fiddler-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Capabilities
Features and capabilities supported by this server
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| open_archiveA | Parse a Fiddler .saz archive and return an overview. Archives are cached; use reload=true to re-read. Args: saz_path: Path to the .saz file. reload: Re-parse the file even if already cached. |
| list_sessionsA | List sessions (method, URL, status, duration, size, process...) with pagination. Args: saz_path: Path to the .saz file (parsed on first use). limit: Max sessions to return (1-500). offset: Skip the first N sessions (pagination). |
| get_sessionA | Full details of one session: request & response start lines, headers, bodies, timers, flags. This is the only tool that returns the complete (unredacted) URL and bodies — intended for deep inspection of a specific session. Args: saz_path: Path to the .saz file. index: Session number (1-based, as shown by list_sessions). include_body: Decode and show bodies (may be truncated). max_body_chars: Max chars of each decoded body to include. |
| filter_sessionsA | Search/filter sessions by host, method, status, URL keyword or regex, body keywords, size and duration. Args: saz_path: Path to the .saz file. host: Substring match on Host[:port]. method: HTTP method, e.g. GET/POST (case-insensitive). status: Exact status code. status_min / status_max: Status code range. url_keyword: Case-insensitive substring of the URL. url_regex: Regex (Python syntax, max 200 chars) matched against the URL. req_body_keyword: Substring search inside the decoded request body. resp_body_keyword: Substring search inside the decoded response body. min_size / max_size: Request+response body size range in bytes. min_ms / max_ms: Total duration range in milliseconds. only_errors: Only 4xx/5xx responses. only_redirects: Only 3xx responses. only_success: Only 2xx responses. with_response: True/False to require/forbid a response. websocket: True/False to require/forbid WebSocket messages. limit: Max sessions returned (1-1000). |
| session_statsB | Aggregate statistics: method/status/host distribution, traffic volume, duration percentiles, error samples. Args: saz_path: Path to the .saz file. |
| slow_requestsA | Rank sessions by total duration (Fiddler TOTAL = ClientDoneResponse - ClientBeginRequest). Args: saz_path: Path to the .saz file. top_n: How many slowest sessions to return (1-100). min_ms: Only consider sessions slower than this threshold. |
| security_scanA | Scan traffic for security issues: cleartext credentials, secret tokens in URLs/bodies, cookie flags, sensitive files, PII leakage. Args: saz_path: Path to the .saz file. max_findings: Cap on reported findings (1-2000). |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/hqzzzz/fiddler-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server