01
workspace://projects
Project management
Switch between targets without leaving the app. Projects keep each engagement isolated, so your history, scope and replay sessions stay where you left them.

GET /api/v2/session/refresh HTTP/1.1 Host: app.example.com User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 Accept: application/json, text/plain, */* Accept-Encoding: gzip, deflate, br Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiI4ODE0MiIsInJvbGUiOiJ1c2VyIn0 Cookie: sid=8f2b9c1ad4e7; csrf=9d31ba77c0; ab_bucket=control
Connection: keep-alive HTTP/1.1 200 OK Content-Type: application/json; charset=utf-8 Content-Length: 1183 Set-Cookie: sid=1a77f0c9e2; Path=/; HttpOnly; Secure; SameSite=Lax X-Request-Id: 7f21c0e4-4d1a-4a77-9d0c-3b8f2c61aa10 Cache-Control: no-store {"ok":true,"user":{"id":88142,"role":"user","scopes":["read:profile","write:notes"]}} POST /api/v2/orders HTTP/1.1 Host: api.example.com Content-Type: application/json
Content-Length: 214 Origin: https://app.example.com Referer: https://app.example.com/checkout {"item_id":9931,"qty":2,"coupon":"SPRING25","address_id":4471} HTTP/1.1 201 Created Location: /api/v2/orders/60218 X-RateLimit-Remaining: 47 {"order_id":60218,"total":"148.00","currency":"USD","status":"pending"} POST /graphql HTTP/1.1 Host: api.example.com Content-Type: application/json {"query":"query Me { viewer { id email roles permissions } }"}
HTTP/1.1 403 Forbidden Content-Type: application/json {"error":"insufficient_scope","required":"admin:read"} GET /assets/js/main.4f21ab9c.js HTTP/1.1 If-None-Match: W/"4f21ab9c" HTTP/1.1 304 Not Modified GET /api/v2/users/88142/exports?format=csv&range=90d HTTP/1.1 Host: api.example.com Authorization: Bearer eyJhbGciOiJIUzI1NiIsImtpZCI6IjIwMjQtMDgifQ.eyJzdWIiOiI4ODE0MiJ9 HTTP/1.1 302 Found Location: https://login.example.com/oauth/authorize?client_id=web&response_type=code
PUT /api/v2/notes/7741 HTTP/1.1 Content-Type: application/json X-CSRF-Token: 9d31ba77c0 {"title":"scoped recon","body":"host: *.example.com","visibility":"private"} HTTP/1.1 500 Internal Server Error Content-Type: application/json {"error":"upstream_timeout","upstream":"orders-svc","retry_after":2} GET /.well-known/openid-configuration HTTP/1.1 Host: login.example.com HTTP/1.1 200 OK
{"issuer":"https://login.example.com","token_endpoint":"/oauth/token"} POST /api/v2/orders HTTP/1.1 Host: api.example.com Content-Type: application/json Content-Length: 214 Origin: https://app.example.com Referer: https://app.example.com/checkout {"item_id":9931,"qty":2,"coupon":"SPRING25","address_id":4471} HTTP/1.1 201 Created Location: /api/v2/orders/60218 X-RateLimit-Remaining: 47 {"order_id":60218,"total":"148.00","currency":"USD","status":"pending"}
POST /graphql HTTP/1.1 Host: api.example.com Content-Type: application/json {"query":"query Me { viewer { id email roles permissions } }"} HTTP/1.1 403 Forbidden Content-Type: application/json {"error":"insufficient_scope","required":"admin:read"} GET /assets/js/main.4f21ab9c.js HTTP/1.1 If-None-Match: W/"4f21ab9c" HTTP/1.1 304 Not Modified GET /api/v2/users/88142/exports?format=csv&range=90d HTTP/1.1
Host: api.example.com Authorization: Bearer eyJhbGciOiJIUzI1NiIsImtpZCI6IjIwMjQtMDgifQ.eyJzdWIiOiI4ODE0MiJ9 HTTP/1.1 302 Found Location: https://login.example.com/oauth/authorize?client_id=web&response_type=code PUT /api/v2/notes/7741 HTTP/1.1 Content-Type: application/json X-CSRF-Token: 9d31ba77c0 {"title":"scoped recon","body":"host: *.example.com","visibility":"private"} HTTP/1.1 500 Internal Server Error Content-Type: application/json
{"error":"upstream_timeout","upstream":"orders-svc","retry_after":2} GET /.well-known/openid-configuration HTTP/1.1 Host: login.example.com HTTP/1.1 200 OK {"issuer":"https://login.example.com","token_endpoint":"/oauth/token"} GET /api/v2/session/refresh HTTP/1.1 Host: app.example.com User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36
Accept: application/json, text/plain, */* Accept-Encoding: gzip, deflate, br Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiI4ODE0MiIsInJvbGUiOiJ1c2VyIn0 Cookie: sid=8f2b9c1ad4e7; csrf=9d31ba77c0; ab_bucket=control Connection: keep-alive HTTP/1.1 200 OK Content-Type: application/json; charset=utf-8 Content-Length: 1183 Set-Cookie: sid=1a77f0c9e2; Path=/; HttpOnly; Secure; SameSite=Lax X-Request-Id: 7f21c0e4-4d1a-4a77-9d0c-3b8f2c61aa10
Cache-Control: no-store {"ok":true,"user":{"id":88142,"role":"user","scopes":["read:profile","write:notes"]}} HTTP/1.1 403 Forbidden Content-Type: application/json {"error":"insufficient_scope","required":"admin:read"} GET /assets/js/main.4f21ab9c.js HTTP/1.1 If-None-Match: W/"4f21ab9c" HTTP/1.1 304 Not Modified GET /api/v2/users/88142/exports?format=csv&range=90d HTTP/1.1
Host: api.example.com Authorization: Bearer eyJhbGciOiJIUzI1NiIsImtpZCI6IjIwMjQtMDgifQ.eyJzdWIiOiI4ODE0MiJ9 HTTP/1.1 302 Found Location: https://login.example.com/oauth/authorize?client_id=web&response_type=code PUT /api/v2/notes/7741 HTTP/1.1 Content-Type: application/json X-CSRF-Token: 9d31ba77c0 {"title":"scoped recon","body":"host: *.example.com","visibility":"private"} HTTP/1.1 500 Internal Server Error
Content-Type: application/json {"error":"upstream_timeout","upstream":"orders-svc","retry_after":2} GET /.well-known/openid-configuration HTTP/1.1 Host: login.example.com HTTP/1.1 200 OK {"issuer":"https://login.example.com","token_endpoint":"/oauth/token"} GET /api/v2/session/refresh HTTP/1.1 Host: app.example.com User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36
Accept: application/json, text/plain, */* Accept-Encoding: gzip, deflate, br Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiI4ODE0MiIsInJvbGUiOiJ1c2VyIn0 Cookie: sid=8f2b9c1ad4e7; csrf=9d31ba77c0; ab_bucket=control Connection: keep-alive HTTP/1.1 200 OK Content-Type: application/json; charset=utf-8 Content-Length: 1183 Set-Cookie: sid=1a77f0c9e2; Path=/; HttpOnly; Secure; SameSite=Lax
X-Request-Id: 7f21c0e4-4d1a-4a77-9d0c-3b8f2c61aa10 Cache-Control: no-store {"ok":true,"user":{"id":88142,"role":"user","scopes":["read:profile","write:notes"]}} POST /api/v2/orders HTTP/1.1 Host: api.example.com Content-Type: application/json Content-Length: 214 Origin: https://app.example.com Referer: https://app.example.com/checkout {"item_id":9931,"qty":2,"coupon":"SPRING25","address_id":4471} HTTP/1.1 201 Created
Location: /api/v2/orders/60218 X-RateLimit-Remaining: 47 {"order_id":60218,"total":"148.00","currency":"USD","status":"pending"} POST /graphql HTTP/1.1 Host: api.example.com Content-Type: application/json {"query":"query Me { viewer { id email roles permissions } }"} X-CSRF-Token: 9d31ba77c0 {"title":"scoped recon","body":"host: *.example.com","visibility":"private"} HTTP/1.1 500 Internal Server Error Content-Type: application/json {"error":"upstream_timeout","upstream":"orders-svc","retry_after":2}
GET /.well-known/openid-configuration HTTP/1.1 Host: login.example.com HTTP/1.1 200 OK {"issuer":"https://login.example.com","token_endpoint":"/oauth/token"} GET /api/v2/session/refresh HTTP/1.1 Host: app.example.com User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 Accept: application/json, text/plain, */* Accept-Encoding: gzip, deflate, br Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiI4ODE0MiIsInJvbGUiOiJ1c2VyIn0
Cookie: sid=8f2b9c1ad4e7; csrf=9d31ba77c0; ab_bucket=control Connection: keep-alive HTTP/1.1 200 OK Content-Type: application/json; charset=utf-8 Content-Length: 1183 Set-Cookie: sid=1a77f0c9e2; Path=/; HttpOnly; Secure; SameSite=Lax X-Request-Id: 7f21c0e4-4d1a-4a77-9d0c-3b8f2c61aa10 Cache-Control: no-store {"ok":true,"user":{"id":88142,"role":"user","scopes":["read:profile","write:notes"]}}
POST /api/v2/orders HTTP/1.1 Host: api.example.com Content-Type: application/json Content-Length: 214 Origin: https://app.example.com Referer: https://app.example.com/checkout {"item_id":9931,"qty":2,"coupon":"SPRING25","address_id":4471} HTTP/1.1 201 Created Location: /api/v2/orders/60218 X-RateLimit-Remaining: 47 {"order_id":60218,"total":"148.00","currency":"USD","status":"pending"} POST /graphql HTTP/1.1 Host: api.example.com
Content-Type: application/json {"query":"query Me { viewer { id email roles permissions } }"} HTTP/1.1 403 Forbidden Content-Type: application/json {"error":"insufficient_scope","required":"admin:read"} GET /assets/js/main.4f21ab9c.js HTTP/1.1 If-None-Match: W/"4f21ab9c" HTTP/1.1 304 Not Modified GET /api/v2/users/88142/exports?format=csv&range=90d HTTP/1.1 Host: api.example.com
Authorization: Bearer eyJhbGciOiJIUzI1NiIsImtpZCI6IjIwMjQtMDgifQ.eyJzdWIiOiI4ODE0MiJ9 HTTP/1.1 302 Found Location: https://login.example.com/oauth/authorize?client_id=web&response_type=code PUT /api/v2/notes/7741 HTTP/1.1 Content-Type: application/json Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiI4ODE0MiIsInJvbGUiOiJ1c2VyIn0 Cookie: sid=8f2b9c1ad4e7; csrf=9d31ba77c0; ab_bucket=control Connection: keep-alive
