Import, replay, sweep.

A focused HTTP request bench for iPhone. Inspect, replay, and parameter-sweep requests — built for developers and authorized security testers, and private by design.

Download on the App Store

What it does

Repeater

Compose and edit a request — method, URL, headers, body — send it, and read the response as Pretty, Raw, or Headers.

Sweep

Mark insertion points, load a wordlist, and run Single, Shared, Paired, or Combination sweeps with live grep matching.

Import

Bring in requests from Charles Proxy session exports (.chlsj) via Files or the share sheet.

Export

Export saved requests as HAR, export sweep results as CSV, or copy raw request/response to the clipboard.

Filter & review

Filter sweep results by status class or grep hits; keep a searchable history of requests and responses.

Light & dark

Native, fast, offline — with Light, Dark, or System appearance.

Private by design. HTTP Workbench has no accounts, no analytics, and no tracking. Everything stays on your device; requests go only to the endpoints you choose.

Use HTTP Workbench only against systems you own or are explicitly authorized to test.