⚡ 59 developer tools, always updated, new upstream releases land in apt within hours. Join the Discord

📅 From , the apt mirror will require a subscription. See pricing · 🆓 There is an always-free mirror

🕵️ Install Latest mitmproxy on Debian

An interactive TLS-capable intercepting HTTP proxy

Latest version: 12.2.3 · updated 2026-09-29
SourceVersion
deb.griffo.io12.2.3 ✅
Official Debian🚫 not packaged
← Back to home
📌 Installing on a specific release? Debian 12 (bookworm) · Debian 13 (trixie) · Debian 14 (forky) · Debian Sid

What is mitmproxy?

mitmproxy is an interactive, TLS-capable intercepting HTTP proxy for penetration testers and software developers. Point a browser, a phone, a CLI or a whole container at it and every request and response passes through where you can see it: headers, bodies, timings, TLS details. You can pause a request mid-flight, edit it and let it go, replay it a hundred times, or rewrite traffic automatically with a few lines of Python. It speaks HTTP/1, HTTP/2, HTTP/3, WebSocket and raw TLS, and runs as a regular, transparent, reverse, upstream, SOCKS5, WireGuard or local capture proxy. One package gives you three front ends: mitmproxy, the interactive console UI, mitmweb, the same thing in your browser, and mitmdump, the command-line version, a tcpdump for HTTP.

🚀 Why Latest Versions Matter: the mitmproxy in the official archives is 8.1.1, a 2022 release, and Debian dropped it from trixie altogether. Everything since then is missing from it: WireGuard mode, running several proxy modes from one instance, local capture mode, full HTTP/3, HAR import and export, and years of fixes for the TLS stacks and HTTP/2 quirks of real-world servers. An intercepting proxy is only useful if it understands what current clients speak, and addon scripts written against today's documentation expect today's API.

⚡ Key Features of mitmproxy

🔓 Sees Inside TLS

mitmproxy generates its own certificate authority in ~/.mitmproxy/ on first run and mints certificates on the fly for every host you visit. Trust that CA once on a client and its HTTPS traffic becomes readable, request by request.

✋ Intercept and Edit

Press i in the console, give it a filter such as ~d api.example.com, and matching requests stop in place. e edits the method, URL, headers or body, a sends it on its way.

🔁 Replay Anything

r replays a single request from the console. Save a session with -w and play the client side back with --client-replay, or answer a client from recorded responses with --server-replay.

🐍 Python Addons

Load a script with -s script.py and hook into every request, response, WebSocket message or TLS handshake. Rewrite headers, mock endpoints, strip tracking, log to a file: the addon API is the same one mitmproxy's own features are built on.

🧭 Every Proxy Mode

Regular, transparent, reverse (--mode reverse:https://example.com), upstream, SOCKS5, WireGuard for phones and VMs, and local capture of a single application. Pass --mode more than once to run several at the same time.

🌐 Console, Web or Headless

The keyboard-driven console for a terminal or an SSH session, mitmweb on http://127.0.0.1:8081 for a point-and-click flow list, and mitmdump for scripts, CI jobs and long unattended captures.

🚀 Always ahead of the official archives: Debian and Ubuntu freeze package versions when a release ships. This repository publishes new upstream releases typically within hours. A simple apt upgrade keeps you on the latest version.

📦 Installation from deb.griffo.io

Run the commands

Step 1: Add Repository

sudo install -d -m 0755 /etc/apt/keyrings
curl -fsSL https://deb.griffo.io/EA0F721D231FDD3A0A17B9AC7808B4DD62C41256.asc | sudo gpg --dearmor --yes -o /etc/apt/keyrings/deb.griffo.io.gpg
echo "deb [signed-by=/etc/apt/keyrings/deb.griffo.io.gpg] https://deb.griffo.io/apt $(lsb_release -sc 2>/dev/null) main" | sudo tee /etc/apt/sources.list.d/deb.griffo.io.list > /dev/null
sudo apt update
install -d -m 0755 /etc/apt/keyrings
curl -fsSL https://deb.griffo.io/EA0F721D231FDD3A0A17B9AC7808B4DD62C41256.asc | gpg --dearmor --yes -o /etc/apt/keyrings/deb.griffo.io.gpg
echo "deb [signed-by=/etc/apt/keyrings/deb.griffo.io.gpg] https://deb.griffo.io/apt $(lsb_release -sc 2>/dev/null) main" | tee /etc/apt/sources.list.d/deb.griffo.io.list > /dev/null
apt update
sudo apt install extrepo
sudo extrepo enable griffo
sudo apt update

🆓 There is an always-free mirror. deb-free.griffo.io serves packages free forever, no account, no subscription, at most 2 months behind upstream, security fixes immediately. It currently carries cliamp, Ghostty, lazydocker, Oh My Posh, Uncloud and Zed; mitmproxy is not one of them, so the repository above is the only way to get it today, ask and it can be enrolled.

How the free mirror works →

🧩 About the extrepo option. extrepo is Debian's own tool for external repositories: it writes the sources file and installs the signing key for you, checking the key against signed metadata first. This repository is registered with it as griffo, and the always-free mirror as griffo-free, so on Debian (bookworm, trixie, forky and sid) the commands above are the whole setup.

extrepo sets up the sources file and the key only, so a subscription's credentials still go in /etc/apt/auth.conf.d/deb.griffo.io.conf. Ubuntu is not covered, because extrepo publishes metadata for Debian suites only: there, use the sudo or root commands.

