Show HN: I built a free Burp/Caido alternative but, zero setup - API Testing
Apiaxess is a free, zero-setup Burp and Caido alternative for capturing and testing web and mobile APIs.
Apiaxess is a free Apache-2.0 API testing workbench positioned as a zero-setup alternative to Burp Suite and Caido. It provides a pre-trusted Android emulator and an isolated Chromium browser, captures and decrypts traffic, and supports replay, fuzzing, and Intruder-style attacks. On a 17-endpoint reference Android app, the authors report finding, capturing, and confirming all 17 endpoints. Version 0.1.0 exports OpenAPI 3.1, Postman, HAR, and a Python client for Windows, Linux, and macOS.
- Zero-setup proxy with a pre-trusted Android emulator and isolated browser.
- Reference test captured and confirmed all 17 documented Android endpoints.
- Apache-2.0 release v0.1.0 exports OpenAPI, Postman, HAR, and Python.
Full article391 words · extracted from apiaxess.dev · click to collapse
A browser already routed through the proxy. An Android emulator that already trusts the certificate. One session, nothing to set up.
try it → click a row, then Send to Resend
apiaxess
Go to surface, flow, endpoint or command⌘K
api.northwind-retail.ioLive control connected
Sessionsession:2l1a434f3f6b1a
Capture
Analyse
Deliver
Capture health
Intercept matching requestsAny method Any status filter: host, path, method, status1,204 flows
MethodPathStMsSize
POST/v1/cart/items201
- host
- api.northwind-retail.io client
- Web capture scope
- In declared scope
- Bearer eyJhbGciOi…Qm9
- application/json
authorization
content-type
Intercept queue 0Diagnostics 0Control · reliable
No paused requestsWith intercept on, matching requests pause here until you forward, modify or drop them.
WORKBENCHsession:2l1a434f3f6b1aControlTelemetry127.0.0.1
2,481Flows captured
128Endpoints merged
9Only the app calls
0Setup steps
From a sample session on the Northwind demo app.
Measured, not claimed.
We built a reference Android app with 17 documented endpoints (Retrofit, OkHttp, HttpURLConnection and GraphQL, plus a third-party host and calls behind taps and a second screen) and scored apiaxess against it.
Static17/17
Found from the code, zero phantom endpoints.
Live capture17/17
Decrypted while the app ran.
Fused17/17
Each one confirmed by both.
Capture both clients. Keep the evidence.
01Mobile
A phone you never had to prepare.
Boots already trusting the certificate. Install an APK, drive it, read the traffic. Pinned apps included.
02Web
A browser that already trusts you.
Its own Chromium on an isolated profile, routed through the proxy. Your browser is never touched.
03Workbench
See it live. Resend it. Fuzz it.
Replay any request, or run a full Intruder-class attack. Four attack types, no throttling.
04Export
Leave with a spec, not a screenshot.
OpenAPI 3.1, Postman, HAR and a Python client, from one command.
It won’t make things up.
- Every endpoint is labelled confirmed or inferred-from-code, first-party or third.
- Your own Resend and Fuzz traffic never leaks into the recovered surface.
- And when something can’t be done, like an app whose pinning can’t be beaten, apiaxess tells you so instead of showing you an empty list.
Nine endpoints a browser-only session never sees.
Open source. Read every line.
Apache-2.0 licensed. Check how the certificate is made, confirm there’s no telemetry, build it yourself.
Point it at an app. Read the API.
v0.1.0WindowsLinuxmacOS next