Your whole API workflow, in your pocket
Test REST, WebSocket, GraphQL, SSE, gRPC, Socket.IO and MQTT from your phone — ten auth types, no-code assertions plus a real JavaScript engine, collections versioned as project files, a local mock server and code generation for 27 targets.


Seven protocols, one client
Everything you call, from REST to gRPC.
- REST with 8 colour-coded methods, GraphQL with schema introspection
- WebSocket, Server-Sent Events, Socket.IO and MQTT
- gRPC by server reflection — no .proto file needed

Auth that means it
Eight types, including the hard ones.
- OAuth2 with four grant types, AWS SigV4 and Digest
- Bearer, Basic, API key and custom
- Pre-request scripts for computed tokens and signatures

Responses under X-ray
See where the milliseconds actually go.
- Timeline: DNS · TCP · TLS · TTFB · transfer
- Six tabs: body, headers, cookies, tests, timeline, console
- No-code assertions plus real JavaScript test scripts

A local mock server
Build the front end before the back end exists.
- Local HTTP server on port 8090
- Route patterns with priority matching
- Configurable status, headers and latency
// spec
The spec sheet
plan.free
- ·All protocols, auth, scripts and code-gen
- ·Import and export (5 in / 6 out)
- ·One collection and environment
plan.premium
- +Local mock server
- +Collection runner and load testing
- +Unlimited collections, environments, history
// works with
From the blog
// faq
Frequently asked questions
Can you test REST APIs from your phone?
Yes. The API tester sends REST requests with all 8 HTTP methods, plus WebSocket, GraphQL, Server-Sent Events, gRPC, Socket.IO and MQTT, and shows status, headers, timing, and body — a full API client running on Android.
Does it support GraphQL and WebSocket?
Yes. Alongside REST it handles GraphQL queries, live WebSocket connections, and SSE streams, so you can test real-time and query-based APIs — not just plain HTTP endpoints — from a single tool on your phone.
Can it test gRPC, Socket.IO or MQTT?
Yes. gRPC calls work through server reflection — no .proto file to import, just point it at host:port and it discovers the services. Socket.IO connects to a namespace to listen for and emit events, and MQTT connects with or without TLS to subscribe and publish by topic with QoS 0/1/2.
Can I write real test scripts, not just check a status code?
Yes, two ways. A no-code assertion builder checks status code, response time, headers, JSONPath or body size against a value with no scripting. For anything more, real JavaScript test scripts run in an isolated sandboxed process — a broken script can't crash the app, and it falls back to a plain console warning on older devices instead of pretending to pass.
Are my API collections stored in the cloud?
No — everything lives on the device. And you can go further: "Save to project" mirrors a collection as one readable JSON file per request inside the same project the code editor has open, so you review and version your API collection with the app's own Git manager, exactly like any other file in the repo.
What authentication methods are supported?
Ten auth types are built in, including Bearer tokens, Basic auth, API keys, and OAuth, so you can call protected endpoints without hand-crafting headers. Variables work across 4 scopes to keep secrets out of each request.
Can it generate client code from a request?
Yes. It exports ready-to-use code for 27 targets, and imports/exports collections (6 import, 6 export formats), so a request you tested on your phone drops straight into your codebase or moves between tools.
Is there a built-in mock server?
Yes. A local mock server runs on port 8090, so you can define routes and responses and develop against a fake API before the real backend exists — useful for building the frontend and the API in parallel.