Glossary

What Is a MITM Proxy? Man-in-the-Middle Proxies for Debugging

Definition: Man-in-the-Middle (MITM) Proxy

A man-in-the-middle (MITM) proxy is a proxy that terminates the client's HTTPS connection with its own certificate, reads and optionally changes the decrypted traffic, then opens a separate HTTPS connection to the real server. Debugging tools such as Charles, Fiddler, mitmproxy and Burp Suite work this way, which is why they require installing a trusted root certificate.

Also called: MITM proxy, man in the middle proxy, SSL proxy, TLS interception proxy, debugging proxy

How HTTPS interception works step by step

  1. You install the proxy's root CA certificate on the device and mark it trusted.
  2. The device sends its traffic to the proxy (system proxy setting, Wi-Fi proxy, or VPN).
  3. When the app connects to api.example.com, the proxy generates a certificate for that hostname on the fly, signed by its root CA.
  4. The app trusts it (because of step 1), so the TLS handshake succeeds with the proxy.
  5. The proxy decrypts, shows and optionally edits the request, then re-encrypts it towards the real server.

Where MITM proxies struggle

  • Devices that will not trust your CA: many Smart TVs and streaming boxes have no user certificate store. Android apps targeting API level 24+ ignore user-installed CAs unless their network security config opts in.
  • Certificate pinning: apps that pin their server's key reject the proxy's certificate. See SSL pinning.
  • HTTP/3 and QUIC: traffic over UDP may bypass an HTTP proxy unless the client falls back to TCP.
  • Team friction: every tester has to install and trust a certificate, and rules usually live in one person's desktop app.

MITM without certificates: interception inside the app

If you control the front-end code (a website, a Smart TV web app, a hybrid WebView app), you can intercept before the request is encrypted. That is what ProxyCeptor does: the Chrome extension and the in-app SDK hook fetch and XMLHttpRequest inside the page, so TLS is never broken and no certificate is installed.

ProxyCeptor also offers a server-side forwarder (/mitm) that acts as a transparent reverse proxy: the client sends the request to ProxyCeptor with an x-target-url header, workspace rules are applied, and the upstream response is streamed back with CORS headers. That is useful for CORS-restricted APIs and for rewriting HLS video playlists.

Certificate-free interception only works for apps whose JavaScript you can load a script into. For a closed native app you do not control, a classic MITM proxy is still the right tool.

Frequently asked questions

Is a MITM proxy a security attack?

The technique is the same one attackers use, which is why browsers warn about unknown certificates. As a debugging tool on your own devices and traffic it is standard practice.

Which MITM proxy is best?

mitmproxy is free and scriptable, Charles and Fiddler are long-standing desktop tools, Proxyman is strong on macOS and iOS, HTTP Toolkit is open source and cross-platform, and Burp Suite leads for security testing.

How do I debug HTTPS on a Smart TV without a certificate?

Load an in-app interceptor such as the ProxyCeptor SDK into the TV web app. See debugging Smart TV apps without SSL certificates.

Keep learning

Intercept your first request in under a minute

Create a free ProxyCeptor account to mock, delay, block and rewrite API traffic, then share the same rules with your team.