The debugging proxy Claude can read
Wirepane turns Claude Code into an HTTPS debugging proxy for the browser, the iOS Simulator, iPhones, the Android emulator and Android phones. It decrypts HTTP/2, gRPC, WebSockets and server-sent events, shows them next to your conversation, and gives Claude the same traffic through 16 tools.
Instead of copying requests into the chat, you ask:
Claude finds the request and reads only the part it needs. It compares the one that works with the one that fails, replays it with a change, writes a rule, and fixes your code. When something is in the way, the doctor names it and fixes it: a missing CA, a pinned certificate, a VPN, or Charles holding the system proxy.
Every protocol a modern app speaks
HTTP/2 both ways
Clients that offer h2 get it. Servers that speak it get it. Everything else gets HTTP/1.1, each side on its own. Plain-text h2c too, for gRPC to a local service.
gRPC and protobuf
gRPC and gRPC-Web, trailers forwarded. Messages are decoded without a schema, by field number. A failed call says why: gRPC NOT_FOUND.
WebSockets, message by message
Both ways, with timing and close codes, compression taken out of the offer so every message stays readable.
Server-sent events, as they arrive
Event by event, with the millisecond each one came. LLM streaming APIs, debugged.
Every client, one press
| Client | How |
|---|---|
| A separate browser | Chrome, Edge, Brave or Chromium with a profile of its own, localhost captured, trusting the proxy by SPKI hash. No certificate to install. |
| iOS Simulator | Use: it boots, gets the CA, and the Mac's system proxy points here, with Claude Code's own traffic left alone. |
| iPhone / iPad | The exact address to type and a QR code that installs the profile; the tab confirms when traffic arrives. |
| Android emulator | Start through the proxy launches an AVD behind it and opens the CA page. On Google APIs images, Trust in all apps makes the CA a system CA. |
| Android phone | On USB through adb reverse, no Wi-Fi needed; on Wi-Fi with the QR code. |
| curl, Node, Python, Go | HTTPS_PROXY, NODE_EXTRA_CA_CERTS, SSL_CERT_FILE, REQUESTS_CA_BUNDLE, copied from the CLI tab. |
Tools for Claude
Sixteen tools, built so Claude reads what it needs and nothing more. Long URLs are cut, requests are read part by part under one budget, and json_path picks one field from a megabyte of JSON.
| Tool | What it does |
|---|---|
list_requests | One line per request, filtered; since lists only what is new. |
get_request | One request by part (summary, headers, request, response, messages), gRPC decoded, trailers, WebSocket messages, SSE events. |
wait_for_request | Waits for the request you are about to trigger and answers it the moment it ends. |
search_requests | Finds a value in URLs, headers, bodies, messages and events: which request returned invalid_token? |
diff_requests | The request that works against the one that fails: query, headers, status, JSON field by field. |
replay_request | Sends a request again, as it was or changed, recorded and under the rules. |
resume_request | Lets go of an exchange held at a breakpoint: as it was, changed, answered by hand, or cut. |
send_ws_message, close_websocket | Injects a message into a live WebSocket, either way, or closes it to test reconnects. |
add_rule, update_rule, remove_rule, list_rules | The rules file, applied at once. |
track_domains | Records only your app's hosts; shows what passed through. |
export_har | HAR 1.2 with bodies and WebSocket messages, for a teammate or Chrome DevTools. |
diagnose | The doctor. |
Three skills ship with it:
- debugging: the order that works.
- troubleshooting: symptom, check, fix, including the fix in your own app's code. Android
network_security_config, pinning in debug builds, Flutter'sHttpOverrides, Node, Go, Java and Docker proxies. - rules: recipes, each tested to validate.
A doctor that fixes what is in the way
/proxy doctor, the Health view, or Claude's diagnose look at the whole path from the client to the server:
- the proxy process and the sessions sharing it;
- the system proxy;
- a VPN;
- other proxy apps;
- the CA on each client;
- pinned hosts;
- upstream failures;
- tracked domains;
- Android devices.
