Chat apps, live scores, trading apps, multiplayer games and AI assistants often skip plain request/response calls. They use WebSocket connections or streaming responses instead. Most packet sniffers show only the opening 101 Switching Protocols request and nothing after it. HTTPS Capture shows every message on the iPhone, frame by frame.
See WebSocket frames
- Start capture and open the app that uses WebSocket.
- In the request list, WebSocket connections carry a WS or WSS badge.
- Open one and switch to the Frames tab.
Each row shows:
- the direction: an orange arrow for sent, a blue arrow for received
- the opcode (text, binary, ping, pong, close)
- a timestamp with milliseconds and the frame size
- a preview of the payload
Use All / Sent / Received to see one side of the conversation. The list keeps updating while the connection stays open, so you can watch messages arrive live.
Look inside a single frame
Tap a frame to see:
- JSON pretty-printed automatically, when the payload is JSON
- plain text for other text payloads
- a hex dump for binary payloads
- frame details such as the final flag, reserved bits and extension data
Tap the copy button to put the payload on the clipboard.
Decode Protobuf and gRPC
Many apps send binary Protobuf messages instead of JSON, over WebSocket or gRPC. HTTPS Capture detects Protobuf and gRPC bodies and decodes them into fields, so you see more than raw bytes. gRPC requests get their own gRPC badge in the list.
Without a schema you see field numbers and values. To see field names and types, add the schema:
- Go to Settings → Protobuf Schemas.
- Tap Import Schema Files and choose one or more
.protofiles, or a compiled descriptor set (.desc,.protosetor.pb). - Import related
.protofiles together so that message references resolve.
Read Server-Sent Events (SSE)
AI chat apps and live dashboards often stream answers with text/event-stream (Server-Sent Events) instead of WebSocket. When a response is SSE, the Response tab adds an SSE Events section. It lists each event with its event type, id and data, so you can follow a streamed answer piece by piece.
Tips
- Make sure the CA certificate is trusted. Without it, secure
wss://connections cannot be decrypted. - The Timing tab shows how long the connection stayed open as a “Streaming” phase.
- Rules that rewrite whole response bodies skip streaming responses, so live streams are passed through untouched.
Ready to try it?
HTTPS Capture · Capture and decrypt HTTPS traffic on iPhone
Free on the App Store