
Terminal-based HTTP intercepting proxy with TUI for capturing, inspecting, and modifying requests in real time, plus a Repeater for resending and tweaking requests.
Minimal terminal-based HTTP/HTTPS intercepting proxy.
https://github.com/user-attachments/assets/94f9c9ae-5842-4b19-9f5b-84dedb9430e6
Features · Installation · HTTPS support · Usage · How it works
Roxy is a lightweight intercepting proxy for HTTP and HTTPS with a terminal user interface (TUI) written in Rust. It captures, inspects and modifies requests in real time, before they reach the server, from inside your terminal. Think of it as a minimal, terminal-native alternative to Burp Suite for everyday traffic analysis.
CONNECT, with certificates generated automatically.$EDITOR.--host and --port, and decide which hosts get intercepted or passed through.To build it from source you need:
| Requirement | Notes |
|---|---|
| Rust 1.85 or newer | Check with rustc --version. |
| A C compiler | gcc or clang. |
$EDITOR | Only needed for the request editing feature. |
git clone https://github.com/vid4l-07/Roxy.git
cd Roxy
cargo build --release
The binary will be available at target/release/roxy.
cargo install --git https://github.com/vid4l-07/Roxy.git
The binary will be available at ~/.cargo/bin/roxy.
[!note] If HTTPS passthrough is enabled, HTTPS support is not required.
| What | Location | Notes |
|---|---|---|
| CA certificate and key | ~/.config/roxy/ca.crt, ~/.config/roxy/ca.key | Created lazily, the first time an HTTPS request is intercepted. |
| Leaf certificate per host | /tmp/roxy_certs/<host>.crt, /tmp/roxy_certs/<host>.key | Issued on demand and cached. The cache is wiped whenever a new CA is generated. |
Roxy generates a self-signed CA named Roxy CA.
[!Warning] Every HTTPS request will fail validation until the CA is trusted by the client.
Install ~/.config/roxyca.crt in your browser or system.
You can also download it from the built-in web page at http://roxy (or http://<host>:<port>).
Firefox / Chrome:
Settings → Privacy & Security → Certificates → View Certificates.~/.config/roxy/ca.crt.System CA store For tools like curl.
# Debian / Ubuntu
sudo cp ~/.config/roxy/ca.crt /usr/local/share/ca-certificates/roxy.crt
sudo update-ca-certificates
# Fedora / RHEL / Arch
sudo cp ~/.config/roxy/ca.crt /etc/pki/ca-trust/source/anchors/roxy.crt
sudo update-ca-trust extract
To remove it again, delete the file and re-run the corresponding command.
rm -rf ~/.config/roxy
Roxy generates a new CA on the next HTTPS request and removes every leaf certificate it had cached. You will have to trust the new CA again. Remember to remove the old one from your browser and system store.
| Option | Description |
|---|---|
-h, --host <HOST> | Listening host. Defaults to 127.0.0.1. |
-p, --port <PORT> | Listening port. Defaults to 8080. |
--passthrough | Tunnel HTTPS without decrypting it, for every host. |
--passthrough-host <HOSTS> | Same as --passthrough, but only for the listed hosts. |
--intercept-https <HOSTS> | Intercept these hosts even in passthrough mode. |
--help | Print the help message. |
# Pass every host through untouched except the one you want to inspect
roxy --passthrough --intercept-https <HOSTS>
| Key | Action |
|---|---|
q | Quit |
Tab | Switch between Proxy and Repeater screens |
? | Open the help popup for the current screen |
| Key | Action |
|---|---|
i | Toggle intercept ON/OFF |
Enter | Forward the intercepted request |
e | Edit request in external editor |
u | Undo edit |
U | Redo edit |
r | Send request to Repeater |
↑/k | Scroll up |
↓/j | Scroll down |
| Key | Action |
|---|---|
Enter | Send the current request |
e | Edit request in external editor |
u | Undo edit |
U | Redo edit |
r | Rename current tab |
n | Next repeater tab |
p | Previous repeater tab |
x | Close current tab |
z | Toggle zoom on the focused panel |
↑/k | Scroll up |
↓/j | Scroll down |
←/h / →/l | Toggle focus between Request and Response panels |
H | Decrease Request panel width |
L | Increase Request panel width |
When you press e, the raw request is written to a temporary file and opened with the binary defined by $EDITOR. Edit it, save, and quit.
The modified request replaces the original and Content-Length is recalculated automatically.
127.0.0.1:8080 by default, configurable with --host and --port, and handles each one in its own async task.CONNECT request is answered with 200 Connection Established, TLS is terminated locally with a certificate issued for the requested host, and the decrypted request is read as a regular HTTP request. Hosts matched by the passthrough options are relayed to the real server instead, without terminating TLS.Host header.tokio::mpsc channel and the connection waits on a oneshot channel until the user forwards it. The request can be forwarded as-is, edited first, or sent to the Repeater.webpki-roots for HTTPS), writes the request, and streams the raw response back to the client.Enter, choosing the transport based on the protocol the request was captured with, and shows the response side by side with the request.The TUI and the proxy never share state directly. They only talk through the event channels, so the interface stays responsive while requests are being intercepted.
Contributions are always welcome. If you find a bug or want to help with new features, you can:
Roxy is released under the MIT License. © 2026 Hugo Vidal Martinez.