HTTP, HTTP2, HTTPS, Websocket debugging proxy

English | 简体中文

whistle logo

We recommend updating whistle and Node to ensure that you receive important features, bugfixes and performance improvements. Some versions of Node have bugs that may cause whistle to not work properly, for detail see the issue: #231


whistle is a cross-platform web debugging tool based on Node.js.

It features the following:

  1. offer HTTP proxying
  2. capture, replay or compose requests of HTTP, HTTPS, WebSocket and TCP.
  3. manipulate http request and response by configing hosts, or patterns like domain, path, regular expression, wildcard characters, wildcard path, etc.
  4. offer build-in mobile debugging mode

If the aboves can't satisfy your requirements, you can also use plugins to extend its capabilities.

The specific functions are as follows:

specific functions

Manipulations to http request and response in whistle can be achieved as a Rule looks like:

pattern operatorURI


  1. pattern is an expression to match the target request url. You can write patterns in different forms including domain, path, regular expression, wildcard, and so on.

     # matching domain
     # domain with port
     # domain with protocol, supporting http, https, ws, wss, tunnel
     # matching path, supporting protocol, port
     # matching regular expression
     /^https?://www\.example\.com\/test/(.*)/ referer://$1
     # matching wildcard
     ^*** referer://$1

    For more details, please visit Pattern Matching

  2. operatorURI is the corresponding operation, made up of opProtocol and opValue:
    opProtocol represents the kind of operation, e.g.

     # host:setting requested server IP
     pattern host://opValue
     # file:using the local file to replace
     pattern file://opValue

    opValue represents the parameters of the specific operation, e.g.

     # host:setting requested server IP
     pattern host:// # or pattern	
     # file:using the local file to replace
     pattern file:///User/test/dirOrFile # or pattern /User/test/dirOrFile
     pattern file://E:\test\dirOrFile # or pattern E:\test\dirOrFile

    For more details, please visit operation value

  3. The position of pattern and operatorURI can be swapped in most situations while the combination mode is also supported. For more details, please visit configuration mode

Install & Setup

install Node

The latest LTS version of Node.js is recommended.

If none or low version of Node.js is installed, you need install the latest version of Node.js according to the following instructions:

  1. For Windows: please visit to download the latest LTS version of Node.js and then, install it using the default options.

  2. For Mac: the same as Windows.

  3. For Linux: using source code to install is recommended, because in this way, you don't need to configure the path.  If you fail to install with source code, you can also use the binary version of Node.js directly.

    • with source package: visit Official website of Node to download the latest version of Source Code*(or using wget in shell), unzip(tar -xzvf node-xxx.tar.gz), switch to the root directory(cd node-xxx), execute ./configure, ./make and ./make install in order。
    • using binary version:visit Official website of Node to download the latest Linux Binaries(or using command wget to download), unzip(tar -xzvf node-xxx.tar.gz), add the absolute path of bin directory to system PATH after extracting。

You can execute node -v in shell to check if the expected version of Node.js is installed successfully:

$ node -v

install whistle

After the Node.js is installed successfully, you can execute the following npm command to install whistle(In Mac or Linux, prefix sudo is needed if you are not root user, i.e. sudo npm install -g whistle

npm install -g whistle

In China, you can install whistle using npm mirror of taobao to speed up installing progress and avoid failure:

npm install cnpm -g --registry=
cnpm install -g whistle

or specify mirror install directly:
npm install whistle -g --registry=

After installation, execute whistle help or w2 help to view help information:

$ w2 help
Usage: whistle <command> [options]


	run       Start a front service
	start     Start a background service
	stop      Stop current background service
	restart   Restart current background service
	help      Display help information


