mitmproxy
Interactive HTTPS proxy for inspecting, modifying and replaying traffic between clients and servers.
External Tool
This open-source tool is maintained externally. View the source on GitHub to learn more or run it yourself.
Browse security tools →What's next with mitmproxy?
Choose how you want to get started.
Use it free
Open the official tool or demo — no account needed.
Self-host it
Run the open-source version on your own infrastructure.
What is mitmproxy?
mitmproxy is an open-source, interactive HTTP/2 proxy tool designed for intercepting and analyzing traffic between clients and servers. It enables penetration testers and developers to inspect, modify, and replay HTTP/1.1 and HTTP/2 requests/responses, with full TLS/SSL decryption capabilities. The tool addresses challenges in debugging web applications, security testing, and API development by providing a flexible, scriptable interface for inspecting encrypted traffic. Its MIT license ensures broad accessibility, while its active community and 38,000+ GitHub stars reflect its value in both security and software development workflows. By acting as a man-in-the-middle (MITM) proxy, it solves the problem of inspecting encrypted communications without requiring changes to client or server configurations.
How it works
mitmproxy is an intercepting HTTP proxy that supports TLS/SSL decryption, allowing users to inspect and manipulate traffic between clients and servers. It serves as a critical tool for security professionals and developers, enabling tasks like API testing, security research, and debugging web applications. The tool's primary purpose is to provide a transparent, scriptable interface for analyzing encrypted traffic, overcoming the limitations of traditional tools that cannot inspect HTTPS content without intermediate steps. mitmproxy supports HTTP/1.1 and HTTP/2 protocols, with full TLS interception capabilities for decrypting HTTPS traffic. It features a console-based interface for real-time inspection and modification of requests/responses, along with scriptable automation via Python plugins. The tool also includes built-in support for handling large-scale traffic analysis and replaying intercepted requests.
How to use it
- 1Install mitmproxy via pip or download the binary from its GitHub repository. 2. Run the proxy using 'mitmproxy' in the terminal to start the interactive console. 3. Configure the target application to use mitmproxy as its HTTP proxy (e.g., set environment variables for HTTP_PROXY and HTTPS_PROXY). 4. Intercept traffic by navigating the target application, then use commands like 'view' or 'modify' to inspect or alter requests/responses. Practical tips include generating a custom CA certificate for TLS interception, using the '--ssl-insecure' flag to bypass certificate validation during testing, and leveraging the 'flow' command to analyze specific interactions.
What it can do
- MITM proxy
Use cases
Assumptions and limitations
Assumptions
- source: https://github.com/mitmproxy/mitmproxy
- license: MIT — free to use
- privacy: Self-hosted — you control your data
Limitations
- Requires manual configuration of client applications to route traffic through the proxy
- Limited GUI interface compared to tools like Burp Suite
- Performance may degrade with high-volume or complex traffic
- Depends on SSL/TLS certificate trust chains for decryption
- Lacks built-in support for WebSocket traffic interception
Understanding the result
Interactive HTTPS proxy for inspecting, modifying and replaying traffic between clients and servers.
Tool details
- Clearly flagged when a network request is needed.
- No account, no sign-up, and no tracking of your content.
- Powered by (MIT).
- Built with
- (mitmproxy/mitmproxy)
- License
- MIT
- Runs locally
- No — requires a network request
- Verification
- Not yet verified
- Input
- Query
- Output
- Text
Built with mitmproxy/mitmproxy. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.
- Built with
- License
- MIT
Open-source project
OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.
References
- / — GitHub Repository
Upstream project · GitHub
- MIT License
Upstream project
Frequently asked
What is mitmproxy used for?
mitmproxy is primarily used for intercepting and analyzing HTTP/1.1 and HTTP/2 traffic between clients and servers. It enables security researchers to inspect encrypted communications, debug APIs, test authentication mechanisms, and automate network analysis tasks. Developers use it to troubleshoot web applications, analyze performance, and ensure compatibility with security protocols.
How does mitmproxy handle TLS interception?
mitmproxy acts as a man-in-the-middle (MITM) proxy by intercepting TLS/SSL traffic and decrypting it using a custom certificate authority (CA). When a client connects to a server, mitmproxy presents its own CA-signed certificate, allowing it to decrypt and inspect the traffic. This requires the client to trust the mitmproxy CA, which is typically achieved by installing the generated certificate on the client system.
How do I intercept HTTPS traffic with mitmproxy?
To intercept HTTPS traffic, first install mitmproxy and generate a CA certificate using 'mitmproxy --gen-certs'. Then, configure the target application to use mitmproxy as its HTTP proxy (e.g., set HTTP_PROXY and HTTPS_PROXY environment variables). Finally, run mitmproxy and navigate the target application; the intercepted traffic will appear in the console, with decryption enabled via the custom CA certificate.
How does mitmproxy compare to Burp Suite?
mitmproxy and Burp Suite are both intercepting proxies but differ in design and use. mitmproxy is open-source, scriptable via Python, and focuses on real-time traffic inspection with a console interface. Burp Suite is a commercial tool with a GUI, advanced automation features, and integrated scanning capabilities. mitmproxy is preferred for lightweight analysis and scripting, while Burp Suite offers deeper security testing functionalities.
What should I do if mitmproxy fails to decrypt TLS traffic?
If decryption fails, ensure the target application is configured to use mitmproxy as its proxy and that the custom CA certificate is installed. Check for SSL/TLS protocol mismatches by using the '--ssl-version' flag. If the server enforces strict certificate validation, temporarily disable it with '--ssl-insecure' or configure the server to accept the mitmproxy CA certificate.