Developer Tools

HTTP & API traffic inspector for Android

Inspect HTTPS traffic on your Android phone

See every request your apps make — on the Android phone.

VpnService capture. HTTPS only for domains you choose. Live to the dashboard — no computer, no Wi-Fi proxy.

The app is currently in testing on Google Play — if the listing isn't available for you yet, sideload the APK directly.

Try the live demo
Busymate DevTools home screen on Android

Quick start

From install to live capture in minutes

Four quick steps — the in-app guided setup walks you through each one.

  1. Sign in

    01

    Create a free Busymate account with Google or email — it pairs the app to your device.

  2. Add your domains

    02

    List the domains you want to decrypt. Everything else stays end-to-end encrypted.

  3. Run the guided setup

    03

    Allow the capture notification, install the certificate generated just for you, and approve Android's VPN consent — one screen at a time.

  4. Capture & inspect

    04

    Flip capture on and requests stream in live — tap any one for full headers and body.

Why capture runs as a foreground service

Real-time feed

See requests as they happen

Every request streams in live — method, URL, host, status. No computer, no Wi-Fi proxy.

Busymate DevTools real-time network feed on Android

Full detail

Drill into headers and bodies

Open any request for URL, method, timing, headers, and formatted bodies.

Busymate DevTools request detail view on Android

Consent first

Nothing is captured until you say so

Capture starts only after you agree. Stop it any time from the home screen.

Busymate DevTools consent screen on Android

Guided setup

The fiddly parts, made step-by-step

Notifications, CA certificate, and VPN consent — a guided wizard, not Settings spelunking.

Busymate DevTools guided capture setup on Android

You decide

You stay in control

Busymate DevTools is built for inspecting traffic from apps and sites you own or are authorized to debug. Capture is always opt-in and you decide exactly what gets decrypted.

Capture is opt-in

Nothing is captured until you explicitly turn it on and accept the on-screen consent.

HTTPS only for chosen domains

Decryption is limited to the domains on your SSL list — add or remove them at any time.

A personal CA, on your device

Decryption uses a CA certificate generated just for you, installed as a user certificate. On rooted devices you can optionally install it system-wide.

Stop and remove anytime

Turn capture off from the home screen and remove the VPN and certificate from Android settings whenever you like. Synced captures are deletable.

Privacy first

Traffic is captured on-device by Android's VpnService — nothing routes through our servers. Captured data can include sensitive values such as tokens and credentials, so only inspect domains you understand and control. Synced captures are stored under your own account and can be deleted at any time. Read the Android privacy policy.

Ready to debug on the go

  • Android 7.0 or later
  • A free Busymate account (sign in with Google or email)
  • No root required — root only unlocks optional system-wide decryption
Get it on Google Play — Busymate DevTools

On-device capture

Your whole phone's traffic, one live feed

HTTPS on the Android phone itself. Pick what to decrypt, turn capture on, watch it live.

System-wide capture via VpnService

Android's VpnService routes the whole phone's traffic through the app — every app, DNS and TCP alike, captured on the device itself. No computer required.

Decrypts only what you allow

TLS is decrypted only for hosts on your SSL list, using a CA certificate generated just for you — installed as a user certificate. On rooted devices it can optionally go system-wide to reach apps that ignore user CAs. Everything else passes through untouched.

Live on your dashboard

Every request streams to your private dashboard in real time — inspect on a bigger screen, search, tag, mock, and export to HAR.

PAC mode, when a VPN won't do

Prefer a proxy? PAC mode gives the device its own proxy auto-config URL — set it on your Wi-Fi network and traffic routes through your personal Busymate proxy instead of the on-device VPN.

Agent-ready over MCP

Everything the phone captures is queryable and scriptable by AI agents over the MCP server — and BusyBro, the built-in AI teammate, already knows your traffic.

Remote-managed, in your language

Capture settings, SSL lists and mock rules push to the phone live from the dashboard — no reinstall, no update. And the whole app speaks 14 languages.

How it works

Inside the netstack

A system VPN, a userspace TCP/IP stack and selective TLS interception — the whole pipeline runs on the phone.

  1. 01

    VpnService takes the route

    Android hands the whole phone's packets to the app's TUN interface — a system VpnService running as a special-use foreground service. Every app's traffic, no root required.

  2. 02

    A userspace netstack rebuilds the flows

    Packets are parsed and TCP is reassembled entirely inside the app — IPv4 and IPv6, DNS forwarding, QUIC accounting — then forwarded upstream. The netstack is the debugger's own, not the kernel's.

  3. 03

    TLS opens only where you allow it

    Hosts on your SSL list are intercepted with a CA generated for your install and added as a user certificate. Rooted devices can opt into a system-wide CA tier for apps that ignore user CAs; everything else passes through encrypted.

  4. 04

    The same rows, the same feed

    Captured pairs land in the identical table and wire shape as iOS, the proxy and Chrome capture — over the same pairing handshake and long-lived device token, listening on the same Realtime control channels.

Under the hood

The stack, specified

What ships on the phone — and how it stays the exact peer of the iOS app.

Capture
System-wide VpnService TUN with a userspace TCP/IP netstack — no root needed
Decryption
Selective per-host TLS interception via a per-install user CA; optional system-CA tier on rooted devices
UI
Kotlin · Jetpack Compose (Material 3)
OS support
minSdk 24 (Android 7.0) · targetSdk 36
Distribution
Google Play (production) — plus a signed APK for direct sideload
Credential storage
Device token in hardware-Keystore-backed encrypted preferences; backups excluded

FAQ

Android questions, answered

Is the app on Google Play?

Yes — it's live in production on the Google Play Store, and a signed APK is also published for direct sideload if your device or fleet can't use Play.

Do I need root?

No. Capture and user-CA decryption work on any Android 7.0+ phone. Root only unlocks the optional system-CA tier, which reaches apps that ignore user-installed certificates.

Is it the same product as the iOS app?

It's the contract-identical twin: the same entry tables, the same wire shape, the same pairing handshake and Realtime channels — so Android and iOS devices stream side by side in one dashboard feed.

Why is there a persistent notification while capturing?

Android requires a visible foreground service while a VPN runs. The notification is your capture-session indicator — and it stops the OS from killing capture mid-session.

Ask your mate