01 · Route and inspect
TLS interception
Decrypts configured CONNECT tunnels so Pipelock can inspect HTTP bodies and headers.
Operator surface
Set the configuration key
The release manifest records this key as the capability's operator entry point. Open the pinned source pointer to inspect its schema context.
Availability
Included tiers
Community
Pro
Enterprise
Deployment boundary
Requires a configured local CA that the intercepted client trusts; passthrough traffic remains encrypted and cannot be body-scanned.
Source records
Open the pinned source
The release manifest names these source pointers. The publication gate confirms their Go files and declarations exist at the same Pipelock commit as this page; the linked code provides the runtime context.
Read next