Step 2: Install mitmproxy

# Install latest mitmproxy
sudo apt install mitmproxy

# One package, three commands: mitmproxy, mitmweb and mitmdump.
# It bundles its own Python and OpenSSL, so nothing else is pulled in

# Verify installation
mitmproxy --version
mitmdump --version
# Install latest mitmproxy
apt install mitmproxy

# One package, three commands: mitmproxy, mitmweb and mitmdump.
# It bundles its own Python and OpenSSL, so nothing else is pulled in

# Verify installation
mitmproxy --version
mitmdump --version

Step 3: First run

# Start the console UI, listening on port 8080
mitmproxy

# Or the web UI, which opens http://127.0.0.1:8081
mitmweb

# In another terminal, send a request through it
curl -x http://127.0.0.1:8080 http://example.com

# The first run generated a CA in ~/.mitmproxy/. With a client
# proxied, browse to http://mitm.it to install it on that client,
# or trust it system-wide on this machine
sudo cp ~/.mitmproxy/mitmproxy-ca-cert.pem /usr/local/share/ca-certificates/mitmproxy.crt
sudo update-ca-certificates
# Start the console UI, listening on port 8080
mitmproxy

# Or the web UI, which opens http://127.0.0.1:8081
mitmweb

# In another terminal, send a request through it
curl -x http://127.0.0.1:8080 http://example.com

# The first run generated a CA in ~/.mitmproxy/. With a client
# proxied, browse to http://mitm.it to install it on that client,
# or trust it system-wide on this machine
cp ~/.mitmproxy/mitmproxy-ca-cert.pem /usr/local/share/ca-certificates/mitmproxy.crt
update-ca-certificates

🎯 Basic Usage Examples

Capturing traffic:

# Listen on another port
mitmproxy --listen-port 9090

# Proxy a single command through it
HTTPS_PROXY=http://127.0.0.1:8080 curl https://example.com

# Record everything to a file without a UI
mitmdump -w session.mitm

# Only show requests to one host
mitmdump "~d api.example.com"

# Save a HAR file for browser dev tools or a bug report
mitmdump --set hardump=./session.har

Replaying and inspecting:

# Open a saved session in the console
mitmproxy -r session.mitm

# Print the POST requests from it without starting a proxy
mitmdump -n -r session.mitm "~m POST"

# Send the recorded requests again
mitmdump -n --client-replay session.mitm

# Answer clients from recorded responses instead of the real server
mitmdump --server-replay session.mitm

Proxy modes and addons:

# Reverse proxy in front of one server
mitmproxy --mode reverse:https://example.com --listen-port 8443

# SOCKS5 and a regular proxy from the same instance
mitmdump --mode socks5 --mode regular

# WireGuard: scan the QR code in mitmweb with a phone's WireGuard app
mitmweb --mode wireguard

# Rewrite traffic with a Python addon, e.g. addon.py containing:
#   def response(flow):
#       flow.response.headers["x-seen-by"] = "mitmproxy"
mitmdump -s addon.py

🔧 Tool Integrations

mitmproxy sits between the tools you already use and the network they talk to:

  • curl, wget and most CLIs: anything that honours HTTP_PROXY and HTTPS_PROXY goes through mitmproxy with one environment variable, and curl -x does it per command
  • Browsers and phones: set the proxy to port 8080, open http://mitm.it and install the CA for that platform, or use WireGuard mode on Android and iOS with no proxy settings at all
  • Browser dev tools: hardump writes a HAR file, and mitmproxy reads HAR files back with -r, so a capture moves between it and Chrome or Firefox in both directions
  • Python addons: scripts loaded with -s run inside mitmproxy's bundled Python, so they can import the standard library and what mitmproxy ships, but not packages installed for the system python3
  • Test suites and CI: mitmdump with --server-replay serves recorded responses, which makes flaky third-party APIs repeatable in integration tests

🚀 Why Choose deb.griffo.io?

📊 Repository Comparison:
  • Official Debian: 8.1.1 from 2022 in bookworm, forky and sid, and not in trixie, the current stable, at all
  • pipx or pip: current, but tied to whichever system Python you have and invisible to apt
  • The upstream tarball: the same standalone build this package ships, unpacked by hand and updated by hand
  • deb.griffo.io: latest version with automatic updates

📦 Package Build Repository

The Debian packages are automatically built and maintained in this GitHub repository:

🔗 Related Packages

Also available from deb.griffo.io:

🎯 Perfect for: seeing exactly what a mobile app or a CLI sends to its backend, debugging OAuth redirects and cookies, testing how a client handles a slow or broken API, penetration testing web applications, and turning a one-off manual test into a repeatable Python script.

💝 Support This Project

If this repository saves you time and effort, please consider supporting it!

⭐ Star on GitHub 🐦 Share on Twitter

Just after the command? See apt install mitmproxy, one page covering Debian and Ubuntu.

📦 Recent releases from this repository

📚 Release-specific install guides

❓ Frequently asked questions

Is mitmproxy in the official Debian repositories?

No, mitmproxy is not packaged in the official Debian archives. This repository is currently the only apt source, serving mitmproxy 12.2.3.

How do I install the latest mitmproxy on Debian?

Add the deb.griffo.io repository once using the instructions above, then run: sudo apt install mitmproxy. New releases arrive through the normal sudo apt upgrade.

Are the packages signed and how are they built?

Every package is signed with the repository's GPG key (EA0F721D231FDD3A0A17B9AC7808B4DD62C41256) and built from upstream releases in public GitHub packaging repositories that anyone can inspect.

Which Debian releases are supported?

Debian 12 Bookworm, Debian 13 Trixie, Forky and Sid.