Each finding has its fix, and a button when Wirepane can do it.
iPhone: install the profile, then Certificate Trust Settings → turn on Wirepane CA.
Pinned hosts pass through
A host that refuses the certificate twice is tunnelled untouched, so the app keeps working. It is decrypted again once the client trusts the CA.
No internet after a crash, never again
A watchdog puts the system proxy back if the proxy is killed, and the next session repairs it at start.
Dev servers with self-signed certificates
One press accepts that host's certificate, and only that host's.
Office networks
An upstream proxy (HTTP with credentials, SOCKS5, or a PAC file) carries every connection to the servers, and the doctor offers the network's own proxy for it.
Rules and mock servers
Ask in plain words and Claude writes the rule into the project's .claude/proxy-rules.json. The proxy applies it at once. You can do:
- breakpoints: a request or a response held until you or Claude let it go, changed or not;
- mocks, delays, throttling, errors and dropped connections;
- rewritten headers, URLs and JSON;
- sending requests to your local server;
- GraphQL operations matched by name.
For WebSockets, rules rewrite, drop, delay and answer messages, or play the whole server:
{ "id": "mock-prices-socket",
"match": { "path": "/ws/prices" },
"request": [{ "type": "respond", "status": 101 }],
"messages": [
{ "type": "send", "on": "open", "to": "client", "json": { "type": "hello" } },
{ "type": "reply", "when": "\"subscribe\"", "json": { "type": "price", "price": 42.5 } } ] }
One proxy for every session
A single proxy serves every Claude Code session on the Mac. A second session attaches and sees what the first recorded, and each project's rules apply while its session is open. The Health view shows the process, its memory and the sessions using it. With every session gone, the proxy puts the system proxy and Android devices back and exits.
Install
You need macOS, Claude Code 2.1.292 or newer, and openssl (built into macOS). The proxy runs on Node.js 18 or newer, which it finds by itself; with none, the pane offers to install it. At the Claude Code prompt:
/plugin install wirepane --marketplace legostin/wirepane
Then run /proxy. No account, no telemetry, no npm dependencies. The CA is made on your machine, and recordings stay in ~/.claude/proxy-mod.
FAQ
Is it a replacement for Proxyman, Charles, mitmproxy or HTTP Toolkit?
For finding out what an app sent, what came back and why it fails, yes, without leaving Claude Code: HTTP/2, gRPC, WebSockets and SSE, with rules, mocks, replays and diffs. It has breakpoints and works behind an office proxy; HTTP/3 never meets an HTTP proxy. It is built around the agent: the doctor, the waiting, search and diff tools, the context budget, and skills that fix the app's own code.
Do I have to install the certificate on my Mac?
Not for the separate browser, which trusts the proxy by SPKI hash. Safari, native Mac apps and the iOS Simulator need the CA, one press each.
Why do some requests show CERT?
The client refused the proxy's certificate: it does not trust the CA yet, or the app pins its certificates. The diagnose tool tells which, and a pinned host passes through after two refusals so the app keeps working.
I see nothing from my Flutter, Go or Unity app.
Some runtimes ignore the system proxy. The troubleshooting skill gives Claude the few lines that fix it in a debug build, such as Flutter's HttpOverrides.
Does my traffic leave my machine?
Only for the servers it was going to anyway. Recordings stay in ~/.claude/proxy-mod, and Claude reads a request only through a tool.
Limits
- HTTP/3 (QUIC): it never meets an HTTP proxy. An app that forces it is not seen.
- Protobuf: decoded without a schema, so it shows field numbers, not names.
- Kerberos: an upstream proxy that takes only Kerberos tickets needs a helper that signs in for you, such as Px. Basic and NTLM sign in by themselves.
- Android system CA: it needs a Google APIs emulator image and lasts until a reboot. Android 17 asks for Certificate Transparency on system CAs.
- Platform: macOS only. Mods are an early-access Claude Code API.