Recording with BlazeMeter + mitmproxy
This page is the dual recording workflow with mitmproxy in place of Fiddler Classic. It works on macOS and Windows. The only change is the evidence-capture tool. BlazeMeter stays exactly as it is in Section 4 - Recording.
When to Use This Page
- You are on macOS. Fiddler Classic does not run on Mac.
- You are on Windows but do not have access to Fiddler, or you cannot use Fiddler Classic for work under its current license. Since 3 August 2026, Progress limits Fiddler Classic to non-commercial use (see Progress's commercial use page).
- You want the same workflow as the Windows guide: BlazeMeter records the
.jmx, mitmproxy captures the evidence session (.flowinstead of.saz) for correlation.
mitmproxy is free, open source and cross-platform. It fills the Fiddler role one to one:
Most steps are the same on both systems. Where they differ, each step shows a macOS and a Windows choice.
| Role | Fiddler | mitmproxy |
|---|---|---|
Recording the .jmx | BlazeMeter extension | BlazeMeter extension (unchanged) |
| Evidence capture | Fiddler Classic | mitmweb (mitmproxy's web UI) |
| Saved session | .saz file | .flow file |
| Search for dynamic values | Ctrl+F highlight | Highlight filter box |
| Proxy port | 8888 | 8080 |
One-Time Setup
1. Install mitmproxy
macOS:
brew install mitmproxy
Windows: download the installer from https://mitmproxy.org, or run:
winget install mitmproxy.mitmproxy
Both add mitmproxy, mitmweb and mitmdump to your PATH. Open a new terminal after installing.
JMeter install stays as in Section 1 - Install Tools. On Mac you can also run brew install jmeter instead of downloading the zip.
Verify: mitmproxy --version prints the version (this guide was checked against 12.2.3).
2. Start the Proxy
mitmweb --listen-port 8080
The terminal must stay open while you record. mitmweb opens its web UI in your browser, usually at http://127.0.0.1:8081. This UI is where you will read the captured traffic, the same way you read the Fiddler session list.
3. Launch a Dedicated Proxied Chrome
This is the same idea as the chrome.exe --proxy-server step in the Fiddler guide, with two changes: port 8080 and a separate profile.
macOS:
open -na "Google Chrome" --args \
--proxy-server="127.0.0.1:8080" \
--user-data-dir="$HOME/chrome-mitm-profile"
Windows (Command Prompt or PowerShell):
"C:\Program Files\Google\Chrome\Application\chrome.exe" --proxy-server="127.0.0.1:8080" --user-data-dir="%USERPROFILE%\chrome-mitm-profile"
The separate --user-data-dir is required. If Chrome is already running, a new window without its own profile just attaches to the running instance and silently ignores the proxy flag. The separate profile gives you a clean Chrome that only talks through mitmproxy, so only your test flow shows up in mitmweb.
Tip: Save this so you do not have to type it every time: a shell alias or small script on Mac (for example
~/bin/chrome-mitm), a desktop shortcut with the flags on Windows. Same idea as the "create a shortcut" tip in the Fiddler section.
4. Trust the mitmproxy Certificate
Without this, HTTPS sites show certificate warnings and you cannot read the request and response content.
- In the proxied Chrome, open
http://mitm.it(type thehttp://explicitly) - Download the certificate for your system, then trust it:
macOS:
- Open the downloaded file. It opens in Keychain Access and is added to your login keychain
- In Keychain Access, find the
mitmproxycertificate and double-click it - Expand Trust and set When using this certificate to Always Trust
- Close the window and save with your Mac password
Windows:
- Double-click the downloaded
.p12file to start the Certificate Import Wizard - Choose Current User, leave the password empty when asked
- Choose Place all certificates in the following store > Trusted Root Certification Authorities
- Finish and click Yes on the security warning
Then fully quit the proxied Chrome and relaunch it with the command from step 3.
