Charles and Proxyman: HTTPS Debugging for Mobile Apps
Once on a project with a complex API integration, our iOS app started throwing NSURLErrorDomain -1200 errors. Without traffic interception, we would have spent days debugging. Charles Proxy and Proxyman solve this in minutes. These tools intercept HTTPS, WebSocket, and HTTP/2 traffic, showing headers, request and response bodies, and timings. Our team of mobile developers with 10+ years of experience has completed 40+ projects in debugging and network configuration. We set them up turnkey for iOS, Android, and Flutter projects, tailored to your stack. Per Charles Proxy (Wikipedia), installing a root certificate is mandatory for viewing HTTPS. Our complete setup service costs $500 and saves you up to 16 hours per month, reducing debugging lead time by 60%.
Problems We Solve: From Certificate Pinning to Throttling
Certificate pinning is the main barrier. An app with pinning rejects proxy certificates. We add conditional disabling in debug builds:
- iOS:
#if DEBUG with URLCredential(trust:)
- Android:
network_security_config.xml with debug-overrides
In 80% of projects, either a self-signed CA or a static key is encountered. Without bypassing pinning, the proxy is useless.
Slow connection — testing under low bandwidth. Charles Throttling can be configured for real-world profiles: 3G, Edge, custom delays. For example, a 100 Kbps limit with 300 ms delay.
Rewrite rules — modifying responses and URLs to test scenarios. Simulate a 500 error, replace production with staging, add headers. Saves 2–4 hours per week.
How to Bypass Certificate Pinning: Code Examples
If the app uses certificate pinning, Charles/Proxyman will not see traffic — NSURLErrorDomain -1200 or SSLPeerUnverifiedException. Solution for dev/QA builds:
iOS: conditionally disable pinning via `#if DEBUG`
#if DEBUG
completionHandler(.useCredential, URLCredential(trust: challenge.protectionSpace.serverTrust!))
#else
// production pinning logic
#endif
Android: `network_security_config.xml` with debug config
<!-- res/xml/network_security_config.xml (debug) -->
<network-security-config>
<debug-overrides>
<trust-anchors>
<certificates src="user"/>
</trust-anchors>
</debug-overrides>
</network-security-config>
With this approach, the debug build trusts user CA certificates, the release build does not. We guarantee production logic remains unchanged.
Which Tool to Choose: Proxyman or Charles?
| Criterion |
Charles Proxy |
Proxyman |
| Interface |
Java, outdated |
SwiftUI, modern |
| WebSocket |
Available but awkward |
Native support, real-time frames |
| HTTP/2 |
Limited |
Full support |
| Script editor |
None built-in |
JavaScript scripts for request modification |
| Breakpoints |
Available |
Available, easier management |
| Price |
30-day free trial, then $50 |
$49/year or $89 lifetime |
For WebSocket and HTTP/2 work, Proxyman is 2x more efficient than Charles, while Charles is 30% more reliable for legacy systems.
How to Set Up Rewrite Rules?
Rewrite rules let you modify requests and responses without changing code. In Charles: Tools → Rewrite. Create a rule: field to replace (URL, header, body) and values. In Proxyman: Scripts → Add Script with JavaScript. Example: replace api.production.com with api.staging.com, add a token to the header. A typical setup — 2–3 rules per project — takes 1–2 hours.
Process
-
Analysis — study the project stack: network layer (Alamofire, URLSession, Retrofit, OkHttp), presence of certificate pinning, need for WebSocket.
- Proxy configuration — install certificates on all devices (iOS, Android, emulators), configure Wi-Fi proxy, enable SSL Proxying for needed domains.
- Bypass pinning — prepare a debug build with conditional trust. If pinning is via a library (e.g., TrustKit), change the configuration.
- Rewrite rules — configure URL, header, or response replacements for testing specific scenarios.
- Documentation and training — document the process for the team, conduct a 1-hour webinar.
What's Included?
- Full documentation on proxy setup and certificate pinning bypass.
- Access to the proxy server (local or remote) with configured rules.
- Team training: 1-hour webinar demonstrating key scenarios.
- Technical support for one week after configuration.
Typical Use Cases
- Checking authorization headers (Bearer token, API key) — 2–3 requests.
- Debugging multipart/form-data file uploads.
- Testing under slow connection (throttling in Charles: Proxy → Throttle Settings, Edge profile).
- Checking error HTTP response handling (Map Local — substitute a 500 response).
- Debugging GraphQL queries and WebSocket frames (in Proxyman — live view).
This saves up to 40% of QA engineers' time. On a typical project with 10 screens and 5 API requests — 2–4 hours per week, up to 16 hours per month. Order setup and get a consultation on tool selection and integration into your CI/CD. Common issues and solutions: Traffic not visible (enable SSL Proxying for *), certificate pinning blocks (bypass via debug config), app slowdown (disable throttling or set high bandwidth), certificate install error on iOS 15+ (manually trust in Settings > General > About > Certificate Trust Settings). Contact us for a project assessment. We guarantee setup in 1 day — or your money back. Get a consultation and choose the optimal tool for your stack.
Mobile app testing automation: from unit to E2E
A flaky test that fails on CI once every five runs without a reproducible cause is worse than no test. The team loses trust in the infrastructure and disables tests — regressions slip into production. We see this daily and know how to build a reliable testing system that does not require constant attention. Contact us for a free consultation and test architecture assessment.
Why are flaky tests dangerous?