HTTP/1.1 200 OK Content-Type: application/json; charset=utf-8 Content-Length: 1183 Set-Cookie: sid=1a77f0c9e2; Path=/; HttpOnly; Secure; SameSite=Lax X-Request-Id: 7f21c0e4-4d1a-4a77-9d0c-3b8f2c61aa10 Cache-Control: no-store {"ok":true,"user":{"id":88142,"role":"user","scopes":["read:profile","write:notes"]}} POST /api/v2/orders HTTP/1.1 Host: api.example.com Content-Type: application/json Content-Length: 214
Origin: https://app.example.com Referer: https://app.example.com/checkout {"item_id":9931,"qty":2,"coupon":"SPRING25","address_id":4471} HTTP/1.1 201 Created Location: /api/v2/orders/60218 X-RateLimit-Remaining: 47 {"order_id":60218,"total":"148.00","currency":"USD","status":"pending"} POST /graphql HTTP/1.1 Host: api.example.com Content-Type: application/json {"query":"query Me { viewer { id email roles permissions } }"}
HTTP/1.1 403 Forbidden Content-Type: application/json {"error":"insufficient_scope","required":"admin:read"} GET /assets/js/main.4f21ab9c.js HTTP/1.1 If-None-Match: W/"4f21ab9c" HTTP/1.1 304 Not Modified GET /api/v2/users/88142/exports?format=csv&range=90d HTTP/1.1 Host: api.example.com Authorization: Bearer eyJhbGciOiJIUzI1NiIsImtpZCI6IjIwMjQtMDgifQ.eyJzdWIiOiI4ODE0MiJ9
HTTP/1.1 302 Found Location: https://login.example.com/oauth/authorize?client_id=web&response_type=code PUT /api/v2/notes/7741 HTTP/1.1 Content-Type: application/json X-CSRF-Token: 9d31ba77c0 {"title":"scoped recon","body":"host: *.example.com","visibility":"private"} HTTP/1.1 500 Internal Server Error Content-Type: application/json {"error":"upstream_timeout","upstream":"orders-svc","retry_after":2}
GET /.well-known/openid-configuration HTTP/1.1 Host: login.example.com HTTP/1.1 200 OK {"issuer":"https://login.example.com","token_endpoint":"/oauth/token"} GET /api/v2/session/refresh HTTP/1.1 Host: app.example.com User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 Accept: application/json, text/plain, */* Accept-Encoding: gzip, deflate, br Referer: https://app.example.com/checkout
{"item_id":9931,"qty":2,"coupon":"SPRING25","address_id":4471} HTTP/1.1 201 Created Location: /api/v2/orders/60218 X-RateLimit-Remaining: 47 {"order_id":60218,"total":"148.00","currency":"USD","status":"pending"} POST /graphql HTTP/1.1 Host: api.example.com Content-Type: application/json {"query":"query Me { viewer { id email roles permissions } }"} HTTP/1.1 403 Forbidden Content-Type: application/json
{"error":"insufficient_scope","required":"admin:read"} GET /assets/js/main.4f21ab9c.js HTTP/1.1 If-None-Match: W/"4f21ab9c" HTTP/1.1 304 Not Modified GET /api/v2/users/88142/exports?format=csv&range=90d HTTP/1.1 Host: api.example.com Authorization: Bearer eyJhbGciOiJIUzI1NiIsImtpZCI6IjIwMjQtMDgifQ.eyJzdWIiOiI4ODE0MiJ9 HTTP/1.1 302 Found Location: https://login.example.com/oauth/authorize?client_id=web&response_type=code
PUT /api/v2/notes/7741 HTTP/1.1 Content-Type: application/json X-CSRF-Token: 9d31ba77c0 {"title":"scoped recon","body":"host: *.example.com","visibility":"private"} HTTP/1.1 500 Internal Server Error Content-Type: application/json {"error":"upstream_timeout","upstream":"orders-svc","retry_after":2} GET /.well-known/openid-configuration HTTP/1.1 Host: login.example.com HTTP/1.1 200 OK {"issuer":"https://login.example.com","token_endpoint":"/oauth/token"}
GET /api/v2/session/refresh HTTP/1.1 Host: app.example.com User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 Accept: application/json, text/plain, */* Accept-Encoding: gzip, deflate, br Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiI4ODE0MiIsInJvbGUiOiJ1c2VyIn0 Cookie: sid=8f2b9c1ad4e7; csrf=9d31ba77c0; ab_bucket=control
Connection: keep-alive HTTP/1.1 200 OK Content-Type: application/json; charset=utf-8 Content-Length: 1183 Set-Cookie: sid=1a77f0c9e2; Path=/; HttpOnly; Secure; SameSite=Lax X-Request-Id: 7f21c0e4-4d1a-4a77-9d0c-3b8f2c61aa10 Cache-Control: no-store {"ok":true,"user":{"id":88142,"role":"user","scopes":["read:profile","write:notes"]}} POST /api/v2/orders HTTP/1.1 Host: api.example.com Content-Type: application/json
Content-Length: 214 Origin: https://app.example.com GET /assets/js/main.4f21ab9c.js HTTP/1.1 If-None-Match: W/"4f21ab9c" HTTP/1.1 304 Not Modified GET /api/v2/users/88142/exports?format=csv&range=90d HTTP/1.1 Host: api.example.com Authorization: Bearer eyJhbGciOiJIUzI1NiIsImtpZCI6IjIwMjQtMDgifQ.eyJzdWIiOiI4ODE0MiJ9 HTTP/1.1 302 Found Location: https://login.example.com/oauth/authorize?client_id=web&response_type=code