Verify: In the proxied Chrome, open any HTTPS site. It loads without a certificate warning, and the request appears in mitmweb with readable headers and body.
Important: Only trust the mitmproxy certificate on machines you control. Remove it (Keychain Access on Mac,
certmgr.msc> Trusted Root Certification Authorities on Windows) when you no longer need it.
5. Install BlazeMeter in the Proxied Profile
The proxied profile is a fresh Chrome profile, so it has no extensions. Repeat the Blazemeter steps from Section 1 - Install Tools inside this profile:
- Install the BlazeMeter extension from the Chrome Web Store
- Sign in to your Blazemeter account
- Pin the extension to the toolbar
- Click the extension icon > Advanced Options and make sure:
- Record Ajax Requests is enabled
- Randomize Recorded Think Time is disabled
Recording (Dual Recording)
Same idea as the Windows workflow: one session, captured by both tools at the same time.
1. Start mitmweb with Saving Enabled
Create a working folder for this recording, then start the proxy so it writes every flow to a file:
mitmweb --listen-port 8080 -w session.flow
Run this from inside the working folder so session.flow lands next to the .jmx.
-w (--save-stream-file) streams flows to session.flow as they happen. This is the .saz equivalent.
2. Clear the Flow List
In the mitmweb UI, clear any existing flows before you start so the session only contains your test flow.
3. Launch the Proxied Chrome and Start BlazeMeter
- Launch the proxied Chrome with the command from setup step 3 (or your alias / shortcut)
- Click the Blazemeter extension icon
- Give your test a name (e.g., "Login Flow")
- Click the record button (red circle)
4. Perform the User Flow
- Name each step before you perform the business action (
01_Home,02_Login,03_Dashboard, and so on). This keeps the recording consistent with Section 4 - Recording - Navigate as a real user would, at a normal pace
- Watch mitmweb: every request you make should appear in the list
5. Stop and Export
- Click the stop button in Blazemeter (square icon)
- Click the
.jmxexport button and save the file into the working folder - Go back to the terminal running mitmweb and press Ctrl+C. This finalizes
session.flow
Result: recording.jmx + session.flow in the same folder. This is the same pair as .jmx + .saz in the Fiddler workflow. Open the .jmx in JMeter as described in Section 4 - Open the Recording in JMeter.
Correlation with mitmproxy
These steps mirror How to Find Dynamic Values Using Fiddler one to one, so you can follow that section and swap in the mitmproxy step where it differs.
Steps:
- Reopen the saved session in mitmweb (no proxy needed, you are only reading):
mitmweb -r session.flow
- Reduce noise. In the Search box at the top of mitmweb, type:
This hides everything except your application's traffic, and hides static assets (CSS, JavaScript, images, fonts).~d yourapp.com & !~a
- Replay the
.jmxonce in JMeter (1 user, 1 loop, with View Results Tree, see Section 7 - Debug) and find the first request that fails - Copy the suspicious dynamic value from that request. Take a distinctive chunk of it, 10 to 20 characters, with no special characters
- Put the chunk in the Highlight box (not Search, so all flows stay visible in order):
This highlights every flow whose response body or header contains the value. The first highlighted flow is where the value first appeared. Cookies are covered too, because they arrive in~bs CHUNK | ~hs CHUNK
Set-Cookieresponse headers - Click that flow and open the Response tab. Check whether the value lives in the body (JSON or HTML) or in a header. That decides which extractor you use
- To find every request that sends the value (the places you will replace with
${variable}), change the highlight to:~bq CHUNK | ~hq CHUNK - In JMeter, add the extractor to the request from step 5 and replace the hardcoded value in the requests from step 7. The extractor configuration is the same as the Fiddler workflow, see Extractors
Tip: Search and Highlight take the same filter language. Search hides non-matching flows, Highlight keeps everything and colours the matches. Use Search for noise, Highlight for tracing a value.
