Security model

Captured traffic stays on your Mac.
Lens proxy settings shut off automatically.

Lens 1.0.1 does not upload requests, responses, WebSocket payloads, or saved Sessions.

Data boundary

Your debugging data stays local.

Captured payloads and workspace configuration remain on this Mac.

Stored locally

What stays on this Mac

  • Saved Sessions and transactions
  • Request and response bodies
  • WebSocket messages and payloads
  • Spaces, Breakpoints, Map Local, Rewrite Rules, themes, and Muted Hosts
  • Map Local file paths

Lens 1.0.1 does not sync these items to Lens servers.

System safety

If Lens stops, its proxy settings switch off.

Lens Helper watches the app and disables the HTTP and HTTPS proxy settings created by Lens after a crash or force quit. Lens checks for leftovers on the next launch.

HTTPS inspection

How Lens inspects encrypted traffic.

Lens creates a local certificate authority for development traffic and generates host certificates only when needed. Certificate-pinned apps may require a debug build or pinning override.

App or devicedevelopment traffic
Lenslocal inspection
API serverupstream TLS
HTTPS inspection flow from development target through Lens to the API server
Responsible disclosure

Found a security issue?

Please send a concise reproduction and impact assessment. Avoid including live customer traffic or credentials.

Report privately

Inspect traffic without uploading the capture.

Download Lens for local-first HTTP/S debugging on macOS.