PUT /api/v2/notes/7741 HTTP/1.1 Content-Type: application/json X-CSRF-Token: 9d31ba77c0 {"title":"scoped recon","body":"host: *.example.com","visibility":"private"} HTTP/1.1 500 Internal Server Error Content-Type: application/json {"error":"upstream_timeout","upstream":"orders-svc","retry_after":2} GET /.well-known/openid-configuration HTTP/1.1 Host: login.example.com HTTP/1.1 200 OK {"issuer":"https://login.example.com","token_endpoint":"/oauth/token"}
GET /api/v2/session/refresh HTTP/1.1 Host: app.example.com User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 Accept: application/json, text/plain, */* Accept-Encoding: gzip, deflate, br Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiI4ODE0MiIsInJvbGUiOiJ1c2VyIn0 Cookie: sid=8f2b9c1ad4e7; csrf=9d31ba77c0; ab_bucket=control Connection: keep-alive
HTTP/1.1 200 OK Content-Type: application/json; charset=utf-8 Content-Length: 1183 Set-Cookie: sid=1a77f0c9e2; Path=/; HttpOnly; Secure; SameSite=Lax X-Request-Id: 7f21c0e4-4d1a-4a77-9d0c-3b8f2c61aa10 Cache-Control: no-store {"ok":true,"user":{"id":88142,"role":"user","scopes":["read:profile","write:notes"]}} POST /api/v2/orders HTTP/1.1 Host: api.example.com Content-Type: application/json
Content-Length: 214 Origin: https://app.example.com Referer: https://app.example.com/checkout {"item_id":9931,"qty":2,"coupon":"SPRING25","address_id":4471} HTTP/1.1 201 Created Location: /api/v2/orders/60218 X-RateLimit-Remaining: 47 {"order_id":60218,"total":"148.00","currency":"USD","status":"pending"} POST /graphql HTTP/1.1 Host: api.example.com Content-Type: application/json {"query":"query Me { viewer { id email roles permissions } }"}
HTTP/1.1 403 Forbidden Content-Type: application/json {"error":"insufficient_scope","required":"admin:read"} {"error":"upstream_timeout","upstream":"orders-svc","retry_after":2} GET /.well-known/openid-configuration HTTP/1.1 Host: login.example.com HTTP/1.1 200 OK {"issuer":"https://login.example.com","token_endpoint":"/oauth/token"} GET /api/v2/session/refresh HTTP/1.1 Host: app.example.com User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36
Accept: application/json, text/plain, */* Accept-Encoding: gzip, deflate, br Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiI4ODE0MiIsInJvbGUiOiJ1c2VyIn0 Cookie: sid=8f2b9c1ad4e7; csrf=9d31ba77c0; ab_bucket=control Connection: keep-alive HTTP/1.1 200 OK Content-Type: application/json; charset=utf-8 Content-Length: 1183 Set-Cookie: sid=1a77f0c9e2; Path=/; HttpOnly; Secure; SameSite=Lax X-Request-Id: 7f21c0e4-4d1a-4a77-9d0c-3b8f2c61aa10
Cache-Control: no-store {"ok":true,"user":{"id":88142,"role":"user","scopes":["read:profile","write:notes"]}} POST /api/v2/orders HTTP/1.1 Host: api.example.com Content-Type: application/json Content-Length: 214 Origin: https://app.example.com Referer: https://app.example.com/checkout {"item_id":9931,"qty":2,"coupon":"SPRING25","address_id":4471} HTTP/1.1 201 Created Location: /api/v2/orders/60218
X-RateLimit-Remaining: 47 {"order_id":60218,"total":"148.00","currency":"USD","status":"pending"} POST /graphql HTTP/1.1 Host: api.example.com Content-Type: application/json {"query":"query Me { viewer { id email roles permissions } }"} HTTP/1.1 403 Forbidden Content-Type: application/json {"error":"insufficient_scope","required":"admin:read"} GET /assets/js/main.4f21ab9c.js HTTP/1.1 If-None-Match: W/"4f21ab9c"
HTTP/1.1 304 Not Modified GET /api/v2/users/88142/exports?format=csv&range=90d HTTP/1.1 Host: api.example.com Authorization: Bearer eyJhbGciOiJIUzI1NiIsImtpZCI6IjIwMjQtMDgifQ.eyJzdWIiOiI4ODE0MiJ9 HTTP/1.1 302 Found Location: https://login.example.com/oauth/authorize?client_id=web&response_type=code PUT /api/v2/notes/7741 HTTP/1.1 Content-Type: application/json
X-CSRF-Token: 9d31ba77c0 {"title":"scoped recon","body":"host: *.example.com","visibility":"private"} HTTP/1.1 500 Internal Server Error Content-Type: application/json Content-Type: application/json; charset=utf-8 Content-Length: 1183 Set-Cookie: sid=1a77f0c9e2; Path=/; HttpOnly; Secure; SameSite=Lax X-Request-Id: 7f21c0e4-4d1a-4a77-9d0c-3b8f2c61aa10 Cache-Control: no-store {"ok":true,"user":{"id":88142,"role":"user","scopes":["read:profile","write:notes"]}}
