BlogScreenshots on your device
What Fiddler Capture Is and How to Use It
Learn how Fiddler Everywhere captures HTTP, HTTPS, WebSocket, SSE and gRPC traffic, including proxy setup, HTTPS certificates and troubleshooting.
Fiddler capture is proxy-based traffic inspection. Fiddler Everywhere sits between a client and the network, records requests and responses, and lets you inspect, filter, replay, mock and share sessions. In system-capturing mode, it sees HTTP, HTTPS, WebSocket, Server-Sent Events (SSE) and gRPC traffic that the client sends through the operating-system proxy.
The fastest setup is: install Fiddler Everywhere, enable System Proxy from the Home or Traffic pane, trust the Fiddler root certificate for HTTPS, then make a request from a browser or application that honors the system proxy. Disable the proxy when finished.
1. What Fiddler capture does
Fiddler Everywhere is a debugging proxy. A captured session normally includes the request method, URL, headers, cookies, body, timing information, response status, response headers and response body. You can use those sessions to:
- Find why a request fails or returns an unexpected status.
- Compare headers, cookies and payloads between working and failing clients.
- Identify slow requests and performance bottlenecks.
- Mock requests and responses during development.
- Save and share sessions with another developer.
Capture only works for traffic routed through the selected Fiddler mode. A request can exist in the browser or application while remaining absent from Fiddler if that client bypasses the system proxy, uses a separate proxy, or a filter hides the session.
2. Install Fiddler Everywhere
- Download and install Fiddler Everywhere from the official Telerik Fiddler page.
- Start the application and complete its first-run setup.
- Open the Home pane and follow the System Proxy tutorial. If the Fiddler CA is already installed and trusted, you can open Traffic and turn System Proxy on directly.
Fiddler Everywhere remembers the last System Proxy switch state and starts with capture in that state. Check the switch before debugging, and turn it off when you no longer want supported applications routed through Fiddler.
3. Capture HTTP traffic with System Proxy
- Open Traffic and enable System Proxy.
- Open a new browser tab or another application that uses the operating-system proxy.
- Visit any HTTP or HTTPS address.
- Return to the Live Traffic grid. The request should appear as a new session.
- Select the session to inspect request headers, query parameters, body, response data and timing.
The documented default listening port is 8866. You can change it under Settings > Connections. HTTP/2 capture is enabled by default in the documented configuration; labels can vary slightly between installed builds.
Generate a request explicitly through Fiddler
If you want to prove that a command-line client is using the proxy, send a request through the listening port:
curl -x http://127.0.0.1:8866 http://example.com
For an HTTPS test, Fiddler must be trusted for decryption. During a temporary command-line check, -k disables curl’s certificate verification, but do not use that flag as a production security setting:
curl -x http://127.0.0.1:8866 -k https://example.com
4. Capture HTTPS traffic safely
After initial startup, Fiddler Everywhere captures only non-secure HTTP traffic by default. HTTPS decryption requires the Fiddler root CA to be installed and trusted.
- Open Settings > HTTPS.
- Use the in-app control to generate, install and trust the Fiddler CA.
- Enable HTTPS decryption for the traffic you need to inspect.
- Reload the target page or repeat the request.
On Windows and macOS, Fiddler can trust the certificate in the operating-system user certificate store. Windows also offers installation into the machine certificate store; that applies to all users and requires administrator privileges. On Linux, export the CA and trust it manually using your distribution’s certificate-store process.
Install the CA only through the official Fiddler Everywhere application. The certificate allows Fiddler to inspect secure traffic routed through its proxy, so remove or reset the CA when you finish work that requires it. The HTTPS settings include a reset action that removes the current CA, creates a new one and trusts it.
5. Choose the right capture mode
| Mode | Best for | Proxy requirement | HTTPS setup |
|---|---|---|---|
| System Proxy | Browsers and applications that honor operating-system proxy settings | Fiddler changes the system proxy while enabled | Trust the Fiddler CA on the host |
| Dedicated browser | Capturing a browser session without changing every system application | Use Fiddler’s browser-capture workflow | Use the mode’s certificate instructions |
| Terminal | Command-line tools and scripts | Configure the terminal client or use Fiddler’s terminal mode | Trust the CA in the client when HTTPS is decrypted |
| Manual proxy | Applications or devices with their own proxy fields | Set the host and port explicitly | Trust the CA on that client or device |
| Remote device | iOS and Android traffic | Point the device at the host proxy and allow network access | Trust the Fiddler CA on the device |
Use System Proxy when the client follows operating-system settings. Use a dedicated browser or terminal mode when you need isolation. For phones and tablets, the device normally needs the computer’s reachable address and proxy port; local firewall rules, Wi-Fi isolation or corporate network policy can prevent the connection. Some applications ignore proxy settings or use certificate pinning, so they may remain invisible or fail when HTTPS inspection is enabled.
