What is mitmproxy?
mitmproxy is an interactive, TLS-capable intercepting HTTP proxy for penetration testers and software developers. Point a browser, a phone, a CLI or a whole container at it and every request and response passes through where you can see it: headers, bodies, timings, TLS details. You can pause a request mid-flight, edit it and let it go, replay it a hundred times, or rewrite traffic automatically with a few lines of Python. It speaks HTTP/1, HTTP/2, HTTP/3, WebSocket and raw TLS, and runs as a regular, transparent, reverse, upstream, SOCKS5, WireGuard or local capture proxy. One package gives you three front ends: mitmproxy, the interactive console UI, mitmweb, the same thing in your browser, and mitmdump, the command-line version, a tcpdump for HTTP.
⚡ Key Features of mitmproxy
🔓 Sees Inside TLS
mitmproxy generates its own certificate authority in ~/.mitmproxy/ on first run and mints certificates on the fly for every host you visit. Trust that CA once on a client and its HTTPS traffic becomes readable, request by request.
✋ Intercept and Edit
Press i in the console, give it a filter such as ~d api.example.com, and matching requests stop in place. e edits the method, URL, headers or body, a sends it on its way.
🔁 Replay Anything
r replays a single request from the console. Save a session with -w and play the client side back with --client-replay, or answer a client from recorded responses with --server-replay.
🐍 Python Addons
Load a script with -s script.py and hook into every request, response, WebSocket message or TLS handshake. Rewrite headers, mock endpoints, strip tracking, log to a file: the addon API is the same one mitmproxy's own features are built on.
🧭 Every Proxy Mode
Regular, transparent, reverse (--mode reverse:https://example.com), upstream, SOCKS5, WireGuard for phones and VMs, and local capture of a single application. Pass --mode more than once to run several at the same time.
🌐 Console, Web or Headless
The keyboard-driven console for a terminal or an SSH session, mitmweb on http://127.0.0.1:8081 for a point-and-click flow list, and mitmdump for scripts, CI jobs and long unattended captures.
apt upgrade keeps you on the latest version.
📦 Installation from deb.griffo.io
Step 1: Add Repository
sudo install -d -m 0755 /etc/apt/keyrings
curl -fsSL https://deb.griffo.io/EA0F721D231FDD3A0A17B9AC7808B4DD62C41256.asc | sudo gpg --dearmor --yes -o /etc/apt/keyrings/deb.griffo.io.gpg
echo "deb [signed-by=/etc/apt/keyrings/deb.griffo.io.gpg] https://deb.griffo.io/apt $(lsb_release -sc 2>/dev/null) main" | sudo tee /etc/apt/sources.list.d/deb.griffo.io.list > /dev/null
sudo apt updateinstall -d -m 0755 /etc/apt/keyrings
curl -fsSL https://deb.griffo.io/EA0F721D231FDD3A0A17B9AC7808B4DD62C41256.asc | gpg --dearmor --yes -o /etc/apt/keyrings/deb.griffo.io.gpg
echo "deb [signed-by=/etc/apt/keyrings/deb.griffo.io.gpg] https://deb.griffo.io/apt $(lsb_release -sc 2>/dev/null) main" | tee /etc/apt/sources.list.d/deb.griffo.io.list > /dev/null
apt updatesudo apt install extrepo
sudo extrepo enable griffo
sudo apt update🆓 There is an always-free mirror. deb-free.griffo.io serves packages free forever, no account, no subscription, at most 2 months behind upstream, security fixes immediately. It currently carries cliamp, Ghostty, lazydocker, Oh My Posh, Uncloud and Zed; mitmproxy is not one of them, so the repository above is the only way to get it today, ask and it can be enrolled.
🧩 About the extrepo option. extrepo is Debian's own tool for external repositories: it writes the sources file and installs the signing key for you, checking the key against signed metadata first. This repository is registered with it as griffo, and the always-free mirror as griffo-free, so on Debian (bookworm, trixie, forky and sid) the commands above are the whole setup.
extrepo sets up the sources file and the key only, so a subscription's credentials still go in /etc/apt/auth.conf.d/deb.griffo.io.conf. Ubuntu is not covered, because extrepo publishes metadata for Debian suites only: there, use the sudo or root commands.
Step 2: Install mitmproxy
# Install latest mitmproxy
sudo apt install mitmproxy
# One package, three commands: mitmproxy, mitmweb and mitmdump.
# It bundles its own Python and OpenSSL, so nothing else is pulled in
# Verify installation
mitmproxy --version
mitmdump --version# Install latest mitmproxy
apt install mitmproxy
# One package, three commands: mitmproxy, mitmweb and mitmdump.
# It bundles its own Python and OpenSSL, so nothing else is pulled in
# Verify installation
mitmproxy --version
mitmdump --versionStep 3: First run
# Start the console UI, listening on port 8080
mitmproxy
# Or the web UI, which opens http://127.0.0.1:8081
mitmweb
# In another terminal, send a request through it
curl -x http://127.0.0.1:8080 http://example.com
# The first run generated a CA in ~/.mitmproxy/. With a client
# proxied, browse to http://mitm.it to install it on that client,
# or trust it system-wide on this machine
sudo cp ~/.mitmproxy/mitmproxy-ca-cert.pem /usr/local/share/ca-certificates/mitmproxy.crt
sudo update-ca-certificates# Start the console UI, listening on port 8080
mitmproxy
# Or the web UI, which opens http://127.0.0.1:8081
mitmweb
# In another terminal, send a request through it
curl -x http://127.0.0.1:8080 http://example.com
# The first run generated a CA in ~/.mitmproxy/. With a client
# proxied, browse to http://mitm.it to install it on that client,
# or trust it system-wide on this machine
cp ~/.mitmproxy/mitmproxy-ca-cert.pem /usr/local/share/ca-certificates/mitmproxy.crt
update-ca-certificates🎯 Basic Usage Examples
Capturing traffic:
# Listen on another port
mitmproxy --listen-port 9090
# Proxy a single command through it
HTTPS_PROXY=http://127.0.0.1:8080 curl https://example.com
# Record everything to a file without a UI
mitmdump -w session.mitm
# Only show requests to one host
mitmdump "~d api.example.com"
# Save a HAR file for browser dev tools or a bug report
mitmdump --set hardump=./session.harReplaying and inspecting:
# Open a saved session in the console
mitmproxy -r session.mitm
# Print the POST requests from it without starting a proxy
mitmdump -n -r session.mitm "~m POST"
# Send the recorded requests again
mitmdump -n --client-replay session.mitm
# Answer clients from recorded responses instead of the real server
mitmdump --server-replay session.mitmProxy modes and addons:
# Reverse proxy in front of one server
mitmproxy --mode reverse:https://example.com --listen-port 8443
# SOCKS5 and a regular proxy from the same instance
mitmdump --mode socks5 --mode regular
# WireGuard: scan the QR code in mitmweb with a phone's WireGuard app
mitmweb --mode wireguard
# Rewrite traffic with a Python addon, e.g. addon.py containing:
# def response(flow):
# flow.response.headers["x-seen-by"] = "mitmproxy"
mitmdump -s addon.py🔧 Tool Integrations
mitmproxy sits between the tools you already use and the network they talk to:
- curl, wget and most CLIs: anything that honours
HTTP_PROXYandHTTPS_PROXYgoes through mitmproxy with one environment variable, andcurl -xdoes it per command - Browsers and phones: set the proxy to port 8080, open
http://mitm.itand install the CA for that platform, or use WireGuard mode on Android and iOS with no proxy settings at all - Browser dev tools:
hardumpwrites a HAR file, and mitmproxy reads HAR files back with-r, so a capture moves between it and Chrome or Firefox in both directions - Python addons: scripts loaded with
-srun inside mitmproxy's bundled Python, so they can import the standard library and what mitmproxy ships, but not packages installed for the systempython3 - Test suites and CI:
mitmdumpwith--server-replayserves recorded responses, which makes flaky third-party APIs repeatable in integration tests
🚀 Why Choose deb.griffo.io?
- Official Debian: 8.1.1 from 2022 in bookworm, forky and sid, and not in trixie, the current stable, at all
- pipx or pip: current, but tied to whichever system Python you have and invisible to apt
- The upstream tarball: the same standalone build this package ships, unpacked by hand and updated by hand
- deb.griffo.io: latest version with automatic updates
- ✅ Years Ahead of the Archives: the current mitmproxy release instead of 8.1.1, with HTTP/3, WireGuard and local capture modes included
- ✅ Three Commands, One Package:
mitmproxy,mitmwebandmitmdumpall land on your PATH, the names every tutorial uses - ✅ Automatic Updates: packages updated within hours of upstream releases
- ✅ Complete Package: upstream's official self-contained Linux build, nothing added, nothing patched
- ✅ No Python Dependencies: it bundles its own Python and OpenSSL, so it never conflicts with system Python packages or waits on them to be updated
- ✅ Two Architectures: amd64 and arm64, the same standalone build on every suite
- ✅ Multi-Distribution: works on Bookworm, Trixie, Forky and Sid
- ✅ Easy Maintenance: standard apt commands for updates
📦 Package Build Repository
The Debian packages are automatically built and maintained in this GitHub repository:
- 🕵️ mitmproxy-debian - Latest release builds
🔗 Related Packages
Also available from deb.griffo.io:
- yq - Query and reshape the JSON bodies you pull out of a capture
- Headscale - Self-hosted WireGuard networking, for the other side of the tunnel
- k9s - A terminal UI for the Kubernetes services you end up proxying
- lazydocker - A terminal UI for the containers whose traffic you are debugging
💝 Support This Project
If this repository saves you time and effort, please consider supporting it!