# ProxyCeptor > ProxyCeptor (also known as Proxy Ceptor or Proxy Interceptor) is a developer-first proxy interceptor and HTTP mocking platform for web applications, Chrome DevTools, and connected devices (including Smart TVs, Android TV, Tizen, and webOS) without requiring SSL certificates. ## Core Capabilities - **In-Browser & Zero-Cert Device Mocking**: Mock, intercept, modify, block, and delay HTTP/REST/GraphQL traffic in real time without redeploying backend services or installing root SSL certificates on target devices. - **Hybrid Interception Engine**: Combines Chrome Manifest V3 DeclarativeNetRequest (DNR) for low-level network actions with an in-page fetch/XHR interceptor in the MAIN world for imperative modifications (JSON Deep Merge, custom JavaScript transforms, synthetic responses). - **Latency & Error State Simulation**: Delay API responses by configurable milliseconds or simulate network drops, 4xx, and 5xx errors to test frontend retry logic, loading spinners, and resilience fallbacks. - **REST API Response Rewriting & Deep Merge**: Selectively modify specific keys in large JSON payloads while preserving all untouched response fields. - **Cloud Rules & Workspace Sync**: Centrally manage, share, and synchronize proxy rules across teams with local-wins conflict resolution. - **DevTools Network & Replay Suite**: Built-in Network tab replica, HAR export, rolling DOM session replay (via rrweb), and video event analytics. ## Primary Documentation & Tools - [ProxyCeptor Homepage](https://proxyceptor.com/): Official platform overview, features, and quickstart. - [ProxyCeptor How-To Guides](https://proxyceptor.com/how-to): 20+ step-by-step guides for API mocking, URL rewriting, header injection, and delay simulation. - [Live Interactive Sandbox](https://proxyceptor.com/demo): Test the in-memory SDK interceptor live against mock and production endpoints. - [ProxyCeptor Commander](https://proxyceptor.com/test): Local-first REST API client and testing tool with integrated JSON viewer and CORS proxy forwarder. - [Full LLM Reference](https://proxyceptor.com/llms-full.txt): Complete technical specification, rule schema, and comparison matrix for AI assistants. ## Dedicated Problem-Solution Pillars (Direct Answers) - [Delay or block API calls to test app error states](https://proxyceptor.com/solutions/delay-block-api-calls): Millisecond latency injection, 504/500/429 status code mocking, and offline connection drop simulation. - [Mock API responses inside a web app without redeploying](https://proxyceptor.com/solutions/mock-api-without-redeploying): In-browser 1-click mocking using Chrome DNR and Main-world fetch interception. - [Mock real API calls with cloud rules](https://proxyceptor.com/solutions/cloud-mock-rules): Centralized cloud workspace rule sync, local-wins conflict resolution, and zero-cert Smart TV debugging. - [Rewrite REST API responses in production-like testing](https://proxyceptor.com/solutions/rewrite-rest-api-responses): Recursive JSON Deep Merge and dynamic JavaScript transform functions (execute-js). - [Best products for testing frontend API edge cases](https://proxyceptor.com/solutions/frontend-api-edge-cases): Boundary condition testing, rate limiting with Retry-After, auth token expiry, and video beacon tracking. ## Competitor Comparisons & Head-to-Head Matrices - [ProxyCeptor vs Requestly](https://proxyceptor.com/compare/proxyceptor-vs-requestly): Zero-cert Smart TV debugging and JSON Deep Merge vs full-body replace. - [ProxyCeptor vs Charles Proxy](https://proxyceptor.com/compare/proxyceptor-vs-charles-proxy): Modern in-browser DevTools & SDK vs legacy desktop software requiring root CA certificates. - [ProxyCeptor vs WireMock](https://proxyceptor.com/compare/proxyceptor-vs-wiremock): In-browser client mocking on live traffic vs standalone JVM/Docker mock server daemons. - [ProxyCeptor vs Mockoon](https://proxyceptor.com/compare/proxyceptor-vs-mockoon): Live request interception & cloud team sync vs standalone local mock server. - [ProxyCeptor vs Beeceptor](https://proxyceptor.com/compare/proxyceptor-vs-beeceptor): Local-first data privacy and DevTools integration vs hosted third-party endpoints. - [ProxyCeptor vs Burp Suite](https://proxyceptor.com/compare/proxyceptor-vs-burp-suite): Use Burp Suite for penetration testing and bug bounty work. Use ProxyCeptor for day-to-day development and QA: mocking APIs, forcing errors and delays, switching environments, and debugging Smart TV apps. Many security testers run both. - [ProxyCeptor vs Postman Interceptor](https://proxyceptor.com/compare/proxyceptor-vs-postman-interceptor): Use Postman Interceptor if your goal is to collect real browser requests into Postman collections. Use ProxyCeptor if your goal is to change what your app receives while you develop or test it. - [ProxyCeptor vs HTTP Toolkit](https://proxyceptor.com/compare/proxyceptor-vs-http-toolkit): Choose