Fiddler Everywhere is a desktop debugging proxy for Windows, macOS and Linux. To make the traffic it captures leave through an upstream proxy, open Settings, go to Gateway, pick Manual proxy configuration and enter the proxy string HOST:PORT. The Gateway has no field for a username and password, so if your proxy authenticates that way, point Fiddler at a small local forwarder that adds them, as shown below.

Fiddler is a GUI application we could not run on our test machines. Setting names come from Fiddler Everywhere's documentation; the forwarder half of the chain we ran with mitmproxy 12.1.2 against a local authenticating proxy.

The Gateway settings

Settings > Gateway has three choices:

OptionWhat Fiddler does
Use system proxyThe default. Fiddler chains to whatever proxy the operating system uses
Manual proxy configurationUses the proxy string and bypass list you enter
No proxySends everything directly to the servers

The proxy string takes one proxy for everything, HOST:PORT, or one per scheme:

http=HOST:PORT;https=HOST:PORT

The bypass list is semicolon-separated and accepts wildcards such as *.internal.example.com, the token <local> for any host name without a dot, and <-loopback>, which removes Fiddler's default bypass for 127.0.0.1 and localhost.

Adding a username and password

ProxyHive proxies authenticate with a username and password. Fiddler's Settings > Connections has Enable Automatic Authentication, but that fetches Kerberos, Negotiate or NTLM credentials from the operating system's store; it is not a place to type a provider's login. The documented Gateway has nothing else.

A local forwarder solves it without touching Fiddler. mitmproxy can run as a pass-through that only adds the credentials:

mitmdump --listen-host 127.0.0.1 --listen-port 8081 \
  --mode upstream:http://HOST:PORT \
  --upstream-auth USERNAME:PASSWORD \
  --ignore-hosts '.*'

--ignore-hosts '.*' tells mitmproxy to tunnel every HTTPS connection without decrypting it, so Fiddler stays the only tool reading your traffic. In our test, a client pointed at this forwarder saw the real site certificate, and the upstream proxy received an authenticated CONNECT. Then set Fiddler's proxy string to:

127.0.0.1:8081

The chain is your app, then Fiddler (decrypting), then the forwarder (adding credentials), then the proxy.

Capture HTTPS

Fiddler Everywhere captures only plain HTTP until you trust its root CA. Under Settings > HTTPS:

  1. Trust CA Certificate in the User Store on Windows or macOS. On Linux, use Export (DER, PEM or PKCS 12) and trust the certificate yourself.
  2. Turn on Capture HTTPS traffic, which is off by default.
  3. Leave Ignore server certificate errors off. With it on, Fiddler stops warning you about invalid server certificates, which is how an impersonated site would look.

Enable HTTP/2 support under Connections is on by default, so HTTP/2 sessions are captured as HTTP/2.

Check the route

With Fiddler capturing, request https://api.ipify.org?format=json from a captured browser, or from a terminal with the exported PEM: curl -x http://127.0.0.1:8866 --cacert fiddler-root.pem "https://api.ipify.org?format=json". The ip in the response should be the proxy's. If it is yours, the Gateway is still on Use system proxy or the host matched the bypass list. If Fiddler shows an error from the upstream, the proxy error codes guide decodes the status; a 407 means the credentials did not reach the proxy.

Rules and scripting

The Rules tab edits traffic with a visual condition and action builder. The Scripting tab, marked beta, runs C# hooks such as OnBeforeRequest and OnBeforeResponse, one active script at a time. Fiddler Classic, the older Windows-only tool, has different settings that this page does not cover.

With ProxyHive

Testing how your own site or API behaves from another country does not need a consumer address. A datacenter IP is a static exit in the location you choose at checkout, with HTTP, HTTPS and SOCKS5 and username and password authentication, which is what the forwarder above passes on. For a scripted alternative to the whole chain, see mitmproxy.