Install WireLens for iPhone and iPad

Capture every app on your iPhone or iPad, on the device itself, through a local VPN that never leaves it.

iPhone and iPad

WireLens for iPhone and iPad captures on the device. There is no computer involved and no server of ours in the path: WireLens runs a local VPN on the phone, reads the traffic there, and connects to the real servers directly.

Requirements#

  • iOS or iPadOS 17 or later.
  • A few minutes for the one-time setup below.

Install#

Download WireLens from the App Store and open it. A short welcome explains what it does, then setup walks you through the two permissions it needs.

1. Allow the VPN configuration#

WireLens asks to add a VPN configuration. iOS shows its standard prompt, and you confirm with Face ID, Touch ID or your passcode.

This is how iOS lets an app see other apps' traffic. The VPN is local: traffic goes from your apps into WireLens on the phone and straight out to the servers they were talking to. The VPN badge in the status bar shows when capture is running.

2. Install and trust the certificate#

WireLens creates a root certificate on your phone. Install it and turn on full trust:

  1. Tap Install Certificate and tap Allow when iOS asks about a configuration profile.
  2. Open Settings, tap Profile Downloaded, then Install.
  3. Open Settings ▸ General ▸ About ▸ Certificate Trust Settings and switch on WireLens Root CA.
  4. Come back to WireLens. Setup detects the trust by itself and restarts capture so decryption starts.

The WireLens root certificate has more detail, including how to remove it.

3. Capture#

Start capture from the bar at the bottom of the Traffic tab and use the app you want to inspect. Requests appear as they happen.

  • Domains groups traffic by host; Requests is the flat list.
  • Long-press a host or a request and choose Enable SSL Proxying to decrypt that host. The next request to it is decrypted, with no restart.
  • Tap a request to open it: headers, bodies, JSON, images, WebSocket frames and timing.

The four tabs#

TabWhat is there
TrafficThe live capture, sessions and the capture bar
ToolsSSL Proxying, Breakpoints, Map Local, Map Remote, Rewrite, Scripting, DNS Spoof, Block List and Compose
RulesEvery rule across the tools, in one place
SettingsSetup health, the certificate, diagnostics and your plan

Send a capture to your Mac#

Export a capture as a .wirelens session package and share it with AirDrop or Files. WireLens for Mac opens it as its own session, with every header and body intact.

Things iOS decides#

  • Pinned apps refuse decryption and stop loading. Leave their hosts off the Include list and they keep working. See SSL Proxying.
  • HTTP/3 uses QUIC over UDP. With Block QUIC on, apps fall back to TCP, where WireLens can decrypt them.
  • Memory. iOS limits how much memory a network extension may use, so WireLens keeps very large bodies truncated and marks them that way.
  • Other VPNs. iOS runs one VPN at a time. Starting WireLens capture pauses another VPN, and the other way round.

Pro on iPhone and iPad#

Capture, inspection and sessions are free. Pro is an in-app purchase through the App Store, monthly, yearly or once, and removes the limits on every tool. To use it on another iPhone or iPad with the same Apple Account, choose Restore Purchases on the Pro screen. A Pro license for the Mac is sold separately at pay.wirelens.app; see Licenses, trial and activation.

Something here is unclear, or wrong for your setup? Contact support or write to support@wirelens.app.