What Is a MITM Proxy? Man-in-the-Middle Proxies for Debugging
A man-in-the-middle (MITM) proxy is a proxy that terminates the client's HTTPS connection with its own certificate, reads and optionally changes the decrypted traffic, then opens a separate HTTPS connection to the real server. Debugging tools such as Charles, Fiddler, mitmproxy and Burp Suite work this way, which is why they require installing a trusted root certificate.
Also called: MITM proxy, man in the middle proxy, SSL proxy, TLS interception proxy, debugging proxy
How HTTPS interception works step by step
- You install the proxy's root CA certificate on the device and mark it trusted.
- The device sends its traffic to the proxy (system proxy setting, Wi-Fi proxy, or VPN).
- When the app connects to
api.example.com, the proxy generates a certificate for that hostname on the fly, signed by its root CA. - The app trusts it (because of step 1), so the TLS handshake succeeds with the proxy.
- The proxy decrypts, shows and optionally edits the request, then re-encrypts it towards the real server.
Where MITM proxies struggle
- Devices that will not trust your CA: many Smart TVs and streaming boxes have no user certificate store. Android apps targeting API level 24+ ignore user-installed CAs unless their network security config opts in.
- Certificate pinning: apps that pin their server's key reject the proxy's certificate. See SSL pinning.
- HTTP/3 and QUIC: traffic over UDP may bypass an HTTP proxy unless the client falls back to TCP.
- Team friction: every tester has to install and trust a certificate, and rules usually live in one person's desktop app.
MITM without certificates: interception inside the app
If you control the front-end code (a website, a Smart TV web app, a hybrid WebView app), you can intercept before the request is encrypted. That is what ProxyCeptor does: the Chrome extension and the in-app SDK hook fetch and XMLHttpRequest inside the page, so TLS is never broken and no certificate is installed.
ProxyCeptor also offers a server-side forwarder (/mitm) that acts as a transparent reverse proxy: the client sends the request to ProxyCeptor with an x-target-url header, workspace rules are applied, and the upstream response is streamed back with CORS headers. That is useful for CORS-restricted APIs and for rewriting HLS video playlists.
Frequently asked questions
Is a MITM proxy a security attack?
The technique is the same one attackers use, which is why browsers warn about unknown certificates. As a debugging tool on your own devices and traffic it is standard practice.
Which MITM proxy is best?
mitmproxy is free and scriptable, Charles and Fiddler are long-standing desktop tools, Proxyman is strong on macOS and iOS, HTTP Toolkit is open source and cross-platform, and Burp Suite leads for security testing.
How do I debug HTTPS on a Smart TV without a certificate?
Load an in-app interceptor such as the ProxyCeptor SDK into the TV web app. See debugging Smart TV apps without SSL certificates.
Keep learning
Intercept your first request in under a minute
Create a free ProxyCeptor account to mock, delay, block and rewrite API traffic, then share the same rules with your team.