Skip to main content

Recording with BlazeMeter + mitmproxy

This page is the dual recording workflow with mitmproxy in place of Fiddler Classic. It works on macOS and Windows. The only change is the evidence-capture tool. BlazeMeter stays exactly as it is in Section 4 - Recording.

When to Use This Page​

  • You are on macOS. Fiddler Classic does not run on Mac.
  • You are on Windows but do not have access to Fiddler, or you cannot use Fiddler Classic for work under its current license. Since 3 August 2026, Progress limits Fiddler Classic to non-commercial use (see Progress's commercial use page).
  • You want the same workflow as the Windows guide: BlazeMeter records the .jmx, mitmproxy captures the evidence session (.flow instead of .saz) for correlation.

mitmproxy is free, open source and cross-platform. It fills the Fiddler role one to one:

Most steps are the same on both systems. Where they differ, each step shows a macOS and a Windows choice.

RoleFiddlermitmproxy
Recording the .jmxBlazeMeter extensionBlazeMeter extension (unchanged)
Evidence captureFiddler Classicmitmweb (mitmproxy's web UI)
Saved session.saz file.flow file
Search for dynamic valuesCtrl+F highlightHighlight filter box
Proxy port88888080

One-Time Setup​

1. Install mitmproxy​

macOS:

brew install mitmproxy

Windows: download the installer from https://mitmproxy.org, or run:

winget install mitmproxy.mitmproxy

Both add mitmproxy, mitmweb and mitmdump to your PATH. Open a new terminal after installing.

JMeter install stays as in Section 1 - Install Tools. On Mac you can also run brew install jmeter instead of downloading the zip.

Verify: mitmproxy --version prints the version (this guide was checked against 12.2.3).

2. Start the Proxy​

mitmweb --listen-port 8080

The terminal must stay open while you record. mitmweb opens its web UI in your browser, usually at http://127.0.0.1:8081. This UI is where you will read the captured traffic, the same way you read the Fiddler session list.

3. Launch a Dedicated Proxied Chrome​

This is the same idea as the chrome.exe --proxy-server step in the Fiddler guide, with two changes: port 8080 and a separate profile.

macOS:

open -na "Google Chrome" --args \
--proxy-server="127.0.0.1:8080" \
--user-data-dir="$HOME/chrome-mitm-profile"

Windows (Command Prompt or PowerShell):

"C:\Program Files\Google\Chrome\Application\chrome.exe" --proxy-server="127.0.0.1:8080" --user-data-dir="%USERPROFILE%\chrome-mitm-profile"

The separate --user-data-dir is required. If Chrome is already running, a new window without its own profile just attaches to the running instance and silently ignores the proxy flag. The separate profile gives you a clean Chrome that only talks through mitmproxy, so only your test flow shows up in mitmweb.

Tip: Save this so you do not have to type it every time: a shell alias or small script on Mac (for example ~/bin/chrome-mitm), a desktop shortcut with the flags on Windows. Same idea as the "create a shortcut" tip in the Fiddler section.

4. Trust the mitmproxy Certificate​

Without this, HTTPS sites show certificate warnings and you cannot read the request and response content.

  1. In the proxied Chrome, open http://mitm.it (type the http:// explicitly)
  2. Download the certificate for your system, then trust it:

macOS:

  1. Open the downloaded file. It opens in Keychain Access and is added to your login keychain
  2. In Keychain Access, find the mitmproxy certificate and double-click it
  3. Expand Trust and set When using this certificate to Always Trust
  4. Close the window and save with your Mac password

Windows:

  1. Double-click the downloaded .p12 file to start the Certificate Import Wizard
  2. Choose Current User, leave the password empty when asked
  3. Choose Place all certificates in the following store > Trusted Root Certification Authorities
  4. Finish and click Yes on the security warning

Then fully quit the proxied Chrome and relaunch it with the command from step 3.

Verify: In the proxied Chrome, open any HTTPS site. It loads without a certificate warning, and the request appears in mitmweb with readable headers and body.

