How it works
An intercepting proxy such as Burp Suite, mitmproxy, ZAP (formerly OWASP ZAP), Charles or Fiddler runs on the tester's computer, and the browser, phone or app under test is pointed at it. Every HTTP request passes through, so it can be read, paused, edited and replayed. To read HTTPS, the tester installs the proxy's own certificate authority on the test device, which lets the proxy decrypt and re-encrypt the traffic; a device without that certificate shows warnings instead, which is exactly what TLS is designed to do.
The main lesson is that anything the client sends can be changed. If a price, a user id or an 'is admin' flag travels from the app and the server trusts it, anyone with a proxy can alter it. Interception also shows whether an app leaks tokens or personal data, and what its third-party SDKs send. Browser DevTools cover the basics for websites; proxies add editing, replay, automated scanning and mobile apps.
Mobile platforms make it harder on purpose: apps built for Android 7 and later ignore user-installed certificates unless their network security configuration allows them, and apps with certificate pinning accept only their own server's certificate. Teams usually allow interception in debug builds of their own apps. It is legitimate on your own devices and systems, or ones you have written permission to test; intercepting other people's traffic without consent is against the law in most places.
Traffic interception pros and cons
Pros
- Shows exactly what an app sends and receives
- Edit and replay requests to test the server's own checks
- Reveals leaked tokens, personal data and chatty SDKs
- Capable free options: mitmproxy, ZAP and Burp Suite Community
Cons
- HTTPS needs a trusted certificate installed on the test device
- Certificate pinning and Android defaults block it in release builds
- Burp Suite's scanner and full-speed Intruder need the paid Professional edition
- Only lawful on systems you own or have permission to test
When to use Traffic interception
Pick it when
- Debugging what a web or mobile app really sends to its API
- Security testing your own app before a release
- Checking what data third-party SDKs in your app send out
Skip it when
- The browser's DevTools network panel already shows what you need
- You do not have permission to test the system
Traffic interception pricing
Open source
mitmproxy and ZAP are free and open source, and Burp Suite Community Edition is free. Burp Suite Professional costs about $499 per user a year.
Traffic interception pricing page (opens in a new tab)Approximate, checked September 2026.What the other tools cost
Related terms
More in Security
Testing and research