The request you know. The answer, read properly.
REST, GraphQL, SOAP, JSON-RPC and XML-RPC from one request pane. Nine ways to authenticate, every body type, and an answer pane that tells you what the status code cannot: whether the call actually worked, where the time went, and what changed since the last send.
At a glance
Everything a request can be.
Path variables as /users/:id, rows you tick on and off, the headers Sonda adds shown and unticked at will, a Host header that overrides the host.
GraphQL, with the schema beside you
Fetch the schema with the request's own auth. A side panel lists types and fields; click one and it lands at the cursor. Completions for fields, arguments, enum values and variables. With GET, the document goes in the URL.
SOAP, JSON-RPC, XML-RPC
SOAP 1.1 and 1.2: you write the Header and Body, Sonda wraps the envelope and sets SOAPAction. JSON-RPC 2.0 with an automatic id or notifications. XML-RPC with parameters typed on the way out. A request left on GET is corrected to POST.
A verdict, not just a status
A 200 with a SOAP Fault in it is a failure. Sonda reads the body and says so: SOAP Fault, JSON-RPC error with its code, XML-RPC fault, a FHIR OperationOutcome named by its worst issue, an OData error, a Bundle with its count and a Next page button.
OAuