Skip to content

How to Intercept and Modify HTTP Requests and Responses on iPhone

Pause matching HTTPS requests or responses on iPhone with a breakpoint, then edit headers, body or status code before passing or dropping them.

3 min readHTTPS Capture

Sometimes reading traffic is not enough, and you need to change it as it happens. You might set a price to 0 in a response, swap a user ID in a request, or turn a 200 into a 403 to see what the app does. With breakpoints in HTTPS Capture, you can pause a live request or response on the iPhone, edit it by hand, and then send it on.

How breakpoints work

When a request matches a breakpoint rule, HTTPS Capture holds it before it goes anywhere:

  • A request breakpoint pauses the request before it reaches the server. Nothing is sent until you decide.
  • A response breakpoint waits for the full server response and pauses it before the app receives it.

While a request is paused you can Pass it unchanged, Drop it, or Edit & Pass with your changes.

Step 1: Add a breakpoint rule

  1. On the Capture tab, tap Rules → Breakpoint.
  2. Turn on Enable Breakpoint and tap Add Rule.
  3. Enter a URL pattern, for example api.example.com/checkout. Choose Contains or Regex for Match.
  4. Set Direction to Request or Response. To edit both sides of a call, add one rule for each.
  5. Add a comment if you like, then save. The rule is active immediately.

Keep the pattern narrow. A breakpoint on example.com pauses every image and script from that site.

Step 2: Trigger the request

Start capture and do the action in the app. When the rule matches, the Capture tab shows a red paused requests badge. Tap it to open Paused Requests. The same list is also on the Breakpoint page.

Each paused item shows its direction (REQ or RESP), method, status code and URL, along with an auto-pass countdown.

Step 3: Pass, drop or edit

  • Pass: forward it unchanged.
  • Drop: cancel it. The app sees a failed connection.
  • Edit & Pass: open the editor, then:
    • Edit headers, one Key: Value per line. Duplicate headers such as several Set-Cookie lines are kept.
    • Edit the body of text content such as JSON, XML, HTML, form data or JavaScript. Compressed bodies (gzip, deflate, Brotli) are decoded for editing and compressed again automatically.
    • For responses, change the status code (100–599).

After you submit, Content-Length is recalculated so the edited message stays valid.

Things to know

  • Auto-pass after 10 minutes: a request you forget about is released automatically, so an app never hangs forever. The countdown turns red in the last minute.
  • The app may time out first: many apps give up after 30–60 seconds. Edit quickly, or use a rewrite rule or script for repeatable changes.
  • Streaming responses such as Server-Sent Events are not suited to response breakpoints, because the response must arrive in full before it can be paused.
  • Binary bodies and bodies larger than 8 MB are shown read-only.
  • Request timing records the time spent paused separately, so the Timing waterfall stays honest.

When to use something else

HTTPS Capture

Capture and decrypt HTTPS traffic on iPhone

App Store

Ready to try it?

HTTPS Capture · Capture and decrypt HTTPS traffic on iPhone

Free on the App Store