Testing tools for web development & security.
Hexbuffer is a local-first desktop suite to inspect HTTP traffic, modify requests mid-flight, replay and fuzz endpoints, and organize reconnaissance notes.
Built-in modules for every phase of testing.
Seven dedicated desktop tools engineered for web application reconnaissance, traffic analysis, and vulnerability discovery.

HTTP History
Core ProxyLive Traffic Stream & Deep Inspection
Capture and inspect every HTTP and HTTPS transaction in real-time. Analyze request headers, query parameters, multipart bodies, and response latency with zero lag.
HTTP History
Capture and inspect every HTTP and HTTPS transaction in real-time. Analyze request headers, query parameters, multipart bodies, and response latency with zero lag.
Intercept
Hold live HTTP traffic mid-flight before it hits the target server or browser. Modify headers, rewrite request bodies, swap parameters, or drop unwanted packets on the fly.
Repeater
Fine-tune HTTP requests and reissue them instantaneously. Analyze response status, headers, and body payloads across test iterations.
Intruder
Pinpoint vulnerability surfaces with automated attacks. Place custom payload markers across headers or parameters, attach wordlists, and sort results by response delta.
Port Scanner
Scan target hosts for open ports and running network services. Leverage preset port collections, stealth connection modes, and banner grabbing in a dedicated tab.
JWT Analyzer
Inspect, decode, and tamper with JSON Web Tokens. Edit header algorithms, modify payload claims, verify signatures, and audit for weak keys or none-algorithm flaws.
Notes & Scratchpad
Record reproduction steps, store sample payloads, and document active targets without context switching. Notes persist seamlessly across your local sessions.
Who is Hexbuffer for?
Tailored for security engineers, penetration testers, and developers requiring fast, private local reconnaissance.
Penetration Testers
A dedicated local workstation for intercepting, inspecting, and manipulating live target HTTP traffic.
Security Researchers
Deep request and response payload inspection with automated fuzzing and token tampering.
Developers & QA
Debug web APIs, mock scenarios, and verify endpoint behavior with instant request replay.
Try Hexbuffer on your next target.
A lightweight desktop workspace for HTTP inspection, request interception, payload testing, and API debugging.
macOS available now