What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To make Chrome or Chromium trust mitmproxy’s HTTPS interception, start mitmproxy, send the browser through its proxy (the default is localhost:8080), open http://mitm.it in that proxied browser, and install the platform-specific public CA certificate. Then visit an HTTPS site and confirm the flow appears in mitmproxy.

Only inspect systems and traffic you are authorized to test. A trusted root CA can validate certificates for intercepted connections; Google describes installing one as a privacy- and security-sensitive operation. Install only the CA created by your own mitmproxy instance and remove its trust after testing.

What the mitmproxy certificate does

mitmproxy acts as an HTTPS-intercepting proxy. For each site you visit, it presents a dynamically generated certificate signed by its own certificate authority (CA). Chrome or Chromium must trust that CA or the TLS handshake produces a certificate warning and the connection cannot be inspected normally. The CA is generated locally the first time mitmproxy runs and is unique to that installation; it is normally stored in ~/.mitmproxy. See mitmproxy’s certificate documentation for the certificate model and file details.

Installing the CA does not route traffic by itself. The browser or device must first use the mitmproxy listener. If the browser is not proxied, mitm.it cannot provide the correct onboarding path and no flows will appear.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Thales - SafeNet eToken Fusion - Phishing-Resistant FIDO2 Certified Security Key for Digital Certificates or Web Apps & Desktop Authentication - USB-A - Pack of 1
  • PKI FIDO2 SECURITY KEY: This USB-A security key combines X509 digital certificates (PKI) and FIDO for maximum protection. Supports digital signatures, file encryption, and phishing-resistant authentication based on FIDO or PKI. FIDO 2.0 level 1 and U2F certified
  • PASSWORDLESS CONVENIENCE: Replace frustrating passwords with a simple 4-digit PIN for accessing apps and sites. Seamlessly login to web apps and Windows sessions
  • BROAD COMPATIBILITY: Works with Windows, Linux and USB-A devices. Seamlessly integrates with Identity Providers or Credential Management Systems supporting FIDO2, ensuring secure use across various platforms, including Thales, Microsoft, AWS, and Google
  • ENHANCED USER ADOPTION: Features a sensitive presence detector on the USB key, providing ease of use and superior security. Certified for U2F and FIDO2, ideal for individuals who want to secure access to their personal online accounts - Microsoft, Google, Twitter, Facebook, GitHub
  • THALES: We offer a wide range of FIDO authenticators, providing robust, phishing-resistant MFA that comply with stringent regulations. With almost three decades of experience, Thales is a pioneer in passwordless authentication devices, supported globally by the FIDO Alliance and industry analysts

Before you install anything

Confirm authorization and scope

  • Use mitmproxy only on applications, accounts, devices and networks you are allowed to inspect.
  • Plan how you will remove the CA from the operating-system trust store when the test ends.
  • Do not copy or publish the private-key-containing CA bundle.

Start the proxy and identify its address

Launch mitmproxy on the workstation or proxy host. Its default listener is http://localhost:8080. If a phone, tablet or another computer is the client, replace localhost with the reachable address of the machine running mitmproxy and keep port 8080 unless you deliberately changed the listener. The mitmproxy getting-started guide covers the initial startup and proxy setup.

Use the public certificate file

mitmproxy creates several files. Install the public CA certificate appropriate for the platform, not the file that contains the private key.

File What it contains Typical purpose
mitmproxy-ca.pem Certificate plus private key Keep private; do not distribute as an ordinary CA certificate
mitmproxy-ca-cert.pem Public CA certificate in PEM format Most non-Windows platforms
mitmproxy-ca-cert.p12 Public CA certificate in PKCS#12 form Windows
mitmproxy-ca-cert.cer The same public certificate with a device-oriented extension Some Android installation flows

The exact files are created under the mitmproxy configuration directory after first startup. If you have more than one mitmproxy installation, each has its own CA; a certificate from one installation will not automatically validate certificates generated by another.

