Manual

Capture HTTPS Traffic on iPhone Without a Mac

To sniff HTTPS traffic from iPhone apps without a Mac, run the capture on the phone. NetPeek records traffic through an on-device tunnel, so the iPhone is the only device involved. Install and fully trust NetPeek's local CA, add the host you are debugging to the MITM list, and send the request again. Two limits apply: an app that pins its certificate still shows no plaintext, and QUIC traffic has to fall back to TCP first.

Ways to inspect iPhone traffic and what each one needs

ApproachWhat you needCertificateWhere it falls short
Desktop proxy toolA computer running the proxy tool, with the iPhone able to reach it over a network. You point the iPhone's Wi-Fi settings at the proxy by hand.Install the tool's root certificate on the iPhone and turn on full trust in Certificate Trust Settings.Apps or SDKs that ignore the system proxy may never reach it.
Packet trace through a MacA Mac with Xcode, the iPhone attached by USB, and the rvictl command run in Terminal with the device's UDID.Not part of Apple's steps for recording the trace.Needs a Mac and a cable. The result is a packet trace, not a request list.
NetPeek on the iPhoneThe iPhone and the NetPeek app. No computer, no jailbreak. Allow the iOS VPN configuration when capture starts.Install and fully trust the NetPeek CA, then add hosts to the MITM list.Certificate-pinned apps and QUIC traffic still hide plaintext.

Apple documents the Mac route in Recording a Packet Trace. Each desktop proxy tool documents its own setup. If you are choosing between a desktop proxy and NetPeek, the comparison with a desktop proxy lists what each one covers.

Capture HTTPS on the iPhone itself

  1. Open NetPeek and tap Start Capture. Allow the iOS VPN configuration when prompted. The capture manual covers the list, filters, and request detail.
  2. Install and fully trust the NetPeek CA. Download the profile from the app, install it under Settings → General → VPN & Device Management, then turn on full trust under Settings → General → About → Certificate Trust Settings. The HTTPS manual has every step.
  3. Add the host you are debugging to the MITM list.
  4. Use the app, then open the new request. Rows captured before step 3 stay encrypted, so send the request again.

You turn on trust yourself because iOS does not trust a certificate you installed by hand until you enable it. Apple's support page on trusting manually installed certificates describes the setting, and Apple's deployment guide says automatic trust of additional root certificates takes a device management service. NetPeek generates the CA on the phone, and the private key is not uploaded.

When the phone alone fits better

The capture manual lists the cases where on-device capture tends to help compared with a desktop HTTP proxy. It is not a guarantee for every SDK or every background request.

  • The app uses a networking library that ignores the system proxy.
  • The bug only appears on cellular.
  • You are away from your desk with no computer.

When you still want a computer

A computer is optional. If you want an AI client on your computer to analyze captures, turn on the local MCP service. It is off by default, uses a token, and works over your trusted LAN or USB connection. See NetPeek MCP.

If plaintext is still missing

Check the usual causes in order: full trust is off in Certificate Trust Settings, the host is not on the MITM list, the app pins its certificate, or the traffic uses QUIC/HTTP3 and Block QUIC is off. The HTTPS manual explains each one. NetPeek does not bypass certificate pinning.

Export and repeat a request

Copy any request as cURL, export HAR for a bug report, or edit and resend it. See replay.

FAQ

Can I capture HTTPS on an iPhone without a Mac?

Yes. NetPeek captures on the iPhone itself, with no computer. HTTPS plaintext needs you to install and fully trust the NetPeek CA and add the host to the MITM list.

Do I need to jailbreak the iPhone?

No. NetPeek records traffic through the standard iOS on-device VPN tunnel API.

Is my capture data uploaded?

Not by NetPeek by default. Capture, storage, and inspection stay on the device. A client can read captures only if you enable MCP and give it the token. More in the FAQ.

Why do I only see the host for an HTTPS request?

The payload is encrypted until the CA is installed and fully trusted and the host is on the MITM list. Existing rows are not decrypted afterward.

Related: NetPeek manual · Home