POST /api/v2/orders HTTP/1.1 Host: api.example.com Content-Type: application/json Content-Length: 214 Origin: https://app.example.com Referer: https://app.example.com/checkout {"item_id":9931,"qty":2,"coupon":"SPRING25","address_id":4471} HTTP/1.1 201 Created Location: /api/v2/orders/60218 X-RateLimit-Remaining: 47 {"order_id":60218,"total":"148.00","currency":"USD","status":"pending"}
POST /graphql HTTP/1.1 Host: api.example.com Content-Type: application/json {"query":"query Me { viewer { id email roles permissions } }"} HTTP/1.1 403 Forbidden Content-Type: application/json {"error":"insufficient_scope","required":"admin:read"} GET /assets/js/main.4f21ab9c.js HTTP/1.1 If-None-Match: W/"4f21ab9c" HTTP/1.1 304 Not Modified GET /api/v2/users/88142/exports?format=csv&range=90d HTTP/1.1 Host: api.example.com Authorization: Bearer eyJhbGciOiJIUzI1NiIsImtpZCI6IjIwMjQtMDgifQ.eyJzdWIiOiI4ODE0MiJ9
HTTP/1.1 302 Found Location: https://login.example.com/oauth/authorize?client_id=web&response_type=code PUT /api/v2/notes/7741 HTTP/1.1 Content-Type: application/json X-CSRF-Token: 9d31ba77c0 {"title":"scoped recon","body":"host: *.example.com","visibility":"private"} HTTP/1.1 500 Internal Server Error Content-Type: application/json {"error":"upstream_timeout","upstream":"orders-svc","retry_after":2}
GET /.well-known/openid-configuration HTTP/1.1 Host: login.example.com HTTP/1.1 200 OK {"issuer":"https://login.example.com","token_endpoint":"/oauth/token"} GET /api/v2/session/refresh HTTP/1.1 Host: app.example.com User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 Accept: application/json, text/plain, */* Accept-Encoding: gzip, deflate, br
Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiI4ODE0MiIsInJvbGUiOiJ1c2VyIn0 Cookie: sid=8f2b9c1ad4e7; csrf=9d31ba77c0; ab_bucket=control Connection: keep-alive HTTP/1.1 200 OK X-RateLimit-Remaining: 47 {"order_id":60218,"total":"148.00","currency":"USD","status":"pending"} POST /graphql HTTP/1.1 Host: api.example.com Content-Type: application/json {"query":"query Me { viewer { id email roles permissions } }"}
HTTP/1.1 403 Forbidden Content-Type: application/json {"error":"insufficient_scope","required":"admin:read"} GET /assets/js/main.4f21ab9c.js HTTP/1.1 If-None-Match: W/"4f21ab9c" HTTP/1.1 304 Not Modified GET /api/v2/users/88142/exports?format=csv&range=90d HTTP/1.1 Host: api.example.com Authorization: Bearer eyJhbGciOiJIUzI1NiIsImtpZCI6IjIwMjQtMDgifQ.eyJzdWIiOiI4ODE0MiJ9 HTTP/1.1 302 Found
Location: https://login.example.com/oauth/authorize?client_id=web&response_type=code PUT /api/v2/notes/7741 HTTP/1.1 Content-Type: application/json X-CSRF-Token: 9d31ba77c0 {"title":"scoped recon","body":"host: *.example.com","visibility":"private"} HTTP/1.1 500 Internal Server Error Content-Type: application/json {"error":"upstream_timeout","upstream":"orders-svc","retry_after":2} GET /.well-known/openid-configuration HTTP/1.1
Host: login.example.com HTTP/1.1 200 OK {"issuer":"https://login.example.com","token_endpoint":"/oauth/token"} GET /api/v2/session/refresh HTTP/1.1 Host: app.example.com User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 Accept: application/json, text/plain, */* Accept-Encoding: gzip, deflate, br Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiI4ODE0MiIsInJvbGUiOiJ1c2VyIn0
Cookie: sid=8f2b9c1ad4e7; csrf=9d31ba77c0; ab_bucket=control Connection: keep-alive HTTP/1.1 200 OK Content-Type: application/json; charset=utf-8 Content-Length: 1183 Set-Cookie: sid=1a77f0c9e2; Path=/; HttpOnly; Secure; SameSite=Lax X-Request-Id: 7f21c0e4-4d1a-4a77-9d0c-3b8f2c61aa10 Cache-Control: no-store {"ok":true,"user":{"id":88142,"role":"user","scopes":["read:profile","write:notes"]}} POST /api/v2/orders HTTP/1.1
Host: api.example.com Content-Type: application/json Content-Length: 214 Origin: https://app.example.com Referer: https://app.example.com/checkout {"item_id":9931,"qty":2,"coupon":"SPRING25","address_id":4471} HTTP/1.1 201 Created Location: /api/v2/orders/60218 Host: api.example.com Authorization: Bearer eyJhbGciOiJIUzI1NiIsImtpZCI6IjIwMjQtMDgifQ.eyJzdWIiOiI4ODE0MiJ9 HTTP/1.1 302 Found Location: https://login.example.com/oauth/authorize?client_id=web&response_type=code
PUT /api/v2/notes/7741 HTTP/1.1 Content-Type: application/json X-CSRF-Token: 9d31ba77c0 {"title":"scoped recon","body":"host: *.example.com","visibility":"private"} HTTP/1.1 500 Internal Server Error Content-Type: application/json {"error":"upstream_timeout","upstream":"orders-svc","retry_after":2} GET /.well-known/openid-configuration HTTP/1.1 Host: login.example.com HTTP/1.1 200 OK {"issuer":"https://login.example.com","token_endpoint":"/oauth/token"}
