Skip to content

How to Capture HTTPS Traffic on iPhone Without a Computer (No Jailbreak)

A step-by-step guide to sniffing and decrypting HTTP/HTTPS requests directly on iPhone with HTTPS Capture: no Mac, no proxy setup, no jailbreak.

3 min readHTTPS Capture

Want to see exactly which requests an app on your iPhone sends, which servers it talks to, and what comes back? The usual answer is Charles or Fiddler on a computer, a Wi-Fi proxy and a certificate copied over by hand. HTTPS Capture does the whole job on the iPhone itself. It needs no computer and no jailbreak, and the traffic never leaves the device.

How on-device capture works

HTTPS Capture creates a local VPN on the iPhone. Nothing is routed to a remote server: the “VPN” is only a tunnel that lets the app see traffic on the device. A local proxy reads plain HTTP directly. For HTTPS it uses a certificate authority (CA) that you install and trust, so it can decrypt the traffic and show it to you in plaintext.

Captured requests, headers and bodies are stored only on your iPhone.

Step 1: Complete the three setup steps

  1. Open HTTPS Capture and tap MitM on the Capture tab. You will see a three-step checklist.
  2. Enable VPN: allow iOS to add the VPN configuration.
  3. Install Certificate: tap Download Certificate Profile. Safari downloads a profile; then go to Settings → General → VPN & Device Management and install it.
  4. Trust Certificate: go to Settings → General → About → Certificate Trust Settings and turn on the HTTPS Capture certificate.

When all three steps show as done, HTTPS decryption is ready. The certificate steps are covered in detail in How to install and trust the CA certificate.

Step 2: Start capturing

Go back to the Capture tab and tap Start. The card turns green and shows a timer, live request and domain counts, upload and download totals, and a throughput chart. Now use the app or website you want to inspect.

Shortcuts for starting capture:

  • Home Screen quick action: touch and hold the app icon and choose Start Capture.
  • Control Center (iOS 18 and later): add the Traffic Capture control to start or stop without opening the app.
  • Live Activity: while capturing, the Lock Screen and Dynamic Island show the elapsed time and request count.

Step 3: Read the requests

Tap the stats row or open the session. Requests can be grouped by domain or listed by time. Each row shows the method, status code, size, duration and the app that made the request. Tap a request to open five views:

  • Request: URL, headers, cookies and body
  • Response: status, headers and body, with JSON highlighting, image preview, QuickLook and hex dump
  • Frames: WebSocket messages, one by one
  • Overview: destination host, remote IP, traffic and TLS fingerprints
  • Timing: DNS, connect, TLS, waiting (TTFB) and download phases as a waterfall

Use the filter button to narrow by method, status class, content type or duration, and search URLs, headers or bodies.

Step 4: Stop and keep the session

Tap Stop when you are done. Each capture is saved as a session that you can rename, review later, compare, or export as a HAR file.

What else you can do with the captured traffic

Seeing fewer HTTPS requests than expected?

Apple system domains are skipped by default. Apps that use certificate pinning reject any CA except their own, and HTTP/3 (QUIC) traffic is not decrypted. Why some HTTPS traffic does not show up explains each case.

HTTPS Capture

Capture and decrypt HTTPS traffic on iPhone

App Store

Ready to try it?

HTTPS Capture · Capture and decrypt HTTPS traffic on iPhone

Free on the App Store