Hexbuffer
Getting Started

Quickstart & Workspace Setup

Learn how to install Hexbuffer, configure HTTPS proxying, install CA certificates, and start testing in minutes.

Getting Started with Hexbuffer

Welcome to Hexbuffer! This guide walks you through launching the desktop application, configuring network proxying, installing the Root Certificate Authority (CA) certificate for secure HTTPS interception, and capturing your first live HTTP traffic.


Step 1: Launching Hexbuffer

After installing Hexbuffer on your operating system (macOS, Windows, or Linux), open the desktop application. You will be greeted by the Modular Desktop Dashboard.

Desktop Workspace Overview

  • Modular Widget Grid: Customize and rearrange widgets for:
    • Target Widget: Manage and activate the domain scope used for monitoring.
    • Proxy Widget: Quickly toggle the proxy server, view the active listening port, and check status.
    • VPN Widget: Manage OpenVPN configuration files and connect with a log panel.
    • Clipboard Widget: Access recently copied snippets, URLs, and authentication tokens.
    • Collections & Recent Apps Widgets: Access pinned request collections and recently opened apps.
    • Scratchpad Widget: Fast, persistent scratch area for transient payloads and notes—shared with the Notes module.
  • Left Navigation Sidebar: Instant access to HTTP History, Intercept, Repeater, Intruder, API tools, Notes, and Settings.
  • Shortcut Manager: A quick overview of all tools and widgets on the desktop.

Step 2: Setting Up HTTPS Proxying & CA Certificate

To inspect encrypted HTTPS traffic between your web browser or API clients and target servers, Hexbuffer operates as a local Man-in-the-Middle (MITM) proxy.

1. Enable the Proxy

  1. Click on Settings in the left sidebar (or use the Proxy Widget on the Desktop).
  2. Under General settings, verify the proxy listener port (default: 8080) and save your changes.
  3. Start the proxy and confirm the "running on" indicator appears.

2. Install the Root CA Certificate

  1. In Settings, navigate to the CA Certificate tab.
  2. Download the proxy CA certificate or use the one-click Install to macOS Keychain action.
  3. Follow the setup guide to add the Hexbuffer Root Certificate to your operating system's trusted certificates (macOS Keychain, Windows Certificate Manager, or Linux system store).
  4. For Firefox or custom HTTP clients, import the exported certificate directly into the browser's certificate authority store.
  5. Restart your browser or HTTP client to ensure it loads the newly trusted certificate.

Step 3: Capturing Your First Request

Now that your proxy and certificates are configured:

  1. Open your browser or configure your application to use 127.0.0.1:8080 as its HTTP/HTTPS proxy.
  2. Navigate to any target web page or send an API request.
  3. Switch back to Hexbuffer and select HTTP from the sidebar.
  4. You will see requests streaming in real time, displaying HTTP methods, status codes, response times, content lengths, and endpoint paths.

Step 4: Adding Target Scopes

To keep your workspace organized and eliminate noise from background operating system traffic:

  1. Click Scope Settings at the top of the Live Traffic view (or use the Desktop Target Widget).
  2. Enter your target domain (e.g., *.example.com or api.myapp.dev).
  3. Toggle Filter by Scope to hide irrelevant background traffic.

[!TIP] Quick Actions: Right-click any request in the Live Traffic grid to immediately Add to Scope, Send to Repeater, Send to Intruder, Send to API Override, or Copy as cURL.


Privacy & Local-First Model

Hexbuffer is designed with a strict local-first architecture:

  • All proxy traffic logs, database sessions, and project notes are stored locally in an embedded SQLite database on your device.
  • No network captures or sensitive credentials are ever transmitted to third-party telemetry servers.
  • Storage management is available in Settings → General, where you can inspect database sizes, truncate logs, or wipe local data.

Next Steps

Explore the core Hexbuffer feature guides:

On this page