GET /api/v2/session/refresh HTTP/1.1 Host: app.example.com User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 Accept: application/json, text/plain, */* Accept-Encoding: gzip, deflate, br Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiI4ODE0MiIsInJvbGUiOiJ1c2VyIn0 Cookie: sid=8f2b9c1ad4e7; csrf=9d31ba77c0; ab_bucket=control
Connection: keep-alive HTTP/1.1 200 OK Content-Type: application/json; charset=utf-8 Content-Length: 1183 Set-Cookie: sid=1a77f0c9e2; Path=/; HttpOnly; Secure; SameSite=Lax X-Request-Id: 7f21c0e4-4d1a-4a77-9d0c-3b8f2c61aa10 Cache-Control: no-store {"ok":true,"user":{"id":88142,"role":"user","scopes":["read:profile","write:notes"]}} POST /api/v2/orders HTTP/1.1 Host: api.example.com Content-Type: application/json Content-Length: 214
Origin: https://app.example.com Referer: https://app.example.com/checkout {"item_id":9931,"qty":2,"coupon":"SPRING25","address_id":4471} HTTP/1.1 201 Created Location: /api/v2/orders/60218 X-RateLimit-Remaining: 47 {"order_id":60218,"total":"148.00","currency":"USD","status":"pending"} POST /graphql HTTP/1.1 Host: api.example.com Content-Type: application/json {"query":"query Me { viewer { id email roles permissions } }"}
HTTP/1.1 403 Forbidden Content-Type: application/json {"error":"insufficient_scope","required":"admin:read"} GET /assets/js/main.4f21ab9c.js HTTP/1.1 If-None-Match: W/"4f21ab9c" HTTP/1.1 304 Not Modified GET /api/v2/users/88142/exports?format=csv&range=90d HTTP/1.1 {"issuer":"https://login.example.com","token_endpoint":"/oauth/token"} GET /api/v2/session/refresh HTTP/1.1 Host: app.example.com User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36
Accept: application/json, text/plain, */* Accept-Encoding: gzip, deflate, br Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiI4ODE0MiIsInJvbGUiOiJ1c2VyIn0 Cookie: sid=8f2b9c1ad4e7; csrf=9d31ba77c0; ab_bucket=control Connection: keep-alive HTTP/1.1 200 OK Content-Type: application/json; charset=utf-8 Content-Length: 1183 Set-Cookie: sid=1a77f0c9e2; Path=/; HttpOnly; Secure; SameSite=Lax
X-Request-Id: 7f21c0e4-4d1a-4a77-9d0c-3b8f2c61aa10 Cache-Control: no-store {"ok":true,"user":{"id":88142,"role":"user","scopes":["read:profile","write:notes"]}} POST /api/v2/orders HTTP/1.1 Host: api.example.com Content-Type: application/json Content-Length: 214 Origin: https://app.example.com Referer: https://app.example.com/checkout {"item_id":9931,"qty":2,"coupon":"SPRING25","address_id":4471} HTTP/1.1 201 Created
Location: /api/v2/orders/60218 X-RateLimit-Remaining: 47 {"order_id":60218,"total":"148.00","currency":"USD","status":"pending"} POST /graphql HTTP/1.1 Host: api.example.com Content-Type: application/json {"query":"query Me { viewer { id email roles permissions } }"} HTTP/1.1 403 Forbidden Content-Type: application/json {"error":"insufficient_scope","required":"admin:read"}
GET /assets/js/main.4f21ab9c.js HTTP/1.1 If-None-Match: W/"4f21ab9c" HTTP/1.1 304 Not Modified GET /api/v2/users/88142/exports?format=csv&range=90d HTTP/1.1 Host: api.example.com Authorization: Bearer eyJhbGciOiJIUzI1NiIsImtpZCI6IjIwMjQtMDgifQ.eyJzdWIiOiI4ODE0MiJ9 HTTP/1.1 302 Found Location: https://login.example.com/oauth/authorize?client_id=web&response_type=code PUT /api/v2/notes/7741 HTTP/1.1 Content-Type: application/json X-CSRF-Token: 9d31ba77c0
{"title":"scoped recon","body":"host: *.example.com","visibility":"private"} HTTP/1.1 500 Internal Server Error Content-Type: application/json {"error":"upstream_timeout","upstream":"orders-svc","retry_after":2} GET /.well-known/openid-configuration HTTP/1.1 Host: login.example.com HTTP/1.1 200 OK {"ok":true,"user":{"id":88142,"role":"user","scopes":["read:profile","write:notes"]}}
POST /api/v2/orders HTTP/1.1 Host: api.example.com Content-Type: application/json Content-Length: 214 Origin: https://app.example.com Referer: https://app.example.com/checkout {"item_id":9931,"qty":2,"coupon":"SPRING25","address_id":4471} HTTP/1.1 201 Created Location: /api/v2/orders/60218 X-RateLimit-Remaining: 47 {"order_id":60218,"total":"148.00","currency":"USD","status":"pending"} POST /graphql HTTP/1.1 Host: api.example.com Content-Type: application/json
{"query":"query Me { viewer { id email roles permissions } }"} HTTP/1.1 403 Forbidden Content-Type: application/json {"error":"insufficient_scope","required":"admin:read"} GET /assets/js/main.4f21ab9c.js HTTP/1.1 If-None-Match: W/"4f21ab9c" HTTP/1.1 304 Not Modified GET /api/v2/users/88142/exports?format=csv&range=90d HTTP/1.1 Host: api.example.com Authorization: Bearer eyJhbGciOiJIUzI1NiIsImtpZCI6IjIwMjQtMDgifQ.eyJzdWIiOiI4ODE0MiJ9
HTTP/1.1 302 Found Location: https://login.example.com/oauth/authorize?client_id=web&response_type=code PUT /api/v2/notes/7741 HTTP/1.1 Content-Type: application/json X-CSRF-Token: 9d31ba77c0 {"title":"scoped recon","body":"host: *.example.com","visibility":"private"} HTTP/1.1 500 Internal Server Error Content-Type: application/json {"error":"upstream_timeout","upstream":"orders-svc","retry_after":2} GET /.well-known/openid-configuration HTTP/1.1
Host: login.example.com HTTP/1.1 200 OK {"issuer":"https://login.example.com","token_endpoint":"/oauth/token"} GET /api/v2/session/refresh HTTP/1.1 Host: app.example.com User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 Accept: application/json, text/plain, */* Accept-Encoding: gzip, deflate, br Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiI4ODE0MiIsInJvbGUiOiJ1c2VyIn0
Cookie: sid=8f2b9c1ad4e7; csrf=9d31ba77c0; ab_bucket=control Connection: keep-alive HTTP/1.1 200 OK Content-Type: application/json; charset=utf-8 Content-Length: 1183 Set-Cookie: sid=1a77f0c9e2; Path=/; HttpOnly; Secure; SameSite=Lax X-Request-Id: 7f21c0e4-4d1a-4a77-9d0c-3b8f2c61aa10 Cache-Control: no-store Content-Type: application/json {"query":"query Me { viewer { id email roles permissions } }"} HTTP/1.1 403 Forbidden
Content-Type: application/json {"error":"insufficient_scope","required":"admin:read"} GET /assets/js/main.4f21ab9c.js HTTP/1.1 If-None-Match: W/"4f21ab9c" HTTP/1.1 304 Not Modified GET /api/v2/users/88142/exports?format=csv&range=90d HTTP/1.1 Host: api.example.com Authorization: Bearer eyJhbGciOiJIUzI1NiIsImtpZCI6IjIwMjQtMDgifQ.eyJzdWIiOiI4ODE0MiJ9 HTTP/1.1 302 Found Location: https://login.example.com/oauth/authorize?client_id=web&response_type=code
PUT /api/v2/notes/7741 HTTP/1.1 Content-Type: application/json X-CSRF-Token: 9d31ba77c0 {"title":"scoped recon","body":"host: *.example.com","visibility":"private"} HTTP/1.1 500 Internal Server Error Content-Type: application/json {"error":"upstream_timeout","upstream":"orders-svc","retry_after":2} GET /.well-known/openid-configuration HTTP/1.1 Host: login.example.com HTTP/1.1 200 OK {"issuer":"https://login.example.com","token_endpoint":"/oauth/token"}
GET /api/v2/session/refresh HTTP/1.1 Host: app.example.com User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 Accept: application/json, text/plain, */* Accept-Encoding: gzip, deflate, br Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiI4ODE0MiIsInJvbGUiOiJ1c2VyIn0 Cookie: sid=8f2b9c1ad4e7; csrf=9d31ba77c0; ab_bucket=control Connection: keep-alive
HTTP/1.1 200 OK Content-Type: application/json; charset=utf-8 Content-Length: 1183 Set-Cookie: sid=1a77f0c9e2; Path=/; HttpOnly; Secure; SameSite=Lax X-Request-Id: 7f21c0e4-4d1a-4a77-9d0c-3b8f2c61aa10 Cache-Control: no-store {"ok":true,"user":{"id":88142,"role":"user","scopes":["read:profile","write:notes"]}} POST /api/v2/orders HTTP/1.1 Host: api.example.com Content-Type: application/json
Content-Length: 214 Origin: https://app.example.com Referer: https://app.example.com/checkout {"item_id":9931,"qty":2,"coupon":"SPRING25","address_id":4471} HTTP/1.1 201 Created Location: /api/v2/orders/60218 X-RateLimit-Remaining: 47 {"order_id":60218,"total":"148.00","currency":"USD","status":"pending"} POST /graphql HTTP/1.1 Host: api.example.com PUT /api/v2/notes/7741 HTTP/1.1 Content-Type: application/json
X-CSRF-Token: 9d31ba77c0 {"title":"scoped recon","body":"host: *.example.com","visibility":"private"} HTTP/1.1 500 Internal Server Error Content-Type: application/json {"error":"upstream_timeout","upstream":"orders-svc","retry_after":2} GET /.well-known/openid-configuration HTTP/1.1 Host: login.example.com HTTP/1.1 200 OK {"issuer":"https://login.example.com","token_endpoint":"/oauth/token"}
GET /api/v2/session/refresh HTTP/1.1 Host: app.example.com User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 Accept: application/json, text/plain, */* Accept-Encoding: gzip, deflate, br Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiI4ODE0MiIsInJvbGUiOiJ1c2VyIn0 Cookie: sid=8f2b9c1ad4e7; csrf=9d31ba77c0; ab_bucket=control Connection: keep-alive HTTP/1.1 200 OK
