To read HTTPS traffic on an iPhone, any capture tool needs a root CA certificate that iOS trusts. Installing the profile is only half of it. The certificate also has to be switched on in a second, easy-to-miss settings page. This guide covers both steps in HTTPS Capture, explains how to make the certificate unique to your device, and lists fixes for when HTTPS still will not decrypt.
Why a certificate is needed
HTTPS is encrypted between the app and the server. To show you the plaintext, HTTPS Capture acts as a local man-in-the-middle proxy. It presents a certificate for each site, signed by its own CA. iOS only accepts those certificates after you install the CA and fully trust it. Without that, apps reject the connection, and you only see the encrypted tunnel (a CONNECT request) instead of the real URLs and bodies.
Step 1: Download the certificate profile
- Open HTTPS Capture and tap MitM on the Capture tab.
- Make sure step one, Enable VPN, is done.
- Under Install Certificate, tap Download Certificate Profile. Safari opens and asks to download a configuration profile. Tap Allow.
Step 2: Install the profile
- Open the Settings app. A Profile Downloaded row appears near the top. If it does not, go to General → VPN & Device Management.
- Tap the HTTPS Capture profile, then Install, and enter your passcode.
Step 3: Turn on full trust (the step most people miss)
- Go to Settings → General → About.
- Scroll to the bottom and tap Certificate Trust Settings.
- Turn on the switch next to HTTPS Capture and confirm.
The Open Trust Settings button in the app takes you close to this page. Back in HTTPS Capture, the setup progress should show all three steps as complete.
Make the certificate unique to your iPhone (recommended)
The default CA ships with the app. For better security, scroll down to Certificate Management and tap Regenerate CA. The app creates a new CA on your iPhone, and it never leaves the device. After you regenerate, the old certificate stops working: delete the old profile, then repeat steps 1–3 with the new one.
Certificate Management can also:
- Import Custom CA: use your own CA from a PKCS#12 (
.p12/.pfx) file or PEM files, for example one already trusted by your test devices. Only RSA keys are supported. - Export CA Certificate: share the CA as
.pemor.cer, for example to install it on another device when you use LAN capture. - Export PKCS#12: export the certificate and private key together, optionally protected with a password.
- Reset to Default CA: go back to the built-in certificate.
HTTPS still not decrypted?
- Trust switch is off: this is by far the most common cause. Check Certificate Trust Settings again.
- Old certificate is trusted: after Regenerate CA or Import, the previous profile no longer matches. Remove it and trust the new one.
- The app uses certificate pinning: some banking and social apps only accept their own certificate. HTTPS Capture detects this and passes that host through without decrypting it, so the app keeps working.
- Apple system domains: these are skipped by default. You can turn on Apple domain capture in Settings, but many Apple services are pinned anyway.
More cases are covered in why HTTPS capture is not working on iPhone.
Removing the certificate when you are done
A trusted root CA is powerful. If you stop using the app, delete the profile in Settings → General → VPN & Device Management. Its trust setting disappears along with it.
Ready to try it?
HTTPS Capture · Capture and decrypt HTTPS traffic on iPhone
Free on the App Store