6. Inspect, filter and work with sessions
Inspect a request
- Overview: status, method, host, URL and timing.
- Request: query string, headers, cookies and body.
- Response: status, headers, cookies, body and transfer details.
- Timing: use the request timeline to locate slow DNS, connection, server or download phases.
Use filters carefully
Filters help reduce noise, but they can also hide the request you are looking for. When a session is missing, clear or broaden filters before changing application code. Filter by host, URL, status, method or process only after confirming that capture is enabled.
Mock and replay
Captured sessions can be used to mock responses while developing a client, or replayed to compare behavior after a code change. Treat captured cookies, authorization headers and personal data as sensitive. Remove secrets before sharing a session.
7. Capture a remote iOS or Android device
- Connect the device and computer to a network where the device can reach the computer.
- Find the computer’s reachable local IP address.
- Configure the device’s Wi-Fi or network proxy to use that address and Fiddler’s listening port, commonly 8866.
- Install and trust the Fiddler CA on the device using Fiddler’s official certificate workflow.
- Enable capture, generate traffic on the device and watch the Live Traffic grid.
If nothing appears, first test connectivity to the host and port. Then check firewall rules, VPN routing, Wi-Fi client isolation and whether the app ignores the device proxy. Certificate pinning can also prevent HTTPS inspection even when ordinary browser traffic works.
8. Troubleshooting missing or broken captures
| Symptom | Likely cause | Fix |
|---|---|---|
| No sessions at all | System Proxy or the chosen mode is disabled | Enable the mode and repeat a request. |
| Browser works but app traffic is absent | The app bypasses system proxy settings | Use the app’s manual proxy settings, a supported Fiddler mode or a client-specific configuration. |
| HTTP appears but HTTPS does not | The Fiddler CA is not trusted or HTTPS decryption is off | Install and trust the CA from Settings > HTTPS, then reload the request. |
| HTTPS certificate warning | The client does not trust the Fiddler CA, or certificate pinning rejects it | Install the CA in the correct user/device store. If pinning is enforced, use the application’s supported debug configuration. |
| Expected request is missing from the grid | A Fiddler filter hides it | Clear filters and search again. |
| Remote device cannot connect | Wrong host address, blocked port or network isolation | Use a reachable host IP, confirm the port, and allow device-to-host traffic through the firewall and network. |
| Traffic stops after debugging | System Proxy remains enabled | Turn System Proxy off, or restore the previous proxy settings. |
9. Performance, reliability and privacy
- Performance: capture adds a local proxy hop and, for HTTPS, decryption and re-encryption work. Capture only the hosts or processes needed, and disable it during unrelated performance measurements.
- Reliability: a missing session is usually a routing, certificate, filter or network configuration issue. Verify each layer independently: mode, proxy route, CA trust, filters and connectivity.
- HTTP/2 and streaming: HTTP/2 is enabled by default in the documented connection settings. WebSocket, SSE and gRPC support still depends on the client using a route Fiddler can observe.
- Secrets: sessions can contain passwords, cookies, authorization headers, tokens and personal data. Restrict access, redact exports and reset credentials if a secret is accidentally shared.
- Cost: Fiddler Everywhere is desktop software; the capture workflow itself is local. Check the current Telerik licensing and plan terms before using it in a team or production environment.
10. Or skip the browser setup
If your goal is a clean image of a website rather than inspecting every network exchange, ScreenshotNeo provides a single website-screenshot API request. It accepts a URL and returns PNG, JPEG, WebP or PDF. Cookie and consent banners, newsletter popups and chat widgets are removed before capture. Bot checks, blank pages, failed loads, timeouts and cache hits are not billed, and response headers identify the page verdict and billing result.
ScreenshotNeo also offers an MCP server with take_screenshot, get_page_info and capture_pdf for Claude, Cursor and other MCP clients. Every feature is available on every plan; 1,000 screenshots per month are free with no card, and paid plans start at $5 for 3,000 screenshots.
See the ScreenshotNeo API documentation for all options.
cURL
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Python
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
Node.js
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
Create a free ScreenshotNeo account to use 1,000 screenshots a month with no card.
11. FAQ
Does Fiddler capture traffic from every application?
No. The application must use the operating-system proxy or another supported Fiddler mode. Apps that bypass proxies or enforce certificate pinning may not be capturable.
Why is HTTPS empty after installation?
HTTPS decryption is not enabled by default. Install and trust the Fiddler CA through Settings > HTTPS, then repeat the request.
What port does Fiddler use?
The documented default listening port is 8866, and it can be changed under Settings > Connections.
Should I leave System Proxy enabled?
Only while you need system-level capture. Disable it afterward so supported applications return to their normal proxy behavior.
Can Fiddler capture a phone?
Yes, Fiddler Everywhere documents iOS and Android capture. The device must reach the host proxy, and HTTPS inspection requires trusting the Fiddler CA on the device.


