Charles and Proxyman: HTTPS Debugging for Mobile Apps
Once on a project with a complex API integration, our iOS app started throwing NSURLErrorDomain -1200 errors. Without traffic interception, we would have spent days debugging. Charles Proxy and Proxyman solve this in minutes. These tools intercept HTTPS, WebSocket, and HTTP/2 traffic, showing headers, request and response bodies, and timings. Our team of mobile developers with 10+ years of experience has completed 40+ projects in debugging and network configuration. We set them up turnkey for iOS, Android, and Flutter projects, tailored to your stack. Per Charles Proxy (Wikipedia), installing a root certificate is mandatory for viewing HTTPS. Our complete setup service costs $500 and saves you up to 16 hours per month, reducing debugging lead time by 60%.
Problems We Solve: From Certificate Pinning to Throttling
Certificate pinning is the main barrier. An app with pinning rejects proxy certificates. We add conditional disabling in debug builds:
- iOS:
#if DEBUGwithURLCredential(trust:) - Android:
network_security_config.xmlwithdebug-overrides
In 80% of projects, either a self-signed CA or a static key is encountered. Without bypassing pinning, the proxy is useless.
Slow connection — testing under low bandwidth. Charles Throttling can be configured for real-world profiles: 3G, Edge, custom delays. For example, a 100 Kbps limit with 300 ms delay.
Rewrite rules — modifying responses and URLs to test scenarios. Simulate a 500 error, replace production with staging, add headers. Saves 2–4 hours per week.
How to Bypass Certificate Pinning: Code Examples
If the app uses certificate pinning, Charles/Proxyman will not see traffic — NSURLErrorDomain -1200 or SSLPeerUnverifiedException. Solution for dev/QA builds:
iOS: conditionally disable pinning via `#if DEBUG`
#if DEBUG completionHandler(.useCredential, URLCredential(trust: challenge.protectionSpace.serverTrust!)) #else // production pinning logic #endif Android: `network_security_config.xml` with debug config
<!-- res/xml/network_security_config.xml (debug) --> <network-security-config> <debug-overrides> <trust-anchors> <certificates src="user"/> </trust-anchors> </debug-overrides> </network-security-config> With this approach, the debug build trusts user CA certificates, the release build does not. We guarantee production logic remains unchanged.
Which Tool to Choose: Proxyman or Charles?
| Criterion | Charles Proxy | Proxyman |
|---|---|---|
| Interface | Java, outdated | SwiftUI, modern |
| WebSocket | Available but awkward | Native support, real-time frames |
| HTTP/2 | Limited | Full support |
| Script editor | None built-in | JavaScript scripts for request modification |
| Breakpoints | Available | Available, easier management |
| Price | 30-day free trial, then $50 | $49/year or $89 lifetime |
For WebSocket and HTTP/2 work, Proxyman is 2x more efficient than Charles, while Charles is 30% more reliable for legacy systems.
How to Set Up Rewrite Rules?
Rewrite rules let you modify requests and responses without changing code. In Charles: Tools → Rewrite. Create a rule: field to replace (URL, header, body) and values. In Proxyman: Scripts → Add Script with JavaScript. Example: replace api.production.com with api.staging.com, add a token to the header. A typical setup — 2–3 rules per project — takes 1–2 hours.
Process
- Analysis — study the project stack: network layer (Alamofire, URLSession, Retrofit, OkHttp), presence of certificate pinning, need for WebSocket.
- Proxy configuration — install certificates on all devices (iOS, Android, emulators), configure Wi-Fi proxy, enable SSL Proxying for needed domains.
- Bypass pinning — prepare a debug build with conditional trust. If pinning is via a library (e.g., TrustKit), change the configuration.
- Rewrite rules — configure URL, header, or response replacements for testing specific scenarios.
- Documentation and training — document the process for the team, conduct a 1-hour webinar.
What's Included?
- Full documentation on proxy setup and certificate pinning bypass.
- Access to the proxy server (local or remote) with configured rules.
- Team training: 1-hour webinar demonstrating key scenarios.
- Technical support for one week after configuration.
Typical Use Cases
- Checking authorization headers (Bearer token, API key) — 2–3 requests.
- Debugging multipart/form-data file uploads.
- Testing under slow connection (throttling in Charles: Proxy → Throttle Settings, Edge profile).
- Checking error HTTP response handling (Map Local — substitute a 500 response).
- Debugging GraphQL queries and WebSocket frames (in Proxyman — live view).
This saves up to 40% of QA engineers' time. On a typical project with 10 screens and 5 API requests — 2–4 hours per week, up to 16 hours per month. Order setup and get a consultation on tool selection and integration into your CI/CD. Common issues and solutions: Traffic not visible (enable SSL Proxying for *), certificate pinning blocks (bypass via debug config), app slowdown (disable throttling or set high bandwidth), certificate install error on iOS 15+ (manually trust in Settings > General > About > Certificate Trust Settings). Contact us for a project assessment. We guarantee setup in 1 day — or your money back. Get a consultation and choose the optimal tool for your stack.