Install through mitm.it (recommended)

  1. Start mitmproxy on the intended proxy host.
  2. Configure Chrome or Chromium, or the device’s network proxy, to use the host and port. For a local desktop test, use localhost:8080. For a separate device, use the proxy host’s LAN address rather than that device’s own localhost.
  3. In the browser that is already using the proxy, open http://mitm.it. mitmproxy detects the client platform and displays the corresponding certificate download and installation instructions.
  4. Follow the instructions shown for the actual operating system and browser distribution. Do not substitute the private-key bundle for the public CA file.
  5. After the trust change, open an HTTPS site and watch mitmproxy’s flow list. The getting-started guide uses https://mitmproxy.org as a verification destination.

If the page at mitm.it is unreachable, troubleshoot proxy connectivity before attempting certificate import. The onboarding page must be loaded through the configured mitmproxy listener.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Chrome and Chromium trust by platform

Desktop Chrome on Windows, macOS and other desktop systems

Desktop Chrome uses custom roots provided by the computer’s certificate trust facilities. Google documents the browser view at Settings > Privacy and security > Security > Manage certificates; the relevant trust store and import controls are supplied by the operating system and browser build. Use the platform instructions presented by mitm.it rather than assuming that every Chromium distribution exposes identical dialogs. Google’s overview is Manage Chrome safety and security.

On Windows, mitmproxy provides the .p12 form because Windows certificate tooling commonly uses that container. Import it only into the intended machine or user trust store, and confirm that the resulting entry is trusted for certificate-authority use. On macOS and other desktop systems, use the public PEM/CRT-style certificate and the operating system’s certificate manager as directed by mitm.it. Menu names and trust backends can differ between Chrome, Chromium, Linux distributions and packaged builds.

Linux Chrome and Chromium

Linux installations vary by distribution, packaging format and certificate backend. mitmproxy links a dedicated Chrome-on-Linux manual installation path from its certificate guide. Follow the current instructions for your distribution, then restart Chrome or Chromium if the browser does not recognize a newly trusted system root. There is no single import sequence that is guaranteed for every Chromium build.

Managed ChromeOS

ChromeOS is a separate workflow from desktop Chrome. On enrolled devices, an administrator can upload a PEM, CRT or CER CA file in the Google Admin console and deploy it through certificate-management settings. Google’s Set up an HTTPS certificate authority explains the authority import process; ChromeOS certificate-manager guidance describes adding the authority and selecting its trust purposes. Do not treat a managed ChromeOS device as if it were a desktop operating-system trust store. Local users may be unable to install a CA when policy controls the device.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Manual import when mitm.it is unavailable

Manual import is useful when the onboarding page cannot be reached or an administrator must deploy the CA. First obtain the public file from the mitmproxy configuration directory, choosing the format required by the target platform. Then open the operating system or managed-browser certificate manager, import the file into the trusted root or certificate authority store, and enable the trust purpose for identifying websites when the platform asks. Restart Chrome or Chromium after changing system trust if it continues to show the old warning.

On managed ChromeOS, use the administrator workflow rather than a local desktop import. On Linux, use the distribution-specific instructions linked by mitmproxy because Chromium packages can use different trust databases. On Windows, use the supplied .p12 file and verify that the authority, rather than an end-entity site certificate, was imported.

Verify the installation

  1. Leave Chrome or Chromium configured to use mitmproxy.
  2. Open an HTTPS site such as https://mitmproxy.org.
  3. Confirm a new flow appears in mitmproxy and that the browser does not show a CA-untrusted warning.
  4. If the flow is present but the page fails, inspect the flow details for a server error, policy block or application-level certificate pinning.

A successful import only proves that this browser trusts this mitmproxy CA. It does not make applications that bypass the proxy, use a different trust store or enforce certificate pinning interceptable.

Troubleshooting

Symptom Likely cause Fix
mitm.it does not load and no flows appear The client is not reaching the configured proxy, or the address is wrong Check the proxy host and port. For another device, use the proxy host’s reachable address; localhost refers to the client itself.
HTTPS shows a certificate warning after import The CA is not trusted in the store used by this Chrome/Chromium build Verify that the public CA, not the private bundle, was imported as a trusted authority. Restart the browser and follow the platform-specific mitm.it or Chrome instructions.
One application never appears in mitmproxy It bypasses operating-system HTTP proxy settings Use an applicable mitmproxy alternative such as WireGuard, Local Capture or transparent mode, as described in Proxy Modes.
Only particular sites or apps fail Certificate pinning rejects mitmproxy’s generated certificate Exclude those hosts from interception if their contents are not required. Intercepting pinned traffic may require changing the application, which is appropriate only when you control the test target.
The device is managed and import controls are missing Administrative policy controls the trust store Ask the ChromeOS or browser administrator to deploy the CA through the organization’s certificate-authority policy.

