Voyez chaque requête que votre iPhone envoie.
Capture HTTPS de tout le système sur le téléphone lui-même — déchiffrez uniquement les domaines que vous choisissez, suivez le tout en direct sur le tableau de bord et modifiez les règles à distance.
Regardez la procédure de configuration.
De l'installation à la capture en direct en une environ
Suivez les étapes ci-dessous ou regardez la démonstration en haut de cette page.
Sign in
01Create a free Busymate account with Apple or email — it pairs the app to your device.
Add your domains
02List the domains you want to decrypt. Everything else stays end-to-end encrypted.
Install & trust the CA
03Install the local certificate generated just for you — the 1-minute walkthrough above shows exactly how.
Capture & inspect
04Flip capture on, accept the disclosure, and requests stream in live — tap any one for full headers and body.
Voyez les requêtes en direct
Every request streams in live — method, URL, status, headers, and body. No Mac, no Wi-Fi proxy.


Explorez les en-têtes et les corps
Open any request for headers, query, status, timing, and full bodies — formatted and readable.


Ne déchiffrez que les domaines
Decrypt only the domains you add. Everything else stays end-to-end encrypted.


Synchronisez vers
Optionally sync to dash.busymate.dev — search, tag, and export HAR on a bigger screen.


Vous gardez le
Built for traffic from apps and sites you own or are authorized to debug. Capture is always opt-in.
Capture is opt-in
Nothing is captured until you explicitly turn it on and accept the on-screen disclosure.
HTTPS only for chosen domains
Decryption is limited to domains you add — and you can add or remove them at any time.
A local CA, on your device
Decryption uses a CA certificate generated just for you, with guided step-by-step setup inside the app.
Stop and remove anytime
Stop capturing and remove the VPN profile from iOS Settings whenever you like. Synced captures are deletable.
La confidentialité avant tout
La capture s’exécute sur votre appareil. Les captures synchronisées sont stockées dans votre compte et peuvent contenir des données sensibles. Inspectez uniquement le trafic que vous êtes autorisé à déboguer. Politique de confidentialité
Prêt à déboguer
- iOS / iPadOS 17 or later
- A free Busymate account (sign in with Apple or email)
- No in-app purchases
The debugger is
Le HTTPS sur l’iPhone lui-même — sans Mac, sans câble. Choisissez quoi déchiffrer, activez la capture, regardez en direct.
Voit tout, ne déchiffre que ce que vous autorisez
Un VPN NetworkExtension capture le trafic de tout le système — votre app, les apps tierces, tout. Le TLS n’est déchiffré que pour les hôtes que vous ajoutez explicitement à la liste SSL : le reste du téléphone reste privé.
Sans Mac. Sans proxy. Sans bidouille.
Rien à brancher, rien à configurer sur un portable. Le téléphone capture, déchiffre et streame tout seul — depuis votre bureau, le banc de test ou l’autre bout du monde.
Activez le proxy SSL en un clic
Une entrée chiffrée dans le tableau de bord ? Un clic. L’appareil reçoit le changement via Realtime et commence à déchiffrer cet hôte en quelques secondes — sans retourner au téléphone.
Géré à distance, en direct par les airs
Règles, scripts, simulations et interrupteurs VPN sont poussés en direct depuis le tableau de bord — sans rebuild, sans revue App Store. Activez la capture ou ajoutez un hôte à la liste SSL : le téléphone le reçoit via Realtime en quelques secondes.
Inside
A packet tunnel, an SNI matcher and an on-device certificate authority — the whole MITM pipeline runs on the phone.
- 01
The phone becomes the tunnel
A NetworkExtension packet tunnel claims the default route, so every app's DNS and TCP passes through the debugger — on the device itself. No Mac, no cable, no proxy settings.
- 02
The handshake decides what's decrypted
Each TLS connection's server name is read from the handshake and matched against your SSL-proxying list — wildcards included. Listed hosts are intercepted; everything else passes through encrypted.
- 03
Certificates are minted on the phone
La CA est générée sur l'appareil au premier lancement — vos clés ne quittent jamais le téléphone. Les certificats feuilles par hôte sont émis à la demande et mis en cache, si bien que ce qui arrive dans votre flux est exactement la requête et la réponse que votre app a vues.
- 04
Rows stream straight to your feed
Every captured pair is written directly to the shared entries table over the device's own long-lived pairing token — no files to pull, no sync step. The dashboard sees it the moment it lands.
The pipeline,
What actually runs when you flip capture on — and what never leaves the phone.
- Capture
- System-wide DNS + TCP via a NetworkExtension packet tunnel
- Decryption
- Selective, per-host SSL list with wildcard patterns — opt-in, never everything
- MITM engine
- per-host leaf certificates · RSA-2048
- Pairing
- 365-day device token claimed at pairing — capture keeps streaming without re-login
- Live control
- Realtime push for settings, SSL lists, VPN on/off, breakpoints and resends — applied in seconds, over the air
- Alternate mode
- PAC proxy mode routes the phone through the shared MITM proxy instead of the on-device tunnel
- Requirements
- An iPhone. No Mac, no jailbreak, no computer in the loop
iOS questions,
Do I need a Mac or any computer?
No. Capture, decryption and streaming all run on the iPhone itself — the phone is the debugger. You watch and control it from the web dashboard on any screen.
Does it decrypt everything on my phone?
No. TLS is opened only for hosts you explicitly add to the SSL-proxying list; every other connection passes through encrypted and untouched. The list is yours, editable live from the dashboard.
How do changes reach the phone without an app update?
The app is server-driven by design: rules, scripts, mocks, SSL lists and even the VPN toggle push to the device over a live Realtime connection. Behaviour changes in seconds — no rebuild, no App Store review cycle.
What about HTTP/3 (QUIC) traffic?
QUIC is not intercepted: the tunnel declines UDP/443 (and counts it), so apps fall back to HTTPS over TCP — where selective decryption and capture work normally.