Security · Tool

Traffic interception

Putting a proxy between an app and its server, on your own test device, to watch and edit every request and response. Developers use it to debug, and testers use it to check that the server does not blindly trust the app.

Testing and research · Open source · updated

How it works

An intercepting proxy such as Burp Suite, mitmproxy, ZAP (formerly OWASP ZAP), Charles or Fiddler runs on the tester's computer, and the browser, phone or app under test is pointed at it. Every HTTP request passes through, so it can be read, paused, edited and replayed. To read HTTPS, the tester installs the proxy's own certificate authority on the test device, which lets the proxy decrypt and re-encrypt the traffic; a device without that certificate shows warnings instead, which is exactly what TLS is designed to do.

The main lesson is that anything the client sends can be changed. If a price, a user id or an 'is admin' flag travels from the app and the server trusts it, anyone with a proxy can alter it. Interception also shows whether an app leaks tokens or personal data, and what its third-party SDKs send. Browser DevTools cover the basics for websites; proxies add editing, replay, automated scanning and mobile apps.

Mobile platforms make it harder on purpose: apps built for Android 7 and later ignore user-installed certificates unless their network security configuration allows them, and apps with certificate pinning accept only their own server's certificate. Teams usually allow interception in debug builds of their own apps. It is legitimate on your own devices and systems, or ones you have written permission to test; intercepting other people's traffic without consent is against the law in most places.

Traffic interception pros and cons

Pros

  • Shows exactly what an app sends and receives
  • Edit and replay requests to test the server's own checks
  • Reveals leaked tokens, personal data and chatty SDKs
  • Capable free options: mitmproxy, ZAP and Burp Suite Community

Cons

  • HTTPS needs a trusted certificate installed on the test device
  • Certificate pinning and Android defaults block it in release builds
  • Burp Suite's scanner and full-speed Intruder need the paid Professional edition
  • Only lawful on systems you own or have permission to test

When to use Traffic interception

Pick it when

  • Debugging what a web or mobile app really sends to its API
  • Security testing your own app before a release
  • Checking what data third-party SDKs in your app send out

Skip it when

  • The browser's DevTools network panel already shows what you need
  • You do not have permission to test the system

Traffic interception pricing

Open source

mitmproxy and ZAP are free and open source, and Burp Suite Community Edition is free. Burp Suite Professional costs about $499 per user a year.

Traffic interception pricing page (opens in a new tab)Approximate, checked September 2026.What the other tools cost

More in Security

Testing and research

All 20 Security terms

Crafted in the dark. Shipped to the world.

Tell us what you are building. You get a private project space with a proposal and a line-by-line quote within a day.