Content-Type: application/json; charset=utf-8 Content-Length: 1183 Set-Cookie: sid=1a77f0c9e2; Path=/; HttpOnly; Secure; SameSite=Lax X-Request-Id: 7f21c0e4-4d1a-4a77-9d0c-3b8f2c61aa10 Cache-Control: no-store {"ok":true,"user":{"id":88142,"role":"user","scopes":["read:profile","write:notes"]}} POST /api/v2/orders HTTP/1.1 Host: api.example.com Content-Type: application/json
Content-Length: 214 Origin: https://app.example.com Referer: https://app.example.com/checkout {"item_id":9931,"qty":2,"coupon":"SPRING25","address_id":4471} HTTP/1.1 201 Created Location: /api/v2/orders/60218 X-RateLimit-Remaining: 47 {"order_id":60218,"total":"148.00","currency":"USD","status":"pending"} POST /graphql HTTP/1.1 Host: api.example.com Content-Type: application/json {"query":"query Me { viewer { id email roles permissions } }"}
HTTP/1.1 403 Forbidden Content-Type: application/json {"error":"insufficient_scope","required":"admin:read"} GET /assets/js/main.4f21ab9c.js HTTP/1.1 If-None-Match: W/"4f21ab9c" HTTP/1.1 304 Not Modified GET /api/v2/users/88142/exports?format=csv&range=90d HTTP/1.1 Host: api.example.com Authorization: Bearer eyJhbGciOiJIUzI1NiIsImtpZCI6IjIwMjQtMDgifQ.eyJzdWIiOiI4ODE0MiJ9 HTTP/1.1 302 Found
Location: https://login.example.com/oauth/authorize?client_id=web&response_type=code Accept: application/json, text/plain, */* Accept-Encoding: gzip, deflate, br Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiI4ODE0MiIsInJvbGUiOiJ1c2VyIn0 Cookie: sid=8f2b9c1ad4e7; csrf=9d31ba77c0; ab_bucket=control Connection: keep-alive HTTP/1.1 200 OK Content-Type: application/json; charset=utf-8 Content-Length: 1183Why people move
A hacking tool should feel intuitive rather than overwhelming, so Caido keeps the surface small and the power underneath it.
01
workspace://projects
Switch between targets without leaving the app. Projects keep each engagement isolated, so your history, scope and replay sessions stay where you left them.

02
query://httpql
HTTPQL filters traffic with a human readable query language. No scripting or nested settings panels-just intuitive queries that pin down exact requests in seconds.

03
workflow://graph
Workflows turn repetitive testing into a visual graph you assemble on the fly. Drop in a node, wire it up, and it runs against live traffic without writing a plugin.

HTTPQL narrows thousands of requests to the handful worth your attention. Type a query, watch the noise fall away.
HTTPQL query: req.method.eq:"POST" and req.host.cont:"api" and resp.code.gte:500
6 of 512 captured requests match that query:
Under the hood
Two things people notice in their first week, and why they stop reaching for legacy tools.
Caido is built from the ground up in Rust, so it stays responsive on large projects and keeps memory use low, even through long engagement.
You already work with HTML, CSS and JavaScript, so plugin development uses the same tools. There is no Java toolchain to set up before you can extend your own workflow.
01
02
03
04
05
06
07
08
09
10
11
12
Side by side
Comparing Caido and Burp Suite across the features switchers care about most.
Swipe or scroll sideways to compare every plan.
Caido | Burp Suite | |||
|---|---|---|---|---|
Feature | Basic | Individual | Community | Professional |
Pricing | Free | $200/year | Free | $499/year |
Unlimited Installations | Included | Included | Included | Not available |
Project Management | Included | Included | Not available | Not available |
Unrestricted Automation | Included | Included | Not availableRate-limited Intruder | Included |
Intuitive Filtering | IncludedHTTPQL | IncludedHTTPQL | Not availableBambdas | Not availableBambdas |
No-Code Customizations | Included | Included | Not available | Not available |
Simplified Plugin Development | Included | Included | Not available | Not available |
Remote Hosting | Included | Included | Not available | Not available |
Basic is free forever and installs are unlimited, so the only real cost of switching is an afternoon of your time.
Nous utilisons des cookies pour améliorer votre expérience de navigation, diffuser du contenu personnalisé et analyser notre trafic. En cliquant sur "Tout accepter", vous consentez à l'utilisation de nos cookies. Cliquez sur "Essentiels uniquement" pour n'autoriser que les cookies nécessaires au fonctionnement du site.