	-h, --help                                      output usage information
	-D, --baseDir [baseDir]                         the base dir of config data
	-z, --certDir [directory]                       custom certificate path
	-l, --localUIHost [hostname]                    local ui host ( by default)
	-n, --username [username]                       the username of whistle
	-w, --password [password]                       the password of whistle
	-N, --guestName [username]                      the guest name
	-W, --guestPassword [password]                  the guest password
	-s, --sockets [number]                          max sockets (60 by default)
	-S, --storage [newStorageDir]                   the new local storage directory
	-C, --copy [storageDir]                         copy storageDir to newStorageDir
	-c, --dnsCache [time]                           the cache time of DNS (30000ms by default)
	-H, --host [host]                               whistle listening host(:: or by default)
	-p, --port [port]                               whistle listening port (8899 by default)
	-P, --uiport [uiport]                           whistle ui port (8900 by default)
	-m, --middlewares [script path or module name]  express middlewares path (as: xx,yy/zz.js)
	-M, --mode [mode]                               the whistle mode (as: pureProxy|debug|multiEnv)
	-t, --timeout [ms]                              request timeout (66000 ms by default)
	-e, --extra [extraData]                         extra data for plugin
	-f, --secureFilter [secureFilter]               the script path of secure filter
	-R, --reqCacheSize [reqCacheSize]               the cache size of request data (512 by default)
	-F, --frameCacheSize [frameCacheSize]           the cache size of socket frames (512 by default)
	-V, --version                                   output the version number

Setup whistle


w2 start

Note: If you don't want others to visit the configuration page of whistle, just add username and password when start, i.e. -n yourusername -w yourpassword


w2 restart


w2 stop

Debugging mode:

w2 run

For more details, please visit install and start

Proxing Settings

configuring server & port
  1. proxying server: whistle is deployed in remote server or virtual machine, change this address to corresponding IP address)
  2. default port:8899(if port 8899 is used already, you can specify new port using -p when start. More details can be visited by executing whistle help or w2 help (only supported in v0.7.0 and higher version)

Make sure using the same proxying server for all protocol in system proxying setting is checked.

Browser & System configuration
  1. proxy setting in OS: 
  1. proxy setting in browser(recommended)

    • for Chrome:intall chrome plugin whistle-for-chrome or Proxy SwitchySharp

    • for Firefox: Open Options page in Firefox, then switch to General -> Network Proxy, then set Manual proxy configuration to whistle.

  2. in mobiles, configure the proxy of current Wi-Fi in Setting

PS: The mobile may failed to use network after configuration because the fireworks of the PC has forbidden remote visit to the whistle's port. you can try to close the fireworks or configure white list :

For more details, please vsit install and start

Visit whistle's operation page

After the above steps are completed, open the whistle page in browser

whistle webui

There are five main tabs in the navigation bar:

  1. Network
  • check and compose the http request
  • show the console print and javascript errors thrown in pages
  1. Rules:configure rules for manipulating
  2. Plugins
  • show the list of installed plugins
  • enable or disable installed plugins
  1. Weinre:configure Weinre list
  2. HTTPS:
    • configure whether or not to intercept the HTTPS and download the root certificate for whistle

Certificate Installment

Please install root certificate and enable HTTPS interception before using whislte.

For more details, please vsit Certificate Installment

Quick start

Open Rules tab in whistle, and create a group named test by context menu or Create button in menu bar. Then follow the next steps to write rules and save.

  1. cofigure hosts

    Specify the ip of
     # or

    Specify the ip and port of to forward http request to local port 8080. In this way, we can visit the local website just as online when the developing port is not 80:

     # or

    We can also replace the real IP (or domain) and port with any domain without port: host://
     # or

    For more details, please visit Pattern Matching

  2. local files replacing

Replace the response with content in local file system, which is frequently used during web developing.

# Mac or Linux file:///User/username/test
# or file:///User/username/test/index.html
# Both '\' and '/' can be used as path separator for Widows file://E:\xx\test
# or file://E:\xx\test\index.html will try to load /User/username/test first. If the former dosen't exist, the file /User/username/test/index.html will be loaded. For neither exists, it returns 404.

To replace jsonp request, you can refer to tpl

For more details, please vsit Pattern Matching

  1. Request Forward

    To forward all the requests from domain to domain

    For more details, Pattern Matching

  2. Inject html、js、css

    whistle will decide whether injecting corresponding text and how to inject, like whether wrapping the text with HTML label, automatically according to response type.

