You decrypted HTTPS, but the response body is still unreadable binary. That usually means the app adds its own encryption layer, often AES, inside the HTTPS connection. If you are debugging your own app or a project you are authorized to test, you already have the key. HTTPS Capture can then decrypt those bodies right in the request detail view.
What the AES Cipher feature does
An AES Cipher rule tells HTTPS Capture which URLs carry encrypted bodies and how to decrypt them. When you view a matching request, an AES Decrypt switch appears. Turn it on to see the plaintext.
Decryption only affects what you see. The data sent between the app and the server is not changed.
Step 1: Add an AES rule
- On the Capture tab, tap Rules → AES Cipher.
- Turn on Enable AES Cipher and tap +.
- URL pattern: the API path whose bodies are encrypted. Choose Contains or Regex.
- Apply to: request bodies, response bodies, or both.
- Key length: 128-bit, 192-bit or 256-bit.
- Key: type it as text, or paste binary keys with a
base64:prefix, such asbase64:q83vEjRWeJA=. - Mode: CBC (enter the IV, also plain text or
base64:) or ECB (no IV). - Padding: PKCS7 in almost every case. Choose None only if the data is already a multiple of 16 bytes.
- Save.
Step 2: View the decrypted body
- Open a matching request from the capture list.
- Tap the body under Data to open the full preview.
- Turn on AES Decrypt at the top.
The Preview, Raw and Hex views now show the decrypted data. JSON is formatted automatically. If the result is not valid text, you will see a short note instead. In that case, check the key, IV, mode and padding.
Requirements and limits
- The body must contain the raw encrypted bytes. If an API sends the ciphertext as Base64 text, or puts it inside a JSON field, this rule cannot decode it directly.
- Only AES in CBC or ECB mode is supported. GCM, CTR and other modes are not.
- A key or IV that is too short is padded with zeros, and one that is too long is cut to the selected length. This matches many app implementations, but double-check the key if the output looks wrong.
- The first enabled rule that matches the URL and direction is used.
Responsible use
Only decrypt traffic from apps you build or are explicitly authorized to test. Keys you enter are stored with your rules on the device. Remove rules you no longer need.
Related: inspect WebSocket and Protobuf messages · modify traffic with JavaScript
Ready to try it?
HTTPS Capture · Capture and decrypt HTTPS traffic on iPhone
Free on the App Store