Quickstart & Workspace Setup
Learn how to install Hexbuffer, configure HTTPS proxying, install CA certificates, and start testing in minutes.
Getting Started with Hexbuffer
Welcome to Hexbuffer! This guide walks you through launching the desktop application, configuring network proxying, installing the Root Certificate Authority (CA) certificate for secure HTTPS interception, and capturing your first live HTTP traffic.
Step 1: Launching Hexbuffer
After installing Hexbuffer on your operating system (macOS, Windows, or Linux), open the desktop application. You will be greeted by the Modular Desktop Dashboard.
Desktop Workspace Overview
- Modular Widget Grid: Customize and rearrange widgets for:
- Target Widget: Manage and activate the domain scope used for monitoring.
- Proxy Widget: Quickly toggle the proxy server, view the active listening port, and check status.
- VPN Widget: Manage OpenVPN configuration files and connect with a log panel.
- Clipboard Widget: Access recently copied snippets, URLs, and authentication tokens.
- Collections & Recent Apps Widgets: Access pinned request collections and recently opened apps.
- Scratchpad Widget: Fast, persistent scratch area for transient payloads and notes—shared with the Notes module.
- Left Navigation Sidebar: Instant access to HTTP History, Intercept, Repeater, Intruder, API tools, Notes, and Settings.
- Shortcut Manager: A quick overview of all tools and widgets on the desktop.
Step 2: Setting Up HTTPS Proxying & CA Certificate
To inspect encrypted HTTPS traffic between your web browser or API clients and target servers, Hexbuffer operates as a local Man-in-the-Middle (MITM) proxy.
1. Enable the Proxy
- Click on Settings in the left sidebar (or use the Proxy Widget on the Desktop).
- Under General settings, verify the proxy listener port (default:
8080) and save your changes. - Start the proxy and confirm the "running on" indicator appears.
2. Install the Root CA Certificate
- In Settings, navigate to the CA Certificate tab.
- Download the proxy CA certificate or use the one-click Install to macOS Keychain action.
- Follow the setup guide to add the Hexbuffer Root Certificate to your operating system's trusted certificates (macOS Keychain, Windows Certificate Manager, or Linux system store).
- For Firefox or custom HTTP clients, import the exported certificate directly into the browser's certificate authority store.
- Restart your browser or HTTP client to ensure it loads the newly trusted certificate.
Step 3: Capturing Your First Request
Now that your proxy and certificates are configured:
- Open your browser or configure your application to use
127.0.0.1:8080as its HTTP/HTTPS proxy. - Navigate to any target web page or send an API request.
- Switch back to Hexbuffer and select HTTP from the sidebar.
- You will see requests streaming in real time, displaying HTTP methods, status codes, response times, content lengths, and endpoint paths.
Step 4: Adding Target Scopes
To keep your workspace organized and eliminate noise from background operating system traffic:
- Click Scope Settings at the top of the Live Traffic view (or use the Desktop Target Widget).
- Enter your target domain (e.g.,
*.example.comorapi.myapp.dev). - Toggle Filter by Scope to hide irrelevant background traffic.
[!TIP] Quick Actions: Right-click any request in the Live Traffic grid to immediately Add to Scope, Send to Repeater, Send to Intruder, Send to API Override, or Copy as cURL.
Privacy & Local-First Model
Hexbuffer is designed with a strict local-first architecture:
- All proxy traffic logs, database sessions, and project notes are stored locally in an embedded SQLite database on your device.
- No network captures or sensitive credentials are ever transmitted to third-party telemetry servers.
- Storage management is available in Settings → General, where you can inspect database sizes, truncate logs, or wipe local data.
Next Steps
Explore the core Hexbuffer feature guides: