Dev tools · alternatives · 2026

24 alternatives to Thor - HTTP Sniffer/Inspector for iOS
Professional HTTPS sniffing and analyzing tool
Below are 24 products that do a similar job, ranked by how close each is in meaning and then by launch-day votes. Thor - HTTP Sniffer/Inspector for iOS launched in 2017; newer entries below may have overtaken it.
- 1

- 2

Win clients faster than ever
2024 · sniff.so · its alternatives →
- 3

Discover, Scan, and Secure every API at scale
2025 · getastra.com · its alternatives →
- 4

- 5

- 6AS
Hiya HN! Just released Artillery Probe - a Swiss army knife for testing HTTP from the CLI. Think mini-curl with better UX for common use-cases, plus a couple of extra features. Would love for you to try it and give some feedback! https://www.artillery.io/blog/swiss-army-knife-for-http-testing and: npm install artillery@latest What does it do? - First of all, it's a HTTP client! It does all the usual stuff you'd expect from a HTTP client... HTTP methods, request bodies, custom headers, forms, Basic Auth etc. - Got some JSON or XML back? It'll pretty-print it, and syntax…
2022 · its alternatives →
- 7

- 8

- 9

- 10ID
2020 · inspect.dev · its alternatives →
- 11IW
Hi everyone, after months of hard-working, I'm glad to have something to show HN. It's an iOS app to help you directly capture and intercept HTTP/HTTPS Traffic from your iPhone/iPad with ease. It's suitable for any developers who would debug iOS without needing a computer. You can also share all traffic to Proxyman macOS via AirDrop for better previewing. - Please join a beta in TestFlight (iOS 14+): https://testflight.apple.com/join/nQ69eb35 - How it works if you don't have any devices: https://www.youtube.com/watch?v=UpzpoTN8efM&feature=youtu.be…
2021 · its alternatives →
- 12

- 13

- 14

- 15

- 16WT
2016 · android.fallible.co · its alternatives →
- 17

- 18

Capture, replay, and automate HTTP requests
Jun 2026 · chromewebstore.google.com · its alternatives →
- 19

This is an educational reference implementation showing how to build reasonably secure, standards-compliant authentication from first principles on Cloudflare Workers. Stack: Hono, Turso (libSQL), PBKDF2-SHA384 + normalization + common-password checks, JWT access + refresh tokens with revocation support, HTTP-only SameSite cookies, device tracking. It's deliberately minimal — no OAuth, no passkeys, no magic links, no rate limiting — because the goal is clarity and auditability. I wrote it mainly to deeply understand edge-runtime auth constraints and to have a clean Apache-2.0 example that…
Feb 2026 · github.com · its alternatives →
- 20KD
I built this after seeing multiple teams accidentally ship API keys in their frontend code. The problem: Modern web development moves fast. You're vibe-coding, shipping features, and suddenly your AWS keys are sitting in a tag visible to anyone who opens DevTools. I've personally witnessed this happen to at least 3-4 production apps in the past year alone. KeyLeak Detector runs through your site (headless browser + network interception) and checks for 50+ types of leaked secrets: AWS/Google keys, Stripe tokens, database connection strings, LLM API keys (OpenAI, Claude, etc.), JWT…
Nov 2025 · github.com · its alternatives →
- 21
TITAN Forensic AI Terminal: Real-time infrastructure audit.
Dec 2025 · digitalengineered.ai · its alternatives →
- 22IH
A simple Go-based HTTP proxy designed for detailed inspection of requests and responses. It logs traffic to the console with colorization, automatic decompression, and formatting for common content types, while remaining transparent to the client application. Ideal for debugging API interactions, understanding middleware behavior, or simply getting a clear view of HTTP traffic flow with jq-like pretty-printing & colorization of request/response. Automatically redacts parts of Authorization header to avoid token leakage.
2025 · github.com · its alternatives →
- 23JI
The team at Rownd is excited to announce https://jwt.is, an updated take on JSON Web Token debugging. Like most developers, we've used jwt.io for years, but it lacks a number of useful features that would make it even more convenient. We're building on the shoulders of those who've come before us. :-) In addition to the basic JWT decoding and signature verification, we've added things like: - Verification using JWK endpoints - Locally stored history of tokens and keys - Verification for EdDSA signatures - Detection of common token providers (e.g., Google, Apple, etc) - Dark mode!…
2023 · its alternatives →
- 24

Also compare
Ranked by how close each launch is in meaning, then by votes. Prices were read from each product’s own site when checked and can change. Refine with your own description →