Important: Only trust the mitmproxy certificate on machines you control. Remove it (Keychain Access on Mac, certmgr.msc > Trusted Root Certification Authorities on Windows) when you no longer need it.

5. Install BlazeMeter in the Proxied Profile​

The proxied profile is a fresh Chrome profile, so it has no extensions. Repeat the Blazemeter steps from Section 1 - Install Tools inside this profile:

  1. Install the BlazeMeter extension from the Chrome Web Store
  2. Sign in to your Blazemeter account
  3. Pin the extension to the toolbar
  4. Click the extension icon > Advanced Options and make sure:
    • Record Ajax Requests is enabled
    • Randomize Recorded Think Time is disabled

Recording (Dual Recording)​

Same idea as the Windows workflow: one session, captured by both tools at the same time.

1. Start mitmweb with Saving Enabled​

Create a working folder for this recording, then start the proxy so it writes every flow to a file:

mitmweb --listen-port 8080 -w session.flow

Run this from inside the working folder so session.flow lands next to the .jmx.

-w (--save-stream-file) streams flows to session.flow as they happen. This is the .saz equivalent.

2. Clear the Flow List​

In the mitmweb UI, clear any existing flows before you start so the session only contains your test flow.

3. Launch the Proxied Chrome and Start BlazeMeter​

  • Launch the proxied Chrome with the command from setup step 3 (or your alias / shortcut)
  • Click the Blazemeter extension icon
  • Give your test a name (e.g., "Login Flow")
  • Click the record button (red circle)

4. Perform the User Flow​

  • Name each step before you perform the business action (01_Home, 02_Login, 03_Dashboard, and so on). This keeps the recording consistent with Section 4 - Recording
  • Navigate as a real user would, at a normal pace
  • Watch mitmweb: every request you make should appear in the list

5. Stop and Export​

  • Click the stop button in Blazemeter (square icon)
  • Click the .jmx export button and save the file into the working folder
  • Go back to the terminal running mitmweb and press Ctrl+C. This finalizes session.flow

Result: recording.jmx + session.flow in the same folder. This is the same pair as .jmx + .saz in the Fiddler workflow. Open the .jmx in JMeter as described in Section 4 - Open the Recording in JMeter.


Correlation with mitmproxy​

These steps mirror How to Find Dynamic Values Using Fiddler one to one, so you can follow that section and swap in the mitmproxy step where it differs.

Steps:

  1. Reopen the saved session in mitmweb (no proxy needed, you are only reading):
    mitmweb -r session.flow
  2. Reduce noise. In the Search box at the top of mitmweb, type:
    ~d yourapp.com & !~a
    This hides everything except your application's traffic, and hides static assets (CSS, JavaScript, images, fonts).
  3. Replay the .jmx once in JMeter (1 user, 1 loop, with View Results Tree, see Section 7 - Debug) and find the first request that fails
  4. Copy the suspicious dynamic value from that request. Take a distinctive chunk of it, 10 to 20 characters, with no special characters
  5. Put the chunk in the Highlight box (not Search, so all flows stay visible in order):
    ~bs CHUNK | ~hs CHUNK
    This highlights every flow whose response body or header contains the value. The first highlighted flow is where the value first appeared. Cookies are covered too, because they arrive in Set-Cookie response headers
  6. Click that flow and open the Response tab. Check whether the value lives in the body (JSON or HTML) or in a header. That decides which extractor you use
  7. To find every request that sends the value (the places you will replace with ${variable}), change the highlight to:
    ~bq CHUNK | ~hq CHUNK
  8. In JMeter, add the extractor to the request from step 5 and replace the hardcoded value in the requests from step 7. The extractor configuration is the same as the Fiddler workflow, see Extractors

Tip: Search and Highlight take the same filter language. Search hides non-matching flows, Highlight keeps everything and colours the matches. Use Search for noise, Highlight for tracing a value.


