Free and open source · macOS, Windows, Linux

An API client that knows what the browser will block.

Relay sends real HTTP, GraphQL, gRPC, WebSocket and MCP requests — and can replay them the way Chrome would: Origin, credentials, CORS preflight, CSP connect-src. Catch the bug before your frontend does. No account, and nothing leaves your machine.

no sign-up · no telemetry · imports Postman, Insomnia, Bruno, OpenAPI

Relay with a saved request, its JSON body and the response it came back with
One client for every wire
  • HTTP
  • SSE
  • GraphQL
  • gRPC
  • WebSocket
  • Socket.IO
  • MCP

200 OK in your API client. Blocked in Chrome.

API clients are not browsers, so they skip the checks that break your frontend. Give Relay the page’s origin and it sends the preflight, applies the credentials rules and checks the response the way the Fetch spec says — then tells you, in one line, why the browser would refuse.

Any API clientno origin

GET https://api.example.com/me

200 OK 142 ms · 1.2 KB

{ "id": 42, "email": "ada@example.com" }

Looks fine. Ships Friday.
Relay · browser emulationhttps://app.example.com · credentials
  1. OPTIONS /me → 204 preflight ok
  2. GET /me → 200
  3. CORS error: response uses Access-Control-Allow-Origin: * but credentials require the exact origin https://app.example.com
What your users actually get — found before they do.
  • CORS preflight

    Sent when the method or headers are not safelisted. Status, methods, headers and Max-Age are validated — no redirects, no cookies.

  • Credentials mode

    Cookies are held back cross-origin unless you include them, and a wildcard origin is rejected the moment you do.

  • CSP connect-src

    Paste the page’s policy. Relay blocks the request before it connects and checks every redirect again.

  • Origin and fetch metadata

    A browser User-Agent, Origin and Sec-Fetch-Site, -Mode and -Dest, worked out from scheme, host and port.

CSP error: request to https://api.stripe.com violates connect-src 'self' https://api.example.com for origin https://app.example.comHow browser emulation works →
The Mock server panel serving a collection’s examples on localhost

Build the frontend before the endpoint exists.

Capture real responses as examples, pick a port and start serving. Path templates and query values decide which example answers, and every call your app makes shows up in the log beside it.

How the mock matches requests →

Your API workspace, reviewed like code.

Requests live as readable YAML next to the service they call. Commit, pull and switch branches from the app; tokens never land in the diff.

The Relay YAML format →
A Git-backed workspace with its changes listed in Relay

The same tests, in CI. No second tool.

The desktop app is the CLI. relay run executes the workspace from your repo with the same requests, pm.* scripts and collection auth — and a failed assertion fails the build. JUnit and JSON reporters included.

Run Relay in CI →
$ relay run ./api --env CI --reporters cli,junit
✓ GET  https://api.example.com/health → 200  42ms  [2/2 tests]
✓ POST https://api.example.com/login  → 200  88ms  [1/1 tests]
2 requests, 2 passed, 0 failed · 3/3 assertions · 131ms

Nothing to sign up for. Nothing phoning home.

  • No account

    Open it and send. There is no Relay backend to log in to, and no seat to pay for.

  • No telemetry

    No analytics, no crash reports. The network carries your requests, Git, OAuth and update checks — nothing else.

  • Encrypted at rest

    Your profile and secrets use AES-256-GCM, keyed through the operating system’s credential store.

Moving from Postman?

Drop in your export and keep going — your pm.* scripts keep running.

  • Postman
  • Insomnia
  • Bruno
  • OpenAPI
  • HAR
  • curl
Migration guide →

Send your first request in under a minute.

Free and open source. Signed updates install themselves.