You might need to add an Authorization header to every API call, change a User-Agent, remove a Cache-Control header, block a tracking URL, or replace a word in every response. Pausing each request by hand would take forever. URL Rewrite in HTTPS Capture turns these changes into rules that run automatically on every matching request on your iPhone.
Open URL Rewrite
- On the Capture tab, tap Rules → URL Rewrite.
- Turn on Enable Rewrite and tap Add Rewrite Rule.
- Enter the URL pattern that the rule applies to, choose Contains or Regex, then pick a rule type.
Rules take effect as soon as you save them. Each rule has its own on/off switch, and you can drag rules to change their order.
Rule type 1: Request Header / Response Header
| Action | What it does |
|---|---|
| Add / Overwrite | Sets a header, replacing any existing value |
| Remove | Deletes the header |
| Replace | Changes the value only when it equals what you enter |
| Replace (Regex) | Replaces the matching part of the value; supports $1 groups |
Examples:
- Add
Authorization: Bearer <token>toapi.example.comrequests. - Overwrite
User-Agentto test how a server treats another client. - Remove
Cache-ControlorSet-Cookiefrom responses.
All matching header rules apply, in list order.
Rule type 2: Request Body / Response Body
Choose Replace for plain text or Replace (Regex) for patterns. For example, replace "isPremium":false with "isPremium":true in a response to test a premium screen. Compressed responses are decompressed automatically before the text is replaced. Response bodies up to 4 MB can be rewritten; larger responses pass through unchanged.
Rule type 3: URL (block or redirect)
| Action | Response the app receives |
|---|---|
| Reject | An HTML “rejected” page, with an optional status code such as 403 or 404 |
| Reject (Tiny GIF) | A 1×1 transparent image, good for blocking ad and tracking pixels without broken-image icons |
| Reject (Empty Object) | {} as JSON |
| Reject (Empty Array) | [] as JSON |
| Drop Connection | No response; the connection is reset |
| Redirect 302 / 301 / 307 | A redirect to the URL you enter |
Blocked requests still appear in the request list, so you can confirm that the rule matched.
Tips
- Keep URL patterns specific. A rule matching
.comwould touch almost everything. - For body and URL actions, the first matching rule wins. Header rules all apply.
- To send a request to a different server while keeping its path, use Map Remote instead of a redirect. The app never sees the change.
- For conditional logic, such as “only when the user ID is 42”, use a JavaScript script.
- To keep rules for different projects apart, put them in separate Profiles.
Ready to try it?
HTTPS Capture · Capture and decrypt HTTPS traffic on iPhone
Free on the App Store