What it does
mitmproxy sits between a client and its servers and terminates TLS on both sides. It generates a certificate authority on first run, issues leaf certificates for each host the client requests, and, once that authority is trusted on the device, decrypts and re-encrypts traffic while showing you everything in between. You see requests and responses in full, and you can pause a flow, edit it, and let it continue.
It ships three front ends over one engine: an interactive terminal interface, a browser based interface, and a non interactive dumper for scripted capture. The addon API is what makes it more than a viewer. Addons are Python modules with hooks at each stage of a flow, so you can rewrite a request body, strip a header, inject a response, log a field to disk, or replay captured flows against a different environment. It handles WebSocket traffic and runs as a regular proxy, a transparent proxy for clients that ignore proxy settings, a reverse proxy in front of a service, or an upstream proxy chained to another.
Where it fits
In mobile work this is how you see what an app talks to. Point the device at the proxy, install the certificate authority, and the app's backend calls become visible and editable, which is the starting point for testing authorization, input handling and client side trust decisions. It is operated by a tester or developer on a workstation or lab host during manual testing, and is also useful headless as a capture and rewriting component inside larger automation.
Strengths
- The Python addon API turns the proxy into a programmable traffic manipulation platform, the capability that outlasts any single test.
- Three interfaces over one engine, so interactive exploration and headless automation share configuration and behavior.
- Multiple proxy modes, including transparent mode, which covers clients that ignore system proxy settings.
Limitations
- Certificate pinning stops it. Any application that validates a pinned certificate will refuse to talk through the proxy, and you have to defeat the pinning with instrumentation or repackaging first, which is separate work.
- It only sees traffic that goes through it. Apps using QUIC or raw sockets bypass it, and that traffic is silently absent rather than flagged.
- It is a traffic tool, not a scanner. There is no detection, no rules and no report, so findings are a product of what you notice.
Who it suits
Mobile and API testers who want an inspectable, scriptable interception layer, and developers debugging client to server behavior. Teams wanting an integrated testing suite with a scanner and a finding workflow should choose a purpose built proxy suite instead.
Used mitmproxy? Recommend it under your own name and title.
Recommend this tool