Docs

Minimal setup notes for common workflows: certificates (MITM), passthrough, HTTP/2 toggle, and limits. If something looks missing, email us.

macOS 14+ is recommended. Some operations may prompt for administrator privileges.

Installing root CA (for HTTPS MITM)

Installing a root CA lets PULSE Peek decrypt HTTPS traffic for inspection. Only do this on machines you control.

Certificate files are stored in ~/.pulsepeek/certs/.
PULSE Peek generates per-host certificates from a local root CA.

Recommended (in-app)

Use the Certificates panel to generate and install the root certificate.

Manual (Keychain Access)

If you prefer manual steps:

1) Open Keychain Access.
2) Import the root CA file from ~/.pulsepeek/certs/.
3) Set it to Always Trust for SSL.

Security note: trusting a root CA allows interception of HTTPS traffic. Remove it when you’re done.

Passthrough hosts

For hosts you don’t want to MITM (or that break under MITM), add them to passthrough. Traffic will be tunneled without decryption.

Example CSV: api.example.com,cdn.example.com

HTTP/2 toggle

HTTP/2 is supported. If a client behaves oddly while capturing, disable the HTTP/2 MITM toggle to force HTTP/1.1.

Limits

To keep things responsive and safe, captured bodies have size limits. Very large payloads may be truncated or summarized in the UI.

Body size: up to 5 MB per request and 5 MB per response.

zstd (optional)

If you capture traffic encoded with Content-Encoding: zstd, PULSE Peek can decode it when the local CLI is available.

Install: brew install zstd

If zstd isn’t installed, PULSE Peek still works, but decoding may show a warning.

Need help?

Email support with your macOS version and a short description of what you tried. Contact: [email protected]