Where your data lives
Everything about a project lives in the workspace folder: collections, environments, mocks and notes as text files, and captured traffic and send history in a local SQLite database inside the .microkoi service folder.
The app data folder (~/Library/Application Support/Microkoi) holds only settings, the recent workspaces list and the root certificate. Logs go to ~/Library/Logs/Microkoi.
Settings for this machine — the selected environment, running mock servers and their network access, breakpoints, workspace trust — are stored there too, not in the project folder, so nobody can plant them through a repository.
The app never sends us your traffic, your requests or usage information. There is no telemetry and no hidden network calls: the app only contacts addresses you chose — through the proxy, the request client and monitors.
The root certificate
The certificate is generated the first time the proxy is used and is unique to your installation, so there is no shared key that could compromise every Microkoi user at once.
It becomes trusted only through your action and only after your system asks you to confirm it. You can remove it at any time from Settings → Root certificate.
The private key is stored in a file that only your user account can read. That is the usual level of protection for a desktop app, but worth knowing: a program running as you can read the key. A compromised user account therefore means a compromised certificate — in that case, remove the certificate from your keychain and delete the files in the app data folder.
What Microkoi never does
- Install the certificate without your action and confirmation
- Run hidden: you start the proxy, and its state is always visible in the interface
- Accept connections from other devices until you turn that on with a toggle
- Bypass certificate pinning or other protections of third-party apps
- Turn off certificate verification of real servers for all requests at once
- Send your data to us or anyone else
Connections from the local network
To capture a phone’s traffic, the proxy has to be opened to the local network. Only an explicit toggle does that, and while connections are allowed the proxy is marked “on network” on the traffic screen and connected devices are listed by address.
The proxy has no authentication, so any device on the network can use it — turn connections on only on a trusted network and only while debugging. Devices on the network cannot use the proxy to reach your computer’s own addresses — localhost, 127.0.0.0/8 and its network interface addresses — so development services running on your computer stay out of their reach.
The certificate page for phones serves only the certificate itself and its fingerprint for comparison. The private key never leaves your computer.
Workspaces from someone else’s repository
Anything in a workspace from a repository may have been prepared by someone else. So a folder that has never been opened on this computer opens as new: its mock servers and monitors do not start on their own until you click Trust.
- Workspace files replaced with symbolic links are never read or overwritten, so the app never leaves the folder
- Files are read with a size limit, so a planted huge file cannot exhaust memory
- The app shows a mock’s body file but never opens or runs it
- A note never loads images from external addresses — otherwise opening it would send a request wherever its author chose
Mock servers
A mock server grants CORS only to local origins — localhost, *.local and private network addresses — so a web app in development can work with it. Websites on the internet get no permission: otherwise any page open in the browser could read the server’s responses, which often hold data from captured traffic.
While a server is running, any program on your computer can read its responses. Do not leave real tokens or personal data in endpoints.
Secrets in environments
Environment variables are stored as plain text in workspace files. The “secret” flag hides a value in the interface but does not encrypt it on disk, and the environment editor says so plainly.
If your workspace is in a repository, keep tokens and passwords in a separate environment and add its file to your project’s .gitignore. Shared URLs and non-secret settings can live in environments that go to git.
Acceptable use
Microkoi is a debugging tool. Capture and analyse only traffic from your own devices and apps, or traffic you have the owner’s permission to process. If captured traffic contains other people’s personal data, the user is responsible for processing it lawfully.