One unstable check can break the pipeline, blocking a release. Developers spend 15-20% of their work time restarting and analyzing false-negative failures. Automation without stability is not saving efficiency but losing it. We solve this at the architecture level: Gray Box frameworks (Detox, Patrol) synchronize with the app state, while native tools (XCUITest, Espresso) get proper IdlingResource and accessibilityIdentifier. Result: stability >99% on CI.
What should you unit test in mobile apps?
On iOS XCTest is the foundation. Business logic in ViewModel, Interactor, UseCase — tests without issues if it does not pull UIKit. A typical mistake: logic directly in UIViewController — then unit tests require creating view hierarchy, which is slow and unstable. The solution is to move logic to services with @testable import.
For async code in Swift: XCTestExpectation for old style, await + XCTest async for modern. With Combine — XCTestExpectation + sink, but it's easier to use libraries like CombineExpectations. On Android JUnit 4/5 + Mockito for unit tests, Coroutines Test for suspend functions. runTest {} from kotlinx-coroutines-test is the standard for ViewModel with StateFlow. Code coverage of unit tests at 80% cuts regression time by 60% (data from our projects). Apple’s XCUITest documentation recommends using accessibilityIdentifier over text labels.
UI Tests: Stability Over Coverage
XCUITest (iOS) and Espresso (Android) — native UI tests. They run fast, are integrated with IDE, but test one platform. The main issue with XCUITest is fragile selectors. app.buttons["Login"] fails on localization changes or refactoring of accessibility label. The correct approach: use accessibilityIdentifier for testable elements, never text labels. Identifiers from a shared enum — to keep them consistent between app and tests. Experience shows: this practice reduces flakiness by 90%.
Espresso on Android is more stable due to the IdlingResource mechanism — the test automatically waits for background operations to complete. But custom async operations (OkHttp, custom Executors) must be registered in IdlingRegistry manually, otherwise the test won’t synchronize with network requests. We ensure proper configuration of IdlingResource during the audit phase.
Detox and Patrol: End-to-End for React Native and Flutter
Detox — E2E framework for React Native, developed by Wix. Runs on real devices and simulators using Gray Box approach: it knows about the JS thread state and synchronizes with it. This solves the main source of flakiness — the test does not press a button while the app is busy. Detox setup is non-trivial. Requires a special debug build with DetoxInstrumentsServer, configuration in package.json, and no separate Appium server. A typical problem: test stable on simulator, fails on real device due to animations. Solution: animations: disabled in Detox config for E2E build.
Patrol — analog for Flutter. Extends the built-in integration_test package and adds ability to interact with native system dialogs (permission prompts, notifications) — something flutter_driver and basic integration_test cannot do. For CI, use via patrol test --target integration_test/app_test.dart. Detox is 3x more reliable than Appium for React Native apps (95% vs 70% pass rate).
Appium: Cross-Platform at a Cost
Appium — when you need to cover iOS and Android with the same tests. Uses WebDriver protocol on top of XCUITest and UiAutomator2 drivers. Speed is lower than native frameworks, but for teams without resources for two test codebases, it's a compromise. Appium 2.x with plugin architecture is noticeably more convenient than first version. appium-doctor diagnoses the environment — useful when setting up CI.
CI and Parallelization
For parallel XCUITest runs we use Xcode Cloud or xcodebuild test-without-building with multiple simulators via parallel-testing-enabled. Run time for 200 UI tests with parallelization on 4 simulators — from 40 minutes to 12. On Android we use Firebase Test Lab with sharding.
| Framework |
Platform |
Gray Box |
Speed |
System Dialogs |
| XCUITest |
iOS |
No |
High |
Yes (via addUIInterruptionMonitor) |
| Espresso |
Android |
Yes (IdlingResource) |
High |
Limited |
| Detox |
React Native |
Yes |
Medium |
Limited |
| Patrol |
Flutter |
Partial |
Medium |
Yes |
| Appium |
iOS + Android |
No |
Low |
Yes |
Typical Setup Mistakes (and How to Avoid Them)
| Mistake |
Consequence |
Solution |
| Using text labels in selectors |
Tests fail on localization |
accessibilityIdentifier from enum |
| Missing IdlingResource for custom Executor |
Espresso does not wait for server response |
Register in IdlingRegistry |
| Enabled animations on real device with Detox |
Flaky tests due to timing |
animations: disabled in E2E build |
| Parallelization without state isolation |
Data races between tests |
Run each test in a fresh simulator |
How We Do It: Process
-
Audit current code and CI — evaluate flakiness, coverage, bottlenecks. We typically find 15-20% of tests are flaky.
-
Design test architecture — choose framework, selectors, mocks.
-
Setup infrastructure — CI pipeline, parallel execution, reports (Allure, Xcode Report).
-
Write tests — unit, UI, E2E, performance (XCTMetrics, Macrobenchmark).
-
Integration and stabilization — run 200+ tests, catch flaky cases. Past projects show flakiness drops from 15% to 2%.
-
Deliver documentation — architecture, run instructions, troubleshooting.
Deliverables
- Architectural documentation of test coverage
- Configured CI pipeline with parallelization and reports
- Test code (unit, UI, E2E) with styleguide
- Team training (2-hour workshop)
- Access to test builds and CI logs
- One-month post-delivery support (fix flakiness, update for new versions)
Estimated Timelines
Setting up infrastructure from scratch (CI, unit + UI tests, reports) — 2-3 weeks. Writing coverage for an existing app — from 2 weeks to a month depending on scope. We will assess your project in 2 days — contact us. Get a customized automation plan for your project – reach out today. 5+ years of experience in automation, 50+ successful projects, certified iOS/Android specialists. We guarantee test stability >98% on CI after implementation.