What Charles Proxy does and why you'd use it

Charles Proxy is a tool that sits between your browser and the internet and records every request your computer sends and every response it receives. When you load a webpage or use an app, your device talks to servers in the background — asking for data, sending form submissions, loading images. Charles shows you exactly what those conversations look like, in plain text, before encryption scrambles them.

Developers use Charles to debug why a feature isn't working, to understand how a competitor's app fetches data, or to test whether their own API is sending the right information. If you're building a website or app and something feels broken on the backend, Charles lets you see the actual request and response instead of guessing.

The tool works on Windows, Mac, and Linux. It costs $50 for a perpetual license after a 30-day free trial, though the trial has no feature limits — you can test everything before you pay.

Key Takeaways

  • Charles Proxy intercepts traffic between your device and servers, showing you the exact requests and responses your browser sends.
  • You install Charles as an application, configure your browser or system to route traffic through it, and then browse normally while Charles records everything.
  • The Recorder tab shows all requests in a list; click any request to see its headers, body, and response in the Inspector panel below.
  • HTTPS traffic is encrypted by default, but Charles can decrypt it if you install its certificate in your browser's trust store.
  • You can filter requests by domain, pause recording, or replay requests to test how your API behaves under different conditions.

Installing Charles and routing traffic through it

Download Charles from charlesproxy.com and install it like any other application. When you open it, you'll see a mostly empty window — that's normal. Charles is waiting to intercept traffic.

Next, tell your browser to send traffic through Charles. On Windows or Mac, open Charles and go to Proxy > Proxy Settings. Note the port number shown (usually 8888). Then open your browser's network settings and set the HTTP and HTTPS proxy to localhost (or 127.0.0.1) and that port number. On Chrome, go to Settings > Advanced > System > Open proxy settings. On Firefox, go to Settings > Network Settings > Manual proxy configuration.

Once configured, load any webpage. You should see requests start appearing in Charles's main window. If nothing appears, check that the proxy port in Charles matches the port in your browser settings.

Reading the request and response in the Inspector

Charles's main window shows a tree of domains on the left and a list of requests on the right. Click any request to open the Inspector panel at the bottom. The Inspector has tabs: Request, Response, Summary, and others.

The Request tab shows what your browser sent: the HTTP method (GET, POST, etc.), the URL path, the headers (like User-Agent or Authorization), and the body (the actual data, if any). For a login form, the body might contain your username and password in plain text — which is why HTTPS matters.

The Response tab shows what the server sent back: the HTTP status code (200 means success, 404 means not found), the response headers, and the response body (usually JSON or HTML). If an API call fails, the response body often contains an error message that tells you why.

The Summary tab shows timing — how long each step took, from DNS lookup to the final byte received. If a request is slow, this tab helps you see whether the delay is in the network, the server processing, or somewhere else.

Decrypting HTTPS traffic to see encrypted requests

By default, Charles can see that an HTTPS request happened, but not what data it contained — the connection is encrypted end-to-end. To decrypt HTTPS traffic so you can read the request and response bodies, you need to install Charles's certificate in your browser's certificate store.

In Charles, go to Help > SSL Proxying > Install Charles Root Certificate. On Mac, this opens Keychain and adds the certificate automatically. On Windows, it opens the certificate import dialog; click through and choose to trust the certificate. On Linux, the process varies by browser, but Charles will guide you.

Once installed, Charles can decrypt HTTPS traffic for any domain. However, you may need to enable SSL proxying for specific domains. Go to Proxy > SSL Proxying Settings, click Add, and enter the domain (for example, api.example.com). Leave the port blank to intercept all ports. Now Charles will show you the decrypted request and response for that domain.

Filtering requests and focusing on what matters

If you're debugging a single API endpoint, Charles's full request list can be overwhelming. Use the Filter field at the top of the window to show only requests matching a keyword. Type the domain name or part of the URL path, and Charles will hide everything else.

You can also use Proxy > Recording Settings to exclude certain domains entirely. For example, if you're testing your own API but don't want to see requests to Google Analytics or ad networks, add those domains to the exclude list. Charles will still intercept them, but they won't clutter the display.

To pause recording without closing Charles, click the red circle icon in the toolbar or press Ctrl+Alt+R (Cmd+Alt+R on Mac). This is useful if you want to examine requests you've already captured without new ones appearing.

Replaying requests to test your API

Once you've captured a request, you can replay it to test how your API responds to the same input. Right-click any request in the list and select Repeat. Charles sends the exact same request again, and you'll see the new response appear in the Inspector.

This is useful for testing edge cases. Capture a request that causes an error, then modify it and replay it to see if your fix works. Right-click and select Edit and Repeat to change the request body, headers, or URL before sending it again.

You can also use Tools > Repeat to send the same request multiple times in quick succession, which helps you test how your API handles load or concurrent requests.

Exporting requests for documentation or debugging

If you need to share a request with a teammate or include it in a bug report, right-click the request and select Copy as cURL. This gives you a command-line version of the request that anyone can run in a terminal to reproduce the same call.

You can also export the entire session. Go to File > Export and choose a format: HAR (HTTP Archive) is the standard format that other tools can read, or you can export as XML or JSON. This is useful for archiving a debugging session or analyzing traffic patterns later.

Frequently Asked Questions

Why can't I see the request body for HTTPS requests?

HTTPS encrypts the connection, so Charles can see that a request happened but not what it contained. Install Charles's root certificate in your browser's certificate store, then enable SSL proxying for the domain you're debugging. Charles will then decrypt the traffic so you can read the bodies.

Does Charles slow down my internet?

Slightly. Charles sits between your device and the internet, so every request passes through it. The overhead is usually small — a few milliseconds per request — but if you're testing performance-sensitive code, disable Charles or use a separate browser profile for testing.

Can I use Charles to intercept traffic from my phone?

Yes. On your phone, go to Wi-Fi settings, find your network, and set the HTTP proxy to your computer's IP address and Charles's port (usually 8888). Then open Charles on your computer and go to Proxy > Proxy Settings to allow connections from other machines. Install Charles's certificate on your phone the same way you would on a desktop browser.

What if I see a request I don't recognize?

Click the request and look at the domain in the URL. If it's a third-party service (analytics, ads, CDN), it's probably legitimate. If it's your own domain and you don't recognize it, search your codebase for that URL path — it's likely a background request from a library or script you're using.

Can I use Charles to see what data a website is sending about me?

Yes. Set up Charles, visit the website, and look at the requests. You'll see what data is being sent to analytics services, ad networks, and other third parties. This is a useful way to understand what information a site collects, though remember that some data is encrypted and Charles can only decrypt it if you install its certificate.