edit anything
Method, path, headers, body — rewrite any part of the request and fire it.
Send it once. Change one field. Send it again. The careful, hand-driven probe — request and response side by side, over and over.
Method, path, headers, body — rewrite any part of the request and fire it.
Request and response in one pane, so the effect of each change is immediate.
Keep parallel probes in tabs; every send is in the history to diff or resend.
Send any flow from the proxy, scanner or intruder straight into Repeater.
The auth-bypass lab is a live Repeater: flip the login email to ' OR 1=1-- and watch a 401 turn into a 200 with an admin token — replayed from a real Juice Shop capture you can reproduce in five minutes.
Every request your browser makes, on your terms — pause it, rewrite it, release it. HTTP/1.1, HTTP/2, HTTP/3 and WebSocket, with on-the-fly TLS.
An active and passive scanner that ships free — OWASP and API Top 10, with blind out-of-band detection.
Automated payload attacks at full speed — four modes, 21 generators, 32 processors, and a Turbo mode with raw-TCP batching.
Set a budget, hit explore, and an autonomous agent drives every tool over 162 MCP tools — or wire Claude Code, Cursor or your own agent straight in.
Beat check-then-act windows the proxy can't reach — single-packet attacks, last-byte sync and barrier coordination.
Extend the scanner without trusting the code — community modules compiled to WebAssembly and run in a hard sandbox.