See every request your iPhone sends.
System-wide HTTPS capture on the phone itself — decrypt only the domains you choose, watch it live on the dashboard, and change the rules over the air.
Watch the setup walkthrough.
From install to live capture in about a
Follow the setup steps below, or watch the walkthrough at the top of this page.
Sign in
01Create a free Busymate account with Apple or email — it pairs the app to your device.
Add your domains
02List the domains you want to decrypt. Everything else stays end-to-end encrypted.
Install & trust the CA
03Install the local certificate generated just for you — the 1-minute walkthrough above shows exactly how.
Capture & inspect
04Flip capture on, accept the disclosure, and requests stream in live — tap any one for full headers and body.
See requests
Every request streams in live — method, URL, status, headers, and body. No Mac, no Wi-Fi proxy.


Drill into
Open any request for headers, query, status, timing, and full bodies — formatted and readable.


Decrypt only the domains
Decrypt only the domains you add. Everything else stays end-to-end encrypted.


Sync to
Optionally sync to dash.busymate.dev — search, tag, and export HAR on a bigger screen.


You stay in
Built for traffic from apps and sites you own or are authorized to debug. Capture is always opt-in.
Capture is opt-in
Nothing is captured until you explicitly turn it on and accept the on-screen disclosure.
HTTPS only for chosen domains
Decryption is limited to domains you add — and you can add or remove them at any time.
A local CA, on your device
Decryption uses a CA certificate generated just for you, with guided step-by-step setup inside the app.
Stop and remove anytime
Stop capturing and remove the VPN profile from iOS Settings whenever you like. Synced captures are deletable.
Privacy first
Capture runs on your device. Synced captures are stored in your account and may contain sensitive data. Only inspect traffic you are authorized to debug. Privacy Policy
Ready to debug
- iOS / iPadOS 17 or later
- A free Busymate account (sign in with Apple or email)
- No in-app purchases
The debugger is
HTTPS on the iPhone itself — no Mac, no cable. Pick what to decrypt, turn capture on, watch it live.
Sees everything, decrypts only what you allow
A NetworkExtension VPN captures traffic system-wide — your app, third-party apps, all of it. TLS is decrypted only for hosts you explicitly add to the SSL list, so the rest of the phone stays private.
No Mac. No proxy. No fiddling.
There is nothing to tether and nothing to configure on a laptop. The phone captures, decrypts and streams on its own — from your desk, the test bench, or the other side of the world.
Enable SSL proxying in one click
Spot an encrypted entry in the dashboard? Click once. The device picks up the change over Realtime and starts decrypting that host within seconds — no trip back to the phone.
Remote-managed, live over the air
Rules, scripts, mocks and VPN toggles push to the device live from the dashboard — no rebuild, no App Store review. Flip capture on or add a host to the SSL list and the phone picks it up over Realtime within seconds.
Inside
A packet tunnel, an SNI matcher and an on-device certificate authority — the whole MITM pipeline runs on the phone.
- 01
The phone becomes the tunnel
A NetworkExtension packet tunnel claims the default route, so every app's DNS and TCP passes through the debugger — on the device itself. No Mac, no cable, no proxy settings.
- 02
The handshake decides what's decrypted
Each TLS connection's server name is read from the handshake and matched against your SSL-proxying list — wildcards included. Listed hosts are intercepted; everything else passes through encrypted.
- 03
Certificates are minted on the phone
The CA is generated on-device at first launch — your keys never leave the phone. Per-host leaf certificates are minted on demand and cached, so what lands in your feed is the exact request and response your app saw.
- 04
Rows stream straight to your feed
Every captured pair is written directly to the shared entries table over the device's own long-lived pairing token — no files to pull, no sync step. The dashboard sees it the moment it lands.
The pipeline,
What actually runs when you flip capture on — and what never leaves the phone.
- Capture
- System-wide DNS + TCP via a NetworkExtension packet tunnel
- Decryption
- Selective, per-host SSL list with wildcard patterns — opt-in, never everything
- MITM engine
- per-host leaf certificates · RSA-2048
- Pairing
- 365-day device token claimed at pairing — capture keeps streaming without re-login
- Live control
- Realtime push for settings, SSL lists, VPN on/off, breakpoints and resends — applied in seconds, over the air
- Alternate mode
- PAC proxy mode routes the phone through the shared MITM proxy instead of the on-device tunnel
- Requirements
- An iPhone. No Mac, no jailbreak, no computer in the loop
iOS questions,
Do I need a Mac or any computer?
No. Capture, decryption and streaming all run on the iPhone itself — the phone is the debugger. You watch and control it from the web dashboard on any screen.
Does it decrypt everything on my phone?
No. TLS is opened only for hosts you explicitly add to the SSL-proxying list; every other connection passes through encrypted and untouched. The list is yours, editable live from the dashboard.
How do changes reach the phone without an app update?
The app is server-driven by design: rules, scripts, mocks, SSL lists and even the VPN toggle push to the device over a live Realtime connection. Behaviour changes in seconds — no rebuild, no App Store review cycle.
What about HTTP/3 (QUIC) traffic?
QUIC is not intercepted: the tunnel declines UDP/443 (and counts it), so apps fall back to HTTPS over TCP — where selective decryption and capture work normally.