Filter Cheat Sheet​

FilterMatches
~u regexURL
~d regexDomain
~m regexMethod (GET, POST)
~c codeStatus code, exact number
~t regexContent-Type header
~b regexBody, request or response
~bq regexRequest body
~bs regexResponse body
~h regexHeader, request or response (matched as name: value)
~hq regexRequest header
~hs regexResponse header
~aStatic assets: CSS, JavaScript, images, fonts
~eFlows that errored

Operators: & AND, | OR, ! NOT, parentheses for grouping.

Memory aid: q = request, s = response, no suffix = both. A value without a tilde searches the URL.

Examples:

FilterMeaning
~d yourapp.com & !~aOnly app traffic, no static files
~m POST & ~u /loginThe login submission
(~c 401 | ~c 403) & ~d yourapp.comAuth failures on your app

Gotchas​

  • Filter values are regular expressions, and case-insensitive by default. Tokens often contain + ? ( ) $. Escape them with a backslash, or search a chunk that has no symbols
  • URL encoding. A value can appear as abc%2Bdef in a request but abc+def in a response. Searching a symbol-free chunk avoids this
  • Spaces. Wrap values that contain spaces in quotes: ~b "hello world"
  • ~c takes an exact code. Use ~c 500 | ~c 502, not a pattern like ~c 5..
  • Compressed bodies (gzip, br) are decoded before matching. No extra step needed

Troubleshooting​

  • Chrome shows "No internet" and mentions "If you use a proxy server... check System Settings > Network" (or "check your proxy settings" on Windows). This is Chrome's generic "proxy not reachable" page. Do not change the system proxy settings. We only use a Chrome flag. Check that mitmweb is still running in its terminal and listening on the same port as the Chrome flag

  • Port already in use. Check what is holding it:

    # macOS
    lsof -nP -iTCP:8080 -sTCP:LISTEN
    # Windows
    netstat -ano | findstr :8080

    Either stop that process, or switch both mitmweb (--listen-port 8888) and the Chrome flag (--proxy-server="127.0.0.1:8888") to another port

  • Test the proxy without Chrome (curl ships with both macOS and Windows 10+):

    curl -x http://127.0.0.1:8080 http://mitm.it

    An HTML response means the proxy works. "Connection refused" means mitmweb is not listening

  • mitm.it does not load. Fully quit the proxied Chrome (Cmd+Q on Mac, close every window on Windows), relaunch it with the command from setup step 3, and type http://mitm.it with http:// explicitly

  • Certificate warnings on HTTPS sites. The certificate is not trusted yet (Always Trust in Keychain Access on Mac, Trusted Root Certification Authorities on Windows). Redo step 4 of the setup

  • Nothing appears in mitmweb. You are probably browsing in your normal Chrome window instead of the proxied profile. The proxied window is the one launched with the separate --user-data-dir


Optional Extras​

  • Record only app traffic from the CLI, no web UI:

    mitmdump -w session.flow "~d yourapp.com & !~a"
  • List flows in a saved session that contain a value, without opening the UI:

    mitmdump -nr session.flow "~bs CHUNK"

    -n means no proxy server, -r reads the file.

  • Share evidence with teammates who still use Fiddler by exporting the session as HAR, which Fiddler and browser dev tools can open:

    mitmdump -nr session.flow --set hardump=session.har

Note: The hardump option is available from mitmproxy 10.1 onward. Run mitmdump --options | grep hardump to confirm your version has it.


Tips​

  • Keep the .flow file next to the .jmx. You will keep going back to it during correlation, exactly like the .saz in the Fiddler workflow

  • One terminal per job. Recording (-w) and reading (-r) are different commands. Do not open a session file for reading while another mitmweb is still writing to it

  • Highlight, not Search, when tracing. If you hide flows, you lose the order, and order is what tells you where a value first appeared

  • Same skills, different tool. Everything after this page (extractors, script enhancement, debug) is identical to the Fiddler guide