Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Roxy — Terminal-based HTTP intercepting proxy with TUI for capturing, inspecting, and modifying requests in real time, plus a Repeater for resending and tweaking requests. | Kitploit
Tools/GitHubGitHub/vid4l-07/roxy
Web Proxies & InterceptionWeb Application ExploitationAPI Security TestingWeb SecurityPenetration TestingUtilities & Frameworks
GitHubvid4l-07/roxy

Roxy

Terminal-based HTTP intercepting proxy with TUI for capturing, inspecting, and modifying requests in real time, plus a Repeater for resending and tweaking requests.

View Repository
6662 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Roxy

Minimal terminal-based HTTP/HTTPS intercepting proxy.

https://github.com/user-attachments/assets/94f9c9ae-5842-4b19-9f5b-84dedb9430e6

License: MIT Rust 2024

Features · Installation · HTTPS support · Usage · How it works

Overview

Roxy is a lightweight intercepting proxy for HTTP and HTTPS with a terminal user interface (TUI) written in Rust. It captures, inspects and modifies requests in real time, before they reach the server, from inside your terminal. Think of it as a minimal, terminal-native alternative to Burp Suite for everyday traffic analysis.

Features

  • HTTP interception — capture and inspect requests in real time before they reach the server.
  • HTTPS interception — full MITM support through CONNECT, with certificates generated automatically.
  • TLS passthrough (optional) — keeps HTTPS traffic untouched, either for every host or for a selected list.
  • Automatic certificate authority — a local CA is created on first HTTPS request and leaf certificates are issued per host on demand.
  • Request editing — modify intercepted requests on the fly with your $EDITOR.
  • Repeater — resend and tweak requests manually, in separate tabs, like Burp Suite's Repeater.
  • Command-line options — set the listening address with --host and --port, and decide which hosts get intercepted or passed through.
  • Custom TUI — clean and responsive interface built with ratatui.

Installation

Requirements

To build it from source you need:

RequirementNotes
Rust 1.85 or newerCheck with rustc --version.
A C compilergcc or clang.
$EDITOROnly needed for the request editing feature.

Build from source

git clone https://github.com/vid4l-07/Roxy.git
cd Roxy
cargo build --release

The binary will be available at target/release/roxy.

Install it straight from the repository

cargo install --git https://github.com/vid4l-07/Roxy.git

The binary will be available at ~/.cargo/bin/roxy.

HTTPS support

[!note] If HTTPS passthrough is enabled, HTTPS support is not required.

Where the certificates live

WhatLocationNotes
CA certificate and key~/.config/roxy/ca.crt, ~/.config/roxy/ca.keyCreated lazily, the first time an HTTPS request is intercepted.
Leaf certificate per host/tmp/roxy_certs/<host>.crt, /tmp/roxy_certs/<host>.keyIssued on demand and cached. The cache is wiped whenever a new CA is generated.

Trusting the Roxy CA

Roxy generates a self-signed CA named Roxy CA.

[!Warning] Every HTTPS request will fail validation until the CA is trusted by the client.

Install ~/.config/roxyca.crt in your browser or system.

You can also download it from the built-in web page at http://roxy (or http://<host>:<port>).

Firefox / Chrome:

  1. Settings → Privacy & Security → Certificates → View Certificates.
  2. Go to the Authorities tab and press Import.
  3. Select ~/.config/roxy/ca.crt.

System CA store For tools like curl.

# Debian / Ubuntu
sudo cp ~/.config/roxy/ca.crt /usr/local/share/ca-certificates/roxy.crt
sudo update-ca-certificates

# Fedora / RHEL / Arch
sudo cp ~/.config/roxy/ca.crt /etc/pki/ca-trust/source/anchors/roxy.crt
sudo update-ca-trust extract

To remove it again, delete the file and re-run the corresponding command.

Rotating or removing the CA

rm -rf ~/.config/roxy

Roxy generates a new CA on the next HTTPS request and removes every leaf certificate it had cached. You will have to trust the new CA again. Remember to remove the old one from your browser and system store.

Usage

Options

OptionDescription
-h, --host <HOST>Listening host. Defaults to 127.0.0.1.
-p, --port <PORT>Listening port. Defaults to 8080.
--passthroughTunnel HTTPS without decrypting it, for every host.
--passthrough-host <HOSTS>Same as --passthrough, but only for the listed hosts.
--intercept-https <HOSTS>Intercept these hosts even in passthrough mode.
--helpPrint the help message.
# Pass every host through untouched except the one you want to inspect
roxy --passthrough --intercept-https <HOSTS>

Global

KeyAction
qQuit
TabSwitch between Proxy and Repeater screens
?Open the help popup for the current screen

Proxy

KeyAction
iToggle intercept ON/OFF
EnterForward the intercepted request
eEdit request in external editor
uUndo edit
URedo edit
rSend request to Repeater
↑/kScroll up
↓/jScroll down

Repeater

KeyAction
EnterSend the current request
eEdit request in external editor
uUndo edit
URedo edit
rRename current tab
nNext repeater tab
pPrevious repeater tab
xClose current tab
zToggle zoom on the focused panel
↑/kScroll up
↓/jScroll down
←/h / →/lToggle focus between Request and Response panels
HDecrease Request panel width
LIncrease Request panel width

External Editor

When you press e, the raw request is written to a temporary file and opened with the binary defined by $EDITOR. Edit it, save, and quit. The modified request replaces the original and Content-Length is recalculated automatically.

How it works

  1. The listener accepts connections on 127.0.0.1:8080 by default, configurable with --host and --port, and handles each one in its own async task.
  2. A plain CONNECT request is answered with 200 Connection Established, TLS is terminated locally with a certificate issued for the requested host, and the decrypted request is read as a regular HTTP request. Hosts matched by the passthrough options are relayed to the real server instead, without terminating TLS.
  3. Any other request is read directly as plain HTTP, resolving the destination from the absolute target or the Host header.
  4. Intercept ON: the request is pushed to the TUI over a tokio::mpsc channel and the connection waits on a oneshot channel until the user forwards it. The request can be forwarded as-is, edited first, or sent to the Repeater.
  5. Intercept OFF: the request is forwarded immediately.
  6. Forwarding opens a connection to the upstream server (plain TCP for HTTP, TLS verified against webpki-roots for HTTPS), writes the request, and streams the raw response back to the client.
  7. The Repeater resends a stored request whenever you press Enter, choosing the transport based on the protocol the request was captured with, and shows the response side by side with the request.

The TUI and the proxy never share state directly. They only talk through the event channels, so the interface stays responsive while requests are being intercepted.

Contributions

Contributions are always welcome. If you find a bug or want to help with new features, you can:

  • Open an issue in the repository.
  • Open a pull request.

License

Roxy is released under the MIT License. © 2026 Hugo Vidal Martinez.

Download Tool