A 5-minute checklist for your first DevPeek session. For screenshots, videos, and certificate walkthroughs, use the full quick-start guide on the website (中文).
The window is Capture / Debug work modes in the title bar, a request list on the left, details in the center, and closable tools on the right — not a feature sidebar.
- Windows or macOS with DevPeek installed (download)
- Phone and computer on the same Wi‑Fi (or routable LAN) if you capture a device
- A target H5 page or API you are authorized to debug
- Launch DevPeek (the tray launcher stays running after you close the window).
- Confirm the proxy is listening (default port 8888; shown in the title bar).
- Click the LAN IP in the title bar to copy
IP:port.
Menus: Proxy (recording, SSL, throttling, rules), View (Capture / Debug and right-side panels), Settings (preferences, certificates, import/export), About.
Sanity check: With system proxy enabled on this computer, browse locally — you should see requests in the Capture list.
Pick one path:
This computer
Enable Set as system proxy from the Proxy menu.
Android (1.4.0 Beta, preferred on phones)
Open the right-rail Phone panel and scan the pairing QR in the companion app. Approve the system VPN. You do not need to edit Wi‑Fi proxy.
Full path: Android companion · Website
iOS / fallback
On the phone Wi‑Fi settings, set HTTP proxy to manual:
Host: <your computer LAN IP>
Port: 8888
Each device appears as its own client tab (by IP).
- Install the DevPeek root CA on the same device that sends traffic.
- Desktop: Settings → certificate management (wizard / one-click).
- Android companion (after connect): Settings → Install certificate.
- iOS: install the profile, then enable full trust under Certificate Trust Settings.
- QR download still works for browsers that are not using the Android app.
- Open Proxy → SSL proxy settings.
- Include the hosts you want to decrypt (
*,*.example.com,*api*). - Exclude hosts that should stay tunnels (certificate mismatch, pinning, or sites you do not want to decrypt). Exclude wins when both match.
- Include the hosts you want to decrypt (
Sanity check: Browse HTTPS on that device. You should see decrypted method/URL/body — not endless CONNECT tunnels with empty bodies.
Stuck here? Proxy & SSL docs · Install guide
Stay on the Capture work mode (title-bar switch):
- Select the client tab.
- Click a request on the left → inspect Overview / Headers / Body in the center (read-only).
- Search URL, Host, or response body; pin important rows; filter by protocol / method / content type.
- Right-click a row to create Mock, param transform, or a forward rule from that request.
- Need to change a parameter and send again? Open Debug API (details Debug button, list context menu, or
R) — a bottom drawer, not a permanent module.
Next: Param transform if fields are still encrypted at the app layer.
WebSocket / WSS sessions sit under the HTTP list. Multi-turn mocks: WebSocket & WS Flow.
When the page is HTML served through the proxy:
- Switch the title bar (or View menu) to Debug.
- Select the same phone client tab.
- Refresh the page on the phone.
DevPeek mirrors the page and opens built-in Elements / Console / Network / Session panels — not desktop Chrome DevTools.
Guide: Mobile H5 debugging · Website
| Symptom | Likely cause |
|---|---|
| No requests at all | Wrong LAN IP, firewall, AP isolation, or Android VPN not approved |
Only CONNECT, no body |
CA not trusted, host missing from include, or host hit the exclude list |
| HTTPS works in Chrome but not in an Android app | That app rejects user CAs or pins certificates |
| Debug stuck on “waiting for device” | Page not injectable HTML, or SSL/proxy prerequisites not met |
| HTTPS works on PC but not phone | Phone CA install incomplete (especially iOS trust step) |
More: FAQ on website
- Encrypted JSON fields → Param transform
- Android scan + file transfer → Android companion
- Compare with Charles/Fiddler → Charles alternative
- Example configs → examples/
- WebSocket Flow → websocket.md