01 · Route and inspect

TLS interception

Decrypts configured CONNECT tunnels so Pipelock can inspect HTTP bodies and headers.

Free tls-interception
Document source v3.5.0 release Manifest commit ca05ed06 Open manifest

Operator surface

Set the configuration key

The release manifest records this key as the capability's operator entry point. Open the pinned source pointer to inspect its schema context.

Configuration key tls_interception Read Config

Availability

Included tiers

Community Pro Enterprise
Deployment boundary

Requires a configured local CA that the intercepted client trusts; passthrough traffic remains encrypted and cannot be body-scanned.

Source records

Open the pinned source

The release manifest names these source pointers. The publication gate confirms their Go files and declarations exist at the same Pipelock commit as this page; the linked code provides the runtime context.

Read next

Guides and references