Frequently asked questions
Practical answers about capturing real traffic, testing authenticated requests, automating checks, and keeping assessment evidence.
Before your first assessment
Is Ogma free, and do I need an account to test?
The desktop toolkit is currently free to use, with no Ogma account required. You can capture traffic, edit and replay requests, run workflows, and investigate findings without connecting an AI provider. Ogma is proprietary software; optional AI provider usage costs are separate.
Download OgmaCan I use my own browser, or do I need to configure one?
Use the built-in browser to start capturing without configuring an external proxy or importing a CA into another browser. You can also use your own browser: set its proxy to Ogma's listener and trust the Ogma CA in a dedicated testing profile. Desktop builds are available for Windows, macOS, and Linux on x64 and ARM64.
Browser setupHow does Ogma keep large captures manageable?
The Rust proxy uses asynchronous I/O. The Vue interface loads history in pages, renders only the table rows near the viewport, and fetches bodies when you inspect them. Resource use still depends on payload sizes, concurrent tests, and open browser tabs; lightweight design is not a promise of unlimited captures or a fixed memory footprint.
Explore HTTP HistoryCapture and Replay
Can I inspect HTTPS, HTTP/2, and WebSocket traffic?
Yes. Ogma supports HTTP/1.x and HTTP/2 interception, HTTPS inspection through its local CA, and WebSocket capture, interception, and replay. HTTPS inspection requires the client to trust the CA. Certificate-pinned clients may reject interception; TLS passthrough can preserve the connection, but does not expose decrypted content.
Proxy and TLS settingsCan I replay authenticated requests and compare test accounts?
Replay lets you edit authorization headers and cookies, use environment variables for tokens and account IDs, and choose cookies from the request, cookie jar, or Ogma Browser. Keep separate sessions or collections for each identity and compare attempts when testing access control. Captured tokens can expire; verify the current identity rather than assuming a replay remains authenticated.
Replay and environment variablesWill Replay repair a malformed request before sending it?
Use Raw or Hex sending when exact HTTP/1.x bytes matter, including edited CR/LF, duplicate headers, or deliberate framing errors. Structured sending has different behavior, including optional Content-Length calculation. Raw sending uses HTTP/1.1: malformed HTTP/1.x framing cannot be represented as an HTTP/2 request.
Replay guideDoes WebSocket Replay reproduce the whole logged-in conversation?
It gives you a new connection where you can send messages and inspect replies. Some applications require fresh handshake credentials, an authentication message, or a subscription sequence before accepting the message you want to test. Replay those prerequisites first; an old captured message alone may not recreate the server-side session.
WebSocket ReplayAutomation and evidence
Can I automate a test without building a plugin?
Yes. Use Automate for payload variations, Convert workflows for transformations such as beautifying a response, Active workflows for selected history entries, and Passive workflows for processing captured traffic. HTTPQL filters help target the requests you actually want. Workflows include request/response test fixtures and optional run logging.
Workflows and testingCan I start testing from an API definition?
Replay imports self-contained OpenAPI 3.x definitions, Postman v2.1 collections, GraphQL introspection results, and WSDL documents into editable requests. Review generated values, credentials, and target URLs before sending. External schema references are not fetched during import; bundle them into the definition. GraphQL introspection data also needs its target endpoint.
Explore API testing in ReplayWhat should I expect from the scanners?
Passive analysis checks captured traffic without sending additional requests. Active checks send test payloads and assess the responses. Use scope and selected-request testing to control where you test, and validate the linked evidence before reporting a finding. Scanning supports your investigation; it does not establish complete coverage or replace business-logic and authorization testing.
Scanning and evidenceProjects and extensions
Where does client traffic go, and can I work without AI?
Desktop project data is stored locally. Core capture, Replay, workflows, and analysis do not require an AI service. If you enable the assistant or connect an external MCP client, the context used for those interactions may be processed by your chosen model provider. Review what you share, and treat captures, tokens, and exports as sensitive engagement data.
AI context and configurationCan I bring existing captures into Ogma and share my results?
Import HAR traffic or supported Burp XML exports to continue investigating existing captures. Export HTTP traffic as HAR, JSON, CSV, or raw HTTP, and findings as reports with reproduction steps and evidence. Use a project backup when you need to restore Ogma state, not just share traffic. Review exports for credentials and client data before sending them to someone else.
Imports, exports, and backupsCan I extend Ogma or connect my existing AI tools?
Build JavaScript plugins with the SDK and install them from a folder or ZIP package. Use the integrated MCP server to let a compatible external AI client inspect traffic, operate Replay, and interact with Ogma's browser. Plugins and MCP are optional ways to extend your workflow, not requirements for manual testing.
Plugin SDK quickstartStill have a question?
Find a setup guide or talk to the community.