     # Mac、Linux html:///User/xxx/test/test.html js:///User/xxx/test/test.js css:///User/xxx/test/test.css
     # Both '\' and '/' can be used as path separator for Widows html://E:\xx\test\test.html js://E:\xx\test\test.js css://E:\xx\test\test.css

    For all the requests for domain, whistle will inject the processed text to response body according to response type. If the type is HTML, the js content will be wrapped within script, and the css content be wrapped within style to be injected to response body。

    For more details, Pattern Matching

  3. Debug for remote page

    With the protocol weinre and protocol log provided by whistle, you can modify the DOM structure, capture the javascript errors and view the console print easily. Moreover, you can inject specified script to debug the remote page.

    Before using whistle to debug remote page, you need to set the proxy for OS or browser to whistle. Please refers Install and start to know how to set the proxy.

    For weinre: weinre://test

    Add the following rule in group named test and save, open the with a new tab in browser. Then you can see a list when you hover over the button weinre, click the item test to open a weinre debug page. For example, you can see the DOM structure when swich to Elements tab after selected a target.

    For log: log://{test.js}

    Add the following rule in group named test and save. Then you can see a list when you hover over the button Values, whistle will create a group named test.js in Values when you click it. Input the text console.log(1, 2, 3, {a: 123}) in the group editor, open the Network -> Log -> Console, open the, you can see the output '1, 2, 3, {a: 123}' in Console panel.

    For more details, Pattern Matching and Rules


  1. Install and start
  2. CLI operation
  3. How to update
  4. Quickly start
  5. Configuration mode
  6. Pattern Matching
  7. Operation value
  8. Frequent functions
  9. How to develop plugins
  10. Attentions
  11. Common questions
  12. Web UI
  13. Rules
  14. Feedback



  • 安卓12根证书设置后还是提示证书有问题,httpcanary的根证书就没有问题



    通过以下命令生成.0结尾的根证书,并使用adb推送到了安卓设备上,httpcanary的根证书就可以正常抓包,但是whistle转换的就不行 `$ openssl x509 -inform PEM -subject_hash_old -in rootCA.crt | head -1

    $ cat rootCA.crt > 77e83b46.0

    $ openssl x509 -inform PEM -text -in rootCA.crt -out /dev/null >> 77e83b46.0`

  • 当安卓客户端 以protocol 协议为 http时,向后端 发起 websocket 请求,出现问题

    当安卓客户端 以protocol 协议为 http时,向后端 发起 websocket 请求,出现问题

    例如: 请求连接为 请求头为

    GET /index.html HTTP/1.1
    Connection: upgrade
    Upgrade: example/1, foo/2

    向后端发起websocket请求 用 whistle 抓包 protocol 显示为 http 后端服务 显示 此次连接 连接成功后马上断开

    但是同样的 请求 以fiddler 抓包 是能够正常连接后端的websocket服务 不断开的


  • 支持 https 降级代理

    支持 https 降级代理

    平时我配置代理都是 ip domain 形式滴


    如果访问 这个很正常,可以正确得到需要的东西,因为访问了 端口

    但是如果访问 就不正常了,这个时候 whistle 自动去访问了 端口,但是因为内网机器上是不会部署证书滴,而且也只开放 80 端口

    所以我加了一个全局的 rule

    /^https:\/\/(.*)/i http://$1

    这样就可以 hack 把 443 端口强制改成访问 80 端口了

    但是问题来了,如果我想设置其他 rule 就不行了

    因为 rule 只能存在一个,所以就很麻烦

    如果你要让 https 降级 rule,就没办法自定义其他 rule 了

    如果要自定义 rule 就必须带上 https 转换,https -> http

    所以看一下这边有没有办法弄一个方法可以既满足 https 转 http,并且也支持自定义 rule

  • 像下面nginx这样转发怎么配置?