Filter Cheat Sheet
| Filter | Matches |
|---|---|
~u regex | URL |
~d regex | Domain |
~m regex | Method (GET, POST) |
~c code | Status code, exact number |
~t regex | Content-Type header |
~b regex | Body, request or response |
~bq regex | Request body |
~bs regex | Response body |
~h regex | Header, request or response (matched as name: value) |
~hq regex | Request header |
~hs regex | Response header |
~a | Static assets: CSS, JavaScript, images, fonts |
~e | Flows that errored |
Operators: & AND, | OR, ! NOT, parentheses for grouping.
Memory aid: q = request, s = response, no suffix = both. A value without a tilde searches the URL.
Examples:
| Filter | Meaning |
|---|---|
~d yourapp.com & !~a | Only app traffic, no static files |
~m POST & ~u /login | The login submission |
(~c 401 | ~c 403) & ~d yourapp.com | Auth failures on your app |
Gotchas
- Filter values are regular expressions, and case-insensitive by default. Tokens often contain
+ ? ( ) $. Escape them with a backslash, or search a chunk that has no symbols - URL encoding. A value can appear as
abc%2Bdefin a request butabc+defin a response. Searching a symbol-free chunk avoids this - Spaces. Wrap values that contain spaces in quotes:
~b "hello world" ~ctakes an exact code. Use~c 500 | ~c 502, not a pattern like~c 5..- Compressed bodies (gzip, br) are decoded before matching. No extra step needed
Troubleshooting
-
Chrome shows "No internet" and mentions "If you use a proxy server... check System Settings > Network" (or "check your proxy settings" on Windows). This is Chrome's generic "proxy not reachable" page. Do not change the system proxy settings. We only use a Chrome flag. Check that mitmweb is still running in its terminal and listening on the same port as the Chrome flag
-
Port already in use. Check what is holding it:
# macOSlsof -nP -iTCP:8080 -sTCP:LISTEN# Windowsnetstat -ano | findstr :8080Either stop that process, or switch both mitmweb (
--listen-port 8888) and the Chrome flag (--proxy-server="127.0.0.1:8888") to another port -
Test the proxy without Chrome (curl ships with both macOS and Windows 10+):
curl -x http://127.0.0.1:8080 http://mitm.itAn HTML response means the proxy works. "Connection refused" means mitmweb is not listening
-
mitm.it does not load. Fully quit the proxied Chrome (Cmd+Q on Mac, close every window on Windows), relaunch it with the command from setup step 3, and type
http://mitm.itwithhttp://explicitly -
Certificate warnings on HTTPS sites. The certificate is not trusted yet (Always Trust in Keychain Access on Mac, Trusted Root Certification Authorities on Windows). Redo step 4 of the setup
-
Nothing appears in mitmweb. You are probably browsing in your normal Chrome window instead of the proxied profile. The proxied window is the one launched with the separate
--user-data-dir
Optional Extras
-
Record only app traffic from the CLI, no web UI:
mitmdump -w session.flow "~d yourapp.com & !~a" -
List flows in a saved session that contain a value, without opening the UI:
mitmdump -nr session.flow "~bs CHUNK"-nmeans no proxy server,-rreads the file. -
Share evidence with teammates who still use Fiddler by exporting the session as HAR, which Fiddler and browser dev tools can open:
mitmdump -nr session.flow --set hardump=session.har
Note: The
hardumpoption is available from mitmproxy 10.1 onward. Runmitmdump --options | grep hardumpto confirm your version has it.
Tips
-
Keep the
.flowfile next to the.jmx. You will keep going back to it during correlation, exactly like the.sazin the Fiddler workflow -
One terminal per job. Recording (
-w) and reading (-r) are different commands. Do not open a session file for reading while another mitmweb is still writing to it -
Highlight, not Search, when tracing. If you hide flows, you lose the order, and order is what tells you where a value first appeared
-
Same skills, different tool. Everything after this page (extractors, script enhancement, debug) is identical to the Fiddler guide