Security and data handling

Captured request data

New captures preserve raw body bytes with a SHA-256 fingerprint. Pretty views and header masking do not change stored evidence. Bodies are limited to 128 KiB. Captured HTML is displayed as code.

Payloads are stored in Cloudflare R2; metadata is stored in PostgreSQL. Treat webhook URLs and payload links as sensitive. Existing payload links are bearer-accessible; the service does not currently promise private encrypted payload storage.

Secrets and account security

The inspector masks common credential headers by default and allows temporary reveal. Masking is not storage redaction. Avoid sending production credentials or personal data in test payloads. Accounts support authenticator-app MFA and password reset. Application-level encryption of all stored secrets is not currently implemented. Provider signing secrets for Stripe/GitHub verification are separately encrypted with AES-GCM and are never returned after saving.

Replay and forwarding

Replay requires a signed-in endpoint owner or manager. Its server-side sender restricts destinations to public HTTP(S) addresses, checks DNS, pins the connection address, and limits time, concurrency and response size. Replay, edited replay, forwarding, destination tests and retries share this policy. Redirects are not followed.

Retention and deletion

Plan limits determine configurable retention. Scheduled cleanup removes expired payload objects and history; deleting history also removes associated replay and forwarding attempts. Queue copies and infrastructure backups have separate lifecycles. Immediate erasure from backups is not guaranteed.

Review retention limits

Transport and reporting

Use HTTPS for public traffic. TLS termination and infrastructure access controls depend on deployment configuration. No SOC 2, ISO 27001 or HIPAA certification is claimed here.

Report a suspected vulnerability through the contact information on the About page. Do not include captured secrets in a public report.