Behind the curtainEngineeringยท8 min read

Behind the Curtain: Why ProxyCeptor Is Built the Way It Is

The unpolished version.

The decisions we made on purpose, the constraints that forced our hand, and why one small JSON shape ended up running everywhere.

The unpolished summary

  • Chrome lets extensions change headers and redirects via declarativeNetRequest, but not bodies.
  • So bodies are handled by hooking fetch/XHR inside the page.
  • One ProxyRule shape runs in the extension, the SDK, the server-side engine and the dashboard.

Constraint one: Manifest V3 does not let you touch bodies

Chrome's declarativeNetRequest API can block, redirect and modify headers, but the extension never sees a response body. If a product promises to change response bodies, it has to do it somewhere else.

Our answer is a two-part engine. DNR handles what it can (blocking, redirects, headers). A script in the page's main world hooks fetch and XHR for body mocking, merging, transforms, request edits and delays. One rule can use both.

Page makes a requestfetch / XHR / resource
In-page hookBodies, delays, JS transforms
DNR rulesBlock, redirect, headers
NetworkOr the mock answers

Constraint two: not every device is a browser with an extension

Smart TVs and embedded apps cannot install a Chrome extension or trust a custom certificate. So the same rules can also run inside the app through a small SDK, or on the server through a MITM-style route, without anything installed on the device.

One rule shape, three places to run it. That is the only reason the product stayed small.

Arun Gupta

Boring choices we are proud of

  • No build step in the extension: plain JavaScript you can read.
  • If a body transform fails, the page gets the original response, never a broken one.
  • Captured traffic stays local. The only outbound calls are ones the user configures.
  • Docs must match code. When they disagree, we fix the docs in the same change.

Frequently asked questions

Do I need to install a certificate?

Not for the extension or the in-app SDK. Those work inside the browser or app, so no proxy certificate is involved.

Written by

Arun Gupta CEO

Arun runs ProxyCeptor and sets its direction: developer tools that respect people's time and never pretend a hard problem is easy. He writes about the bets behind the product, what the team chose not to build, and the industry shifts that change how web and TV apps get shipped. Expect short sentences, a clear opinion and exactly one joke.

โ€œShip it, then measure it.โ€

More from Arun โ†’

Read next

Intercept your first request in under a minute

Create a free ProxyCeptor account to mock, delay, block and rewrite API traffic, then share the same rules with your team.

๐Ÿš€ Mock, delay and break API calls in ChromeTry ProxyCeptor free