Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

I built a free Burp/Caido alternative but, zero setup

API Testing

This is 1 of 224 launches in MCP tooling and agent infrastructure — see how it stacks up on momentum and crowding →

34 other launches read as similar to this one →

Details

External ID
49911931
Source
HN
Company
—
Product
I built a free Burp/Caido alternative but, zero setup
Website domain
apiaxess.dev
Launched
Sept. 30, 2026
Cohort
—
Upvotes
32
Upvotes percentile
0.8050847457627118
Tags
—
Fetched at
Oct. 2, 2026, 1:01 a.m.
Updated at
Oct. 2, 2026, 1:01 a.m.

Description

This is Katriel, the architect of the tool APIaxess.I have been API pentesting for a good time now, and starting with API pentesting was a bit of a rough patch. Specially the setting up and having to know the intricacies of proxies, networking and other stuff. Then once i got through it, the next rough patch was the apk pentesting, where getting the traffic of any apk was more of a task then the pentesting itself. So i started by writing scripts that automates the process and then made sure that any rooted adb just automatically started sending traffic to the burpsuite setup, and then that helped a lot. Then i just thought that this issue needs to be resolved in a more open manner, since its a very known pain point. So i built a GUI around it, made sure that it can handle everything that a normal api traffic tool can and then thought of releasing it, for people to test it out. Before the inital release, i have myself battle tested this tool, in multiple ways, while also sharing it with other professionals in my industry who constantly use Burp/Caido/HTTPToolkit or other similar tools. I know that the tool needs more features and more refinements, but thought of making it public so that i can get to know about the issues much sooner.Do check out the Github and leave a star if it helped you out, and do share it with your colleagues so that they could also waste less time setting it up and more time doing the work that they like. github.com/KatrielMoses/apiaxess

Enrichment

Theme
MCP tooling and agent infrastructure
Vertical
Security
Function
Dev tools
Audience
Developer
AI stance
Not AI
Project type
Hobby / open-source project
Normalized one-liner
zero-setup web proxy for api security testing
Manually corrected
False

Could you build this?

No Building a zero-setup interception proxy that spins up isolated Chromium profiles, manages Android emulators with injected root certificates, and bypasses TLS certificate pinning requires deep systems, networking, and security reverse-engineering expertise.

What it would actually take: Requires an interception engine (Go/Rust or C++) handling TLS MITM and dynamic cert generation, combined with custom Android emulator orchestration (AVD/QEMU, Frida/Xposed hooks to bypass SSL pinning in APKs) and a headless Chromium runtime with pre-configured proxy flags. Integrating live packet replay, fuzzing, and static APK decompiler pipelines (e.g., Jadx internals) demands specialized systems programming and offensive security engineering.

Discussion

5 comments analyzed.

Concerns raised: Requires rooted device

Competitors

Other products that read as similar to this one — 34 launches clear the similarity bar, closest 8 shown.

Attention rank: #7 of 35 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 323 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a dev tools tool for Sales yet.