← All documentation

Configure dependency capture and replay

Route your application's outbound HTTP and HTTPS requests through the local Mockingo proxy, then trust its development-only Capture CA so HTTPS dependencies can be inspected and replayed.

1

Start Mockingo

expose starts the public tunnel and dependency proxy together. The output includes the proxy address and Capture CA certificate path.

mockingo run --name my-api --http 8080
Dependency proxy started

Proxy          http://127.0.0.1:8899
CA certificate PATH_TO_MOCKINGO_CA/ca.crt

If you do not need an inbound public tunnel, run mockingo capture --name my-api instead. Both commands provide the same dependency proxy and replay behavior.

2

Configure the application proxy

Many HTTP clients read standard proxy environment variables. The HTTPS value still uses an http:// URL because the application reaches HTTPS destinations with the HTTP CONNECT method.

PowerShell

$env:HTTP_PROXY="http://127.0.0.1:8899"
$env:HTTPS_PROXY="http://127.0.0.1:8899"
$env:NO_PROXY="localhost,127.0.0.1,::1"

macOS or Linux shell

export HTTP_PROXY="http://127.0.0.1:8899"
export HTTPS_PROXY="http://127.0.0.1:8899"
export NO_PROXY="localhost,127.0.0.1,::1"

Java and JVM applications

java \
  -Dhttp.proxyHost=127.0.0.1 \
  -Dhttp.proxyPort=8899 \
  -Dhttps.proxyHost=127.0.0.1 \
  -Dhttps.proxyPort=8899 \
  -jar app.jar

Proxy environment variables are conventions, not guarantees. If no dependency traffic appears in Mockingo, check whether your application's HTTP library has its own proxy setting.

3

Trust the Capture CA for HTTPS

Use the exact ca.crt path printed by the Agent. Start the application after applying the trust setting.

Node.js

# PowerShell
$env:NODE_EXTRA_CA_CERTS="PATH_TO_MOCKINGO_CA/ca.crt"
node app.js

# macOS or Linux
NODE_EXTRA_CA_CERTS="PATH_TO_MOCKINGO_CA/ca.crt" node app.js

Java and JVM applications

Import the CA into a development trust store. Keep any other root certificates your application requires in the same store.

keytool -importcert \
  -alias mockingo-capture-ca \
  -file PATH_TO_MOCKINGO_CA/ca.crt \
  -keystore mockingo-dev-truststore.p12 \
  -storetype PKCS12

java \
  -Djavax.net.ssl.trustStore=mockingo-dev-truststore.p12 \
  -Djavax.net.ssl.trustStorePassword=YOUR_PASSWORD \
  -Dhttp.proxyHost=127.0.0.1 -Dhttp.proxyPort=8899 \
  -Dhttps.proxyHost=127.0.0.1 -Dhttps.proxyPort=8899 \
  -jar app.jar

curl

curl \
  --proxy http://127.0.0.1:8899 \
  --cacert PATH_TO_MOCKINGO_CA/ca.crt \
  https://example.com/
Operating-system trust stores

Use this only when the application relies on the operating system trust store. These commands change trust for your user or machine, so remove the Mockingo CA when development is finished.

Windows — current user

certutil -user -addstore Root "PATH_TO_MOCKINGO_CA/ca.crt"

macOS — login keychain

security add-trusted-cert \
  -r trustRoot \
  -k "$HOME/Library/Keychains/login.keychain-db" \
  PATH_TO_MOCKINGO_CA/ca.crt

Debian or Ubuntu

sudo install -m 0644 PATH_TO_MOCKINGO_CA/ca.crt \
  /usr/local/share/ca-certificates/mockingo-capture-ca.crt
sudo update-ca-certificates
4

Verify dependency traffic

Make an outbound request from the configured application. In the Mockingo Console, open the endpoint's Traffic view and select Dependencies. HTTP and trusted HTTPS calls should appear there.

Save a dependency interaction, choose Replay dependency, and repeat the same request. Enabled replays are returned locally before Mockingo attempts DNS, TCP, or TLS with the real dependency.

5

Troubleshooting

Certificate signed by unknown authority
The application runtime has not loaded the printed ca.crt, or it was started before the trust setting was applied.
No dependency traffic appears
Confirm the application's HTTP client honors the proxy setting. Requests covered by NO_PROXY intentionally bypass Mockingo.
Port 8899 is already in use
Stop an older mockingo capture process or start expose with --proxy-port 9000, then use that same port in the application.
Certificate pinning or mutual TLS
These hosts cannot be inspected. Preserve encrypted passthrough with --passthrough-host auth.company.com. Passthrough traffic cannot be captured or replayed.