Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
mkdev — Trusted localhost HTTPS — local CA, /etc/hosts, mDNS LAN sharing, reverse proxy. Maps https://name.local → localhost:port | Kitploit
Tools/GitHubGitHub/venkatkrishna07/mkdev
Encryption/Decryption ToolsReverse EngineeringWeb SecurityNetwork SecurityUtilities & FrameworksDNS Analysis
GitHubvenkatkrishna07/mkdev

mkdev

Trusted localhost HTTPS — local CA, /etc/hosts, mDNS LAN sharing, reverse proxy. Maps https://name.local → localhost:port

View Repository
14014133 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

mkdev

Real HTTPS for local dev — with a TUI and LAN sharing.

ci release license


mkdev runs trusted HTTPS on *.local. A single Go binary: cert authority + reverse proxy + /etc/hosts + mDNS broadcast + a full TUI.

What makes it different:

  • LAN sharing Mark a route shared, hit https://app.local from your phone or any device on the same Wi-Fi.
  • TUI, not just a CLI. Live route table, request logs, cert inspection, health doctor. mkdev with no args drops you in.
  • Hardened privilege boundary. Owner, writability, and symlink checks on the sudo helper binary before any elevated call (internal/safeexec). No PATH-based shadowing, no group-writable shortcuts.
  • Per-SNI cert minting. Leaves are issued on demand and gated by an explicit knownHost allow-list. Not wildcard, not pre-baked.

What it does

mkdev install                    # CA + trust + daemon service + menu bar autostart
mkdev add myapp localhost:3000   # routes https://myapp.local → localhost:3000
curl https://myapp.local         # 200 from your local app

install is one-shot: generates the CA, trusts it in the system store, installs and enables the daemon user-service (launchd / systemd), registers the menu bar to launch on login, and spawns the bar immediately when a GUI session is present. The daemon owns the proxy; the TUI (mkdev no args) and mkdev add | remove | list talk to it over ~/.mkdev/daemon.sock.

mkdev demo

LAN sharing

mkdev's headline feature. Share a route to any device on the same Wi-Fi with real TLS — no warnings, no tunnel service.

  1. In the TUI Domains tab, select a route and press s to flip the SHARE column to LAN.
  2. The route is advertised via mDNS as <name>.local → this machine's LAN IP.
  3. On the phone / second laptop, browse to https://<name>.local. Once the device trusts the mkdev CA (one-time), no warnings.

Caveats

  • Only .local routes broadcast over mDNS. Other TLDs still proxy but aren't LAN-reachable by name.
  • Corporate / cloud Wi-Fi often blocks multicast. Home and office Wi-Fi work.
  • Toggling s is live — mDNS advertising and the LAN-side ACL update on the next request. No restart.
  • Non-shared routes 403 non-loopback requests as defense-in-depth.
  • Anyone on the LAN can hit your shared routes. Don't enable on untrusted Wi-Fi.

Install

Homebrew (macOS, Linux)

brew install venkatkrishna07/tap/mkdev

Upgrade later:

brew update
brew upgrade mkdev

Go

go install github.com/venkatkrishna07/mkdev/cmd/mkdev@latest

Upgrade to a specific version:

go install github.com/venkatkrishna07/mkdev/cmd/[email protected]

Direct download

Pre-built binaries for macOS (Intel + Apple Silicon), Linux (amd64 + arm64), and Windows (amd64) are published on the Releases page. Each release includes checksums.txt plus a cosign keyless signature (checksums.txt.sig + .pem) — see SECURITY.md#verifying-releases for the verify command.

On macOS, if Gatekeeper blocks a direct-download binary:

xattr -d com.apple.quarantine ./mkdev

From source

git clone https://github.com/venkatkrishna07/mkdev.git
cd mkdev
task build
cp bin/mkdev ~/bin/        # or /usr/local/bin

Requires Go 1.25+.

First run

mkdev install   # CA, trust, daemon service, bar autostart — one command
mkdev           # launch TUI

After install, the daemon runs in the background and the menu bar appears (macOS, Linux GNOME/KDE, Windows). The bar shows daemon status, route list, and per-route enable / LAN-share toggles; Quit exits the bar without stopping the daemon.

Menu bar

The bar is the always-on UI. It lives in the system tray and talks to the daemon over ~/.mkdev/daemon.sock. Launches on login (autostart registered by install); also runnable foreground with mkdev bar.

What it shows:

  • Status dot — green up, red down, yellow probing, grey off. Reflects the daemon health.
  • Header — mkdev v0.4.0 + daemon PID + uptime + listening proxy port.
  • Routes — every route in the store, top-down. Each entry shows name.tld → target plus suffix badges ( · disabled, · LAN).

What it does (click on a route):

  • Open in browser — opens https://name.tld with the system default handler.
  • Copy URL — copies the proxy URL to the clipboard (pbcopy / wl-copy / xclip / clip.exe).
  • Enable / Disable — flips the route's Enabled flag. Disabled routes stay in the store but stop being proxied.
  • Share on LAN — toggles mDNS advertise + LAN-side ACL.

Bar-level actions:

  • Stop daemon — calls DisableUnit first so launchd / systemd KeepAlive doesn't immediately respawn it, then sends shutdown over the socket.
  • Quit — exits the bar process only. The daemon and proxy keep running.

Notes:

  • Two bar instances can't run at once (PID-file lock; the second exits immediately).
  • The bar reconnects automatically when the daemon restarts. The status dot updates without a manual refresh.
  • Only the bar (and mkdev daemon stop) cleanly stop the supervised daemon — killing the daemon process directly will get it respawned by launchd / systemd.

Upgrading

Replace the binary (brew upgrade / go install ...@latest / new download). The next time you run any mkdev subcommand, the binary reconciles the parts that live outside it: rewrites the daemon plist / systemd unit and bar autostart entry to point at the new binary, re-asserts /etc/hosts for enabled routes, and re-trusts the CA if it was dropped. Sudo prompts run inline. If you only have the daemon running and never touch the CLI, the daemon does the safe (no-sudo) bits on its own startup and queues the rest until the next CLI command.

Re-running mkdev install does the same thing explicitly and is always safe — every step is idempotent.

Platform support

PlatformTrust storeElevation
macOSSystem Keychain (security add-trusted-cert)sudo / osascript
Linuxupdate-ca-trust / update-ca-certificates / trust extract-compatsudo / pkexec
WindowsROOT system store via crypt32.dllUAC (PowerShell RunAs)

Linux distros detected: Debian/Ubuntu (/usr/local/share/ca-certificates), RHEL/Fedora (/etc/pki/ca-trust/source/anchors), Arch (/etc/ca-certificates/trust-source/anchors), openSUSE (/usr/share/pki/trust/anchors).

Firefox uses its own NSS store and is not yet covered — system Chrome/Safari/Edge/curl/wget all work.

Commands

Download Tool