Google’s policy reference, including managed-browser trust behavior, is available at Set Chrome policies for users or browsers.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Thetis Pro FIDO2 Security Key Passkey with Complex Pin [PinPlex], Hardware Device Supports USB A, Type C &NFC, TOTP/HOTP Authenticator APP, PIV Certificates, FIDO 2.0 Two Factor Authentication 2FA MFA
  • Dual USB-A and USB-C Security Key – Features both USB-A and USB-C connectors for seamless compatibility across desktops, laptops, and tablets. Supports plug-and-stay use or keychain carry.
  • NFC-Enabled for Mobile Access – Built-in NFC allows fast, wireless authentication with Android and iPhone devices. Ideal for mobile logins and on-the-go security.
  • FIDO Certified for Strong Authentication – [CHECK COMPATIBILITY before purchase] Fully compliant with FIDO2 and FIDO U2F standards. Works with major platforms like Google, Microsoft, GitHub, and Dropbox.
  • Passwordless Login with PinPlex – Supports secure passkey login via WebAuthn and CTAP2 with added protection from PinPlex, a complex PIN system that enhances physical security.
  • Multi-Layer Authentication Support – Includes PIV certificates and supports both TOTP and HOTP for strong 2FA/MFA coverage across enterprise and consumer apps.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Security, cleanup and reliability

Keep the CA private to the test environment. Anyone who obtains the CA private key and convinces a client to trust it could generate certificates for intercepted connections. Do not send mitmproxy-ca.pem to colleagues when they only need the public certificate. When testing is complete, remove the mitmproxy CA from the operating-system or ChromeOS trust store, restore the original proxy settings, and close mitmproxy. If the CA directory is deleted or a new installation generates a different CA, clients must be enrolled with the new public certificate.

Proxying can expose failures that are unrelated to CA installation: a client may bypass the proxy, a managed policy may override settings, a server may reject interception, or certificate pinning may stop the handshake. Treat each as a separate diagnostic branch instead of repeatedly reinstalling the certificate.

Or skip the browser setup: ScreenshotNeo

If your goal is a clean image or PDF of a public website rather than inspecting its HTTPS traffic, ScreenshotNeo avoids local browser proxy and certificate configuration. It is a website screenshot API and MCP server: before capture it accepts cookie/consent banners and removes more than 60 known consent platforms, newsletter popups and chat widgets. Bot checks, CAPTCHAs, blank pages, timeouts, failed loads and cache hits are not billed, and response headers identify the page verdict and billing status. Its MCP server provides take_screenshot, get_page_info and capture_pdf tools for Claude, Cursor and other MCP clients.

Here is a one-call cURL capture; the complete parameter reference is in the ScreenshotNeo documentation:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Python

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Node.js

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

ScreenshotNeo supports full-page and selector captures, dark mode, device presets and custom viewports, retina scale, PDF paper and margin controls, HTML/CSS rendering, custom JavaScript, clicks, waits, ad and tracker blocking, headers, cookies, user agents, authorization, timezone and geolocation, transparent backgrounds, resizing, TTL caching, signed image links, asynchronous webhooks and bulk capture of up to 100 URLs per call. Existing parameter names used by other screenshot APIs are accepted to ease migration.

Best Value
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Plan Included shots Price
Free 1,000 per month $0, no card
Starter 3,000 $5
Growth 15,000 $15
Pro 60,000 $39
Scale 250,000 $99
Business 1,000,000 $249

All features are available on every plan, and yearly billing provides two months free. Start with 1,000 free screenshots a month with no card; paid plans start at $5 for 3,000 shots.

Frequently Asked Questions

Why might a reinstall require a new certificate import?

The CA is generated uniquely for each mitmproxy installation. If the original CA directory is removed or a new installation creates another CA, previously enrolled browsers will not trust the new signer until its public certificate is installed.

Can I share the CA file with a teammate who only needs to browse through my proxy?

Share only the public CA certificate when your authorization and security policy permit it. Never distribute mitmproxy-ca.pem, which contains the private key.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.