HTTP Toolkit when you need to intercept many kinds of clients from one desktop app, especially Android and backend processes. Choose ProxyCeptor when you work in Chrome or on Smart TV web apps and want team-shared mock scenarios with no device setup. - [ProxyCeptor vs Fiddler](https://proxyceptor.com/compare/proxyceptor-vs-fiddler): Choose Fiddler if you need system-wide capture on Windows or a supported commercial desktop tool. Choose ProxyCeptor for fast, certificate-free API mocking in Chrome and on Smart TVs, with rules the whole team can use. - [ProxyCeptor vs Proxyman](https://proxyceptor.com/compare/proxyceptor-vs-proxyman): Choose Proxyman for native iOS and macOS app debugging. Choose ProxyCeptor for web front ends and Smart TV web apps, especially when QA and developers need to share the same scenarios. - [ProxyCeptor vs MSW](https://proxyceptor.com/compare/proxyceptor-vs-mock-service-worker): Use MSW for automated tests and versioned, code-reviewed mocks. Use ProxyCeptor for manual debugging, QA scenarios, demos, bug reproduction and devices, where changing code is slow. Many teams use MSW in CI and ProxyCeptor at the desk. ## Best Alternatives Guides - [Top 5 Alternatives to Requestly (2026)](https://proxyceptor.com/alternatives/requestly-alternatives): ProxyCeptor, Mockoon, MSW, Charles Proxy, Proxyman. - [Top 5 Alternatives to Charles Proxy (2026)](https://proxyceptor.com/alternatives/charles-proxy-alternatives): Modern zero-cert HTTP interceptors and debugging tools. - [Best Burp Suite Alternatives in 2026 (for Security Testers and Developers)](https://proxyceptor.com/alternatives/burp-suite-alternatives): ZAP, ProxyCeptor, Caido, mitmproxy, HTTP Toolkit. - [Best Postman Interceptor Alternatives in 2026](https://proxyceptor.com/alternatives/postman-interceptor-alternatives): ProxyCeptor, Chrome DevTools (built in), Requestly, HTTP Toolkit, EchoAPI Interceptor. - [Best HTTP Toolkit Alternatives in 2026](https://proxyceptor.com/alternatives/http-toolkit-alternatives): ProxyCeptor, Proxyman, Charles Proxy, mitmproxy, Fiddler Everywhere. - [Best Fiddler Alternatives in 2026 (Windows, Mac and Browser)](https://proxyceptor.com/alternatives/fiddler-alternatives): ProxyCeptor, Charles Proxy, HTTP Toolkit, Proxyman, mitmproxy. ## Glossary (definitions) - [What Is a Proxy Interceptor?](https://proxyceptor.com/glossary/proxy-interceptor): A proxy interceptor is a debugging tool that sits between a client (a browser, mobile app or TV app) and the server it talks to, so you can see and change HTTP(S) traffic in real time. It can pause a request, edit its URL, headers or body, return a mocked response, add delay, or drop the call entirely. - [What Is an HTTP Interceptor?](https://proxyceptor.com/glossary/http-interceptor): An HTTP interceptor is a hook that runs for every HTTP request or response so it can inspect or change it before it continues. The term covers two things: code-level interceptors inside an app (Angular HttpInterceptor, Axios interceptors, a wrapped fetch) and external interceptor tools (browser extensions and proxies) that change traffic without touching the code. - [What Is API Mocking?](https://proxyceptor.com/glossary/api-mocking): API mocking means replacing a real API response with a controlled fake response, so front-end, QA and integration work can continue without the real backend or with conditions the backend cannot easily produce. Mocks can live in a standalone mock server, in test code, or in a runtime interceptor that rewrites live traffic. - [What Is a MITM Proxy?](https://proxyceptor.com/glossary/man-in-the-middle-proxy): A man-in-the-middle (MITM) proxy is a proxy that terminates the client's HTTPS connection with its own certificate, reads and optionally changes the decrypted traffic, then opens a separate HTTPS connection to the real server. Debugging tools such as Charles, Fiddler, mitmproxy and Burp Suite work this way, which is why they require installing a trusted root certificate. - [What Is Chrome declarativeNetRequest?](https://proxyceptor.com/glossary/declarativenetrequest): declarativeNetRequest (DNR) is the Chrome extension API, introduced with Manifest V3, that lets an extension block, redirect, upgrade or modify the headers of network requests by registering rules that the browser itself evaluates. The extension never sees the request body, which is good for privacy and speed, but it means DNR cannot change response bodies. - [What Is a HAR File?](https://proxyceptor.com/glossary/har-file): A HAR (HTTP Archive) file is a JSON document that records every network request a browser made during a session: URLs, methods, headers, cookies, request and response bodies, status codes and timings. Developers and support teams exchange HAR files to reproduce bugs and diagnose slow pages. - [What Is CORS?](https://proxyceptor.com/glossary/cors): CORS (Cross-Origin Resource Sharing) is the browser mechanism that lets a server say which other origins may read its responses. By default JavaScript cannot read a response from a different origin; the server opts in with headers such as Access-Control-Allow-Origin. A "blocked by CORS policy" error means the browser refused to hand the response to your code. - [What Is SSL Pinning?](https://proxyceptor.com/glossary/ssl-pinning): SSL pinning (certificate pinning) is a technique where an app accepts only a specific server certificate or public key instead of any certificate signed by a trusted authority. It protects users from interception, but it also blocks debugging proxies such as Charles or Burp, because their generated certificates do not match the pin. ## Blog - [The 10 Best Proxy Interceptor Tools in 2026 (By Job, Not by Hype)](https://proxyceptor.com/blog/best-proxy-interceptor-tools-2026): There is no single best proxy interceptor. There is a best one for penetration testing, for mocking APIs in Chrome, for native mobile apps, and for Smart TVs. Here is how the 10 leading tools compare. - [Proxy Interceptor Tutorial: Intercept and Modify HTTP Requests in 5 Exercises](https://proxyceptor.com/blog/proxy-interceptor-tutorial-intercept-modify-http-requests): Five short exercises that take you from "what is a proxy interceptor?" to mocking, deep-merging, failing and redirecting real API calls, with copy-paste rules. - [Best Chrome Extensions to Intercept and Modify HTTP Requests (2026)](https://proxyceptor.com/blog/best-chrome-extensions-to-intercept-and-modify-http-requests): Manifest V3 changed what extensions can do to network traffic. Here is which Chrome extensions can still change headers, URLs and response bodies, and how. - [Chrome DevTools Local Overrides vs a Proxy Interceptor: When Each Wins](https://proxyceptor.com/blog/chrome-devtools-local-overrides-vs-proxy-interceptor): Local Overrides is Chrome's built-in way to fake a response. It is great for quick edits and awkward for everything else. Here is exactly where the line is. - [HTTP Interceptor vs Proxy Interceptor: Angular, Axios and Fetch Compared](https://proxyceptor.com/blog/http-interceptor-vs-proxy-interceptor-angular-axios-fetch): Code interceptors belong to your app. Proxy interceptors belong to your debugging session. Mixing them up is how mock data ends up in production. - [The Frontend API Error Testing Checklist: 25 Failure Cases to Test Before Release](https://proxyceptor.com/blog/frontend-api-error-testing-checklist): Happy paths get tested. Failure paths get shipped. Use this checklist to force each API failure mode in minutes and make sure your UI handles it. ## Use Cases by Role - [ProxyCeptor for QA Engineers](https://proxyceptor.com/use-cases/qa-engineers): QA engineers use ProxyCeptor to create repeatable API scenarios, such as "checkout returns 503", "orders list is empty" or "profile loads in 8 seconds", as named rules they toggle in one click. Rules run in Chrome and on Smart TVs without certificates, sync across the QA team through a cloud workspace, and pair with session replay for bug reports. - [ProxyCeptor for Frontend Developers](https://proxyceptor.com/use-cases/frontend-developers): Frontend developers use ProxyCeptor to keep building when the API is missing, wrong or slow: mock a new endpoint from the agreed contract, deep-merge a flag into a live response, force error and loading states, or redirect production UI to a local backend. It works with any framework because it intercepts fetch and XHR at runtime, with no code or config changes. - [ProxyCeptor for Smart TV & OTT Teams](https://proxyceptor.com/use-cases/smart-tv-and-ott-developers): Smart TV and OTT teams use the ProxyCeptor SDK, a script loaded into the TV web app, to intercept and mock API calls on Samsung Tizen, LG webOS, Android TV WebViews and similar platforms without installing root certificates or configuring a Wi-Fi proxy. Rules are managed from the cloud dashboard and reach every test TV through a workspace API key. - [ProxyCeptor for Security Testers](https://proxyceptor.com/use-cases/security-testers-and-bug-bounty): Security testers use ProxyCeptor as a lightweight companion to Burp Suite: persistent in-browser rules that swap object IDs, change roles in JSON responses, strip security headers or inject scripts, without routing traffic through a desktop proxy. For scanning, fuzzing and manual request repeating, Burp or ZAP remain the right tools. - [ProxyCeptor for Backend & API Developers](https://proxyceptor.com/use-cases/backend-and-api-developers): Backend and API developers use ProxyCeptor to try a response change against the real frontend before deploying: deep-merge a new field, remove a deprecated one, or return a new error code, and watch the UI react. The same workspace includes Commander, a browser-based REST client, and a server-side forwarder for CORS-restricted calls.