CanaryX — API & Traffic Capture
A powerful on-device network debugging tool for developers, security researchers, and power users. Capture, inspect, and modify HTTP, HTTPS, TCP, and UDP traffic from any app on your device — no root required.
CanaryX works by creating a local VPN that routes network traffic through an on-device MITM proxy, similar to Charles Proxy, Proxyman, or Burp Suite. All traffic stays on your device — nothing is uploaded to any server.
► KEY FEATURES
• Network Capture — Intercept and inspect HTTP/HTTPS requests, responses, headers, bodies, and TCP/UDP packet metadata in real time.
• Per-App Filtering — Select specific apps whose traffic you want to capture. Focus only on what matters.
• HTTPS Decryption — Generate a local CA certificate to decrypt HTTPS traffic. Install as user CA (no root) or system CA (root required).
• Request Replay & Compose — Capture any HTTP request, modify it, and re-send it. Perfect for API testing and debugging.
• Rewrite Rules — Define rules to automatically modify request and response headers, bodies, and status codes on the fly. Test different scenarios without changing your app's code.
• Breakpoints — Pause requests in real time before they reach the server. Inspect, modify, or drop them manually.
• Capture Overlay — A floating indicator shows when capture is active, so you always know the VPN tunnel is running.
• CA Certificate Manager — Generate, install (user or system), export, and uninstall your local CA. Full lifecycle management.
► USE CASES
• API Debugging — Inspect REST API calls, check request/response payloads, verify headers and status codes.
• Security Research — Analyze app network behavior, find tracking endpoints, examine certificate pinning.
• QA Testing — Replay and modify requests to test edge cases without touching the app's source code.
• Protocol Analysis — View raw TCP/UDP packet metadata to understand network protocols.
• Development — Debug your own apps' network traffic during development without external proxies or cables.
► PRIVACY & SECURITY
• All data stays on your device — captured traffic is stored in RAM only, never written to disk or sent to any server.
• No ads, no analytics, no crash reporting, no backend servers, no third-party SDKs that collect data.
• ADB backup and cloud backup are fully disabled to prevent data extraction.
• A first-launch privacy consent screen explains what the app does before any capture starts.
• The app does not collect, transmit, or share any personal information, device identifiers, location data, or usage statistics.
► SYSTEM REQUIREMENTS
• Android 7.0 (API 24) or higher.
• No root required for HTTP capture and user CA HTTPS decryption.
• Root required only for system CA installation (makes all apps trust the CA).
► DISCLAIMER
CanaryX is a developer tool for debugging network traffic on devices you own or have explicit permission to test. Do not use it to intercept traffic without consent. Misuse may violate wiretapping and privacy laws in your jurisdiction.
Contact: dev.robinop@gmail.com
Capture, inspect & debug HTTP/HTTPS/TCP/UDP traffic with a local VPN proxy.