Arcane Scout โ API Pentesting per mateocallec
A professional Chrome DevTools extension for API traffic inspection and web pentesting.
Metadatos del extension
Capturas de schermo
A proposito de iste extension
Arcane Scout is a Chrome and Firefox DevTools extension for API traffic inspection and web application security testing. Built for penetration testers, bug bounty hunters, and security-conscious developers who need more than the Network tab.
โโ API INSPECTOR โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Capture every XHR and Fetch request in real time as you browse. Each request is logged with its method, endpoint, status code, and timestamp. Click any row to open a full detail drawer with five tabs:
โข Overview โ URL, status, timing, and a one-click cURL export
โข Headers โ all request and response headers, neatly grouped
โข Payload โ request body with JSON pretty-printing and form data decoding
โข Response โ response body with an HTML preview (sandboxed iframe), inline image, video, and audio viewers
โข Replay โ edit and resend any captured request directly from the panel
Beyond the request table, three additional explorer views give you deeper insight:
โข Routes โ a collapsible tree of all captured path segments, filterable with a single click
โข Header Auditor โ flags missing or misconfigured security headers (CSP, HSTS, X-Frame-Options, and more) with severity ratings
โข Cookies โ lists every cookie on the current domain with enable/disable checkboxes; state persists across reloads but clears when the tab is closed
Export your full session as JSON or HAR for use in other tools.
โโ PENTEST TOOLS โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
A dedicated panel with nine built-in tools:
โข Encoder / Decoder โ encode and decode strings across Base64, URL, HTML, hex, and more
โข JWT โ inspect and decode JSON Web Tokens; view header, payload, and signature fields
โข Payload Generator โ generate fuzzing payloads for common injection categories (SQLi, XSS, path traversal, etc.)
โข Custom Request โ build and send arbitrary HTTP requests with full control over method, URL, headers, and body; responses render inline with the same media viewers
โข JSON Tools โ pretty-print, minify, and diff JSON payloads
โข XOR โ XOR two values with a configurable key; useful for analysing obfuscated data
โข HTTP Downgrade โ test whether a target enforces HTTPS or silently accepts plain HTTP connections
โข HTTP Inspector โ view raw response headers and body without any browser normalisation
โข Vulnerability Disclosure โ automatically fetches /.well-known/security.txt from the current domain (with fallback to www and the bare domain), parses all RFC 9116 fields, renders clickable contact and policy links, and shows an expiry validity badge
โโ PERMISSIONS โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Arcane Scout requests only the permissions it needs:
โข storage โ persists captured requests and cookie state across page reloads within the same session
โข cookies โ reads and toggles cookies for the inspected tab
โข contextMenus โ adds a right-click menu entry to open the Help & Documentation page
โข host_permissions (<all_urls>) โ required to capture network requests on any site you inspect and to fetch security.txt files cross-origin
No data ever leaves your browser. All processing happens locally.
โโ API INSPECTOR โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Capture every XHR and Fetch request in real time as you browse. Each request is logged with its method, endpoint, status code, and timestamp. Click any row to open a full detail drawer with five tabs:
โข Overview โ URL, status, timing, and a one-click cURL export
โข Headers โ all request and response headers, neatly grouped
โข Payload โ request body with JSON pretty-printing and form data decoding
โข Response โ response body with an HTML preview (sandboxed iframe), inline image, video, and audio viewers
โข Replay โ edit and resend any captured request directly from the panel
Beyond the request table, three additional explorer views give you deeper insight:
โข Routes โ a collapsible tree of all captured path segments, filterable with a single click
โข Header Auditor โ flags missing or misconfigured security headers (CSP, HSTS, X-Frame-Options, and more) with severity ratings
โข Cookies โ lists every cookie on the current domain with enable/disable checkboxes; state persists across reloads but clears when the tab is closed
Export your full session as JSON or HAR for use in other tools.
โโ PENTEST TOOLS โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
A dedicated panel with nine built-in tools:
โข Encoder / Decoder โ encode and decode strings across Base64, URL, HTML, hex, and more
โข JWT โ inspect and decode JSON Web Tokens; view header, payload, and signature fields
โข Payload Generator โ generate fuzzing payloads for common injection categories (SQLi, XSS, path traversal, etc.)
โข Custom Request โ build and send arbitrary HTTP requests with full control over method, URL, headers, and body; responses render inline with the same media viewers
โข JSON Tools โ pretty-print, minify, and diff JSON payloads
โข XOR โ XOR two values with a configurable key; useful for analysing obfuscated data
โข HTTP Downgrade โ test whether a target enforces HTTPS or silently accepts plain HTTP connections
โข HTTP Inspector โ view raw response headers and body without any browser normalisation
โข Vulnerability Disclosure โ automatically fetches /.well-known/security.txt from the current domain (with fallback to www and the bare domain), parses all RFC 9116 fields, renders clickable contact and policy links, and shows an expiry validity badge
โโ PERMISSIONS โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Arcane Scout requests only the permissions it needs:
โข storage โ persists captured requests and cookie state across page reloads within the same session
โข cookies โ reads and toggles cookies for the inspected tab
โข contextMenus โ adds a right-click menu entry to open the Help & Documentation page
โข host_permissions (<all_urls>) โ required to capture network requests on any site you inspect and to fetch security.txt files cross-origin
No data ever leaves your browser. All processing happens locally.
Evalutate 0 per 0 recensentes
Permissiones e datos
Permissiones necessari:
- Extende le instrumentos de disveloppamento pro acceder a tu datos in le schedas aperite
Permissiones optional:
- Acceder a tu datos pro tote le sitos web
Collection de datos:
- Le disveloppator dice que iste extension non require collection de datos.
Plus de informationes
- Ligamines del additivo
- Version
- 1.1.0
- Dimension
- 85,27 KB
- Ultime actualisation
- prije 4 dana (1. lip. 2026)
- Categorias associate
- Licentia
- Tote le derectos es reservate
- Historia de versiones
- Adder al collection