Home/Docs/Features/TLS Pass-Through
Features

TLS Pass-Through

Relay selected targets without decrypting them, for applications that pin certificates.

TLS Pass-Through

Some applications pin their server certificate and refuse the InterceptSuite CA. TLS Pass-Through relays those connections untouched so the application keeps working while you intercept everything else.

Configure it in Proxy > Settings > TLS Pass-Through.

What happens

For a matching destination, InterceptSuite:

  • relays the connection without decrypting it,
  • does not record it in Proxy History,
  • cannot hold, edit or replay its contents (they stay encrypted).

Adding a rule

Click Add and fill in:

Field Examples
Host / IP range *.example.com, api.example.com, 10.0.0.0/8
Port 443, a list 443,8443, a range 8000-9000, or * for every port
Enabled Untick to switch the rule off

Use Edit and Remove to manage existing rules.

When to use it

  • A mobile or desktop app fails with a certificate error only when proxied.
  • You want a system's background traffic (updates, telemetry) to work normally while you test one application.
  • You do not need to read a particular connection and want to keep the history clean.

Rules are saved with your project.