Skip to content

How to Modify HTTP Headers, Block or Redirect URLs on iPhone

Use URL Rewrite in HTTPS Capture to add or change request and response headers, find and replace text in bodies, block URLs or redirect them on iPhone.

2 min readHTTPS Capture

You might need to add an Authorization header to every API call, change a User-Agent, remove a Cache-Control header, block a tracking URL, or replace a word in every response. Pausing each request by hand would take forever. URL Rewrite in HTTPS Capture turns these changes into rules that run automatically on every matching request on your iPhone.

Open URL Rewrite

  1. On the Capture tab, tap Rules → URL Rewrite.
  2. Turn on Enable Rewrite and tap Add Rewrite Rule.
  3. Enter the URL pattern that the rule applies to, choose Contains or Regex, then pick a rule type.

Rules take effect as soon as you save them. Each rule has its own on/off switch, and you can drag rules to change their order.

Rule type 1: Request Header / Response Header

ActionWhat it does
Add / OverwriteSets a header, replacing any existing value
RemoveDeletes the header
ReplaceChanges the value only when it equals what you enter
Replace (Regex)Replaces the matching part of the value; supports $1 groups

Examples:

  • Add Authorization: Bearer <token> to api.example.com requests.
  • Overwrite User-Agent to test how a server treats another client.
  • Remove Cache-Control or Set-Cookie from responses.

All matching header rules apply, in list order.

Rule type 2: Request Body / Response Body

Choose Replace for plain text or Replace (Regex) for patterns. For example, replace "isPremium":false with "isPremium":true in a response to test a premium screen. Compressed responses are decompressed automatically before the text is replaced. Response bodies up to 4 MB can be rewritten; larger responses pass through unchanged.

Rule type 3: URL (block or redirect)

ActionResponse the app receives
RejectAn HTML “rejected” page, with an optional status code such as 403 or 404
Reject (Tiny GIF)A 1×1 transparent image, good for blocking ad and tracking pixels without broken-image icons
Reject (Empty Object){} as JSON
Reject (Empty Array)[] as JSON
Drop ConnectionNo response; the connection is reset
Redirect 302 / 301 / 307A redirect to the URL you enter

Blocked requests still appear in the request list, so you can confirm that the rule matched.

Tips

  • Keep URL patterns specific. A rule matching .com would touch almost everything.
  • For body and URL actions, the first matching rule wins. Header rules all apply.
  • To send a request to a different server while keeping its path, use Map Remote instead of a redirect. The app never sees the change.
  • For conditional logic, such as “only when the user ID is 42”, use a JavaScript script.
  • To keep rules for different projects apart, put them in separate Profiles.

HTTPS Capture

Capture and decrypt HTTPS traffic on iPhone

App Store

Ready to try it?

HTTPS Capture · Capture and decrypt HTTPS traffic on iPhone

Free on the App Store