        location  ~.*\.(gif|jpg|jpeg|png|bmp|swf|ico|js|css|html)$
            root   html;
        location / {
            root   html;
  • 使用中遇到了手机 qq 中截图的消息加载很慢问题

    使用中遇到了手机 qq 中截图的消息加载很慢问题



    MacOS 12.2.1 whistle 2.9.13 Android vivo S7 QQ v8.8.88.7830



    电脑中启动 whistle,并在防火墙允许了监听的端口输入请求

    android 系统设置中 wifi 的代理配置http代理指向同局域网电脑的 whistle。

    android 中登录QQ。


    从电脑中任意截图一个区域,将截图发给android的QQ。大小无所谓。一两百一两百的就够。我这边测试是 191104 的尺寸



  • whistle不生效



    1. 按照流程安装、启动;
    2. 启动成功;
    3. 打开默认页面无法访问;
    4. 本地ip+端口可以访问--http://本地IP:8899/#rules;
    5. network页面空白;
    6. 安装demo注入test.js,无效;
    7. 代理转发,无效;


    yunan.chen@DESKTOP-Q8CBUH8 MINGW64 /f/work/Jupiter-BSD (BSD_from_bugfix/20211217_UR)
    $ w2 proxy
    Setting global proxy ( successful.
    yunan.chen@DESKTOP-Q8CBUH8 MINGW64 /f/work/Jupiter-BSD (BSD_from_bugfix/20211217_UR)
    $ w2 start
    [!] [email protected] is running
    [i] 1. use your device to visit the following URL list, gets the IP of the URL you can access:
           Note: If all the above URLs are unable to access, check the firewall settings
                 For help see
    [i] 2. set the HTTP proxy on your device with the above IP & PORT(8899)
    [i] 3. use Chrome to visit to get started
    无法访问此网站 拒绝了我们的连接请求。
  • [feature]能否支持一键开启全局代理配置



    目前使用 whistle 需要配合浏览器的代理插件使用,只能抓包浏览器请求,但如果想抓包其他软件,只能手动配置系统的网络代理


    希望 localhost:8899 whistle 管理平台支持一键开启/关闭系统代理功能


    目前了解到 win 下有个小工具可以通过指令开启/关闭代理,可以参考下[小工具链接] 手头没 mac,需要平台调研下了

  • 想开发一个以请求头中信息作为pattern的proxy插件


    现在whistle的代理设置是这种形式 pattern proxy://ip:port 我想要开发一个插件,能够实现根据请求头中的某一个信息作为pattern使用代理 header_xxx my_proxy://ip:port 问题:

    1. 有没有相关的插件脚手架
    2. 如果我基于whistle源代码改造,能否麻烦大佬给予一些提示
  • weinre 是根据什么判断 html 的?

    weinre 是根据什么判断 html 的?

    系统是 mac,没开防火墙,使用weinre时,targets 是none,貌似要写手动写weinre的 js 才可以用,

    <script src="http://x.x.x.x:8901/target/target-script-min.js#anonymous"></script>
  • Debug 模式下启动出错

    Debug 模式下启动出错

    vscode 中,通过 「JavaScript Debug Terminal 」,执行启动命令,会在下面代码截图的分支中返回,导致启动无法正常完成。

    debug 代码发现,记录error 的文件中的内容为:Debugger attached. 看起来是把命令行中输出的这条debug信息也认为是错误信息了。


  • Error: Parse Error: Duplicate Content-Length

    Error: Parse Error: Duplicate Content-Length

    From: [email protected]
    Node: v16.1.0
    Date: 2021/6/7 下午12:05:30
    Error: Parse Error: Duplicate Content-Length
        at TLSSocket.socketOnData 
    - [ ] 
    - [ ] (node:_http_client:487:22)
        at TLSSocket.emit (node:events:365:28)
        at addChunk (node:internal/streams/readable:314:12)
        at readableAddChunk (node:internal/streams/readable:289:9)
        at TLSSocket.Readable.push (node:internal/streams/readable:228:10)
        at TLSWrap.onStreamRead (node:internal/stream_base_commons:190:23)







