamed requests are labeled from their URL path.
Run requests from Shortcuts
Saved requests appear in the Shortcuts app as a Send Request action. It returns the status code, headers, body, MIME type and duration. You can build automations such as “every morning, call the health-check endpoint and notify me if it’s not 200”.
JavaScript requests
For flows that need several steps, such as logging in first and then calling an API with the returned token, you can write a request as a short JavaScript script with await fetch(url, { method, headers, body }). Use env.get() / env.set() to keep values like tokens between runs, and console.log() to debug. Script requests run inside the app.
Related: compare two captured requests · decode a JWT token
Ready to try it?
HTTPS Capture · Capture and decrypt HTTPS traffic on iPhone
Free on the App Store