Can I capture HTTPS on an iPhone without a Mac?
Yes. NetPeek captures on the iPhone itself, with no computer. HTTPS plaintext needs you to install and fully trust the NetPeek CA and add the host to the MITM list.
Manual
To sniff HTTPS traffic from iPhone apps without a Mac, run the capture on the phone. NetPeek records traffic through an on-device tunnel, so the iPhone is the only device involved. Install and fully trust NetPeek's local CA, add the host you are debugging to the MITM list, and send the request again. Two limits apply: an app that pins its certificate still shows no plaintext, and QUIC traffic has to fall back to TCP first.
| Approach | What you need | Certificate | Where it falls short |
|---|---|---|---|
| Desktop proxy tool | A computer running the proxy tool, with the iPhone able to reach it over a network. You point the iPhone's Wi-Fi settings at the proxy by hand. | Install the tool's root certificate on the iPhone and turn on full trust in Certificate Trust Settings. | Apps or SDKs that ignore the system proxy may never reach it. |
| Packet trace through a Mac | A Mac with Xcode, the iPhone attached by USB, and the rvictl command run in Terminal with the device's UDID. | Not part of Apple's steps for recording the trace. | Needs a Mac and a cable. The result is a packet trace, not a request list. |
| NetPeek on the iPhone | The iPhone and the NetPeek app. No computer, no jailbreak. Allow the iOS VPN configuration when capture starts. | Install and fully trust the NetPeek CA, then add hosts to the MITM list. | Certificate-pinned apps and QUIC traffic still hide plaintext. |
Apple documents the Mac route in Recording a Packet Trace. Each desktop proxy tool documents its own setup. If you are choosing between a desktop proxy and NetPeek, the comparison with a desktop proxy lists what each one covers.
You turn on trust yourself because iOS does not trust a certificate you installed by hand until you enable it. Apple's support page on trusting manually installed certificates describes the setting, and Apple's deployment guide says automatic trust of additional root certificates takes a device management service. NetPeek generates the CA on the phone, and the private key is not uploaded.
The capture manual lists the cases where on-device capture tends to help compared with a desktop HTTP proxy. It is not a guarantee for every SDK or every background request.
A computer is optional. If you want an AI client on your computer to analyze captures, turn on the local MCP service. It is off by default, uses a token, and works over your trusted LAN or USB connection. See NetPeek MCP.
Check the usual causes in order: full trust is off in Certificate Trust Settings, the host is not on the MITM list, the app pins its certificate, or the traffic uses QUIC/HTTP3 and Block QUIC is off. The HTTPS manual explains each one. NetPeek does not bypass certificate pinning.
Copy any request as cURL, export HAR for a bug report, or edit and resend it. See replay.
Yes. NetPeek captures on the iPhone itself, with no computer. HTTPS plaintext needs you to install and fully trust the NetPeek CA and add the host to the MITM list.
No. NetPeek records traffic through the standard iOS on-device VPN tunnel API.
Not by NetPeek by default. Capture, storage, and inspection stay on the device. A client can read captures only if you enable MCP and give it the token. More in the FAQ.
The payload is encrypted until the CA is installed and fully trusted and the host is on the MITM list. Existing rows are not decrypted afterward.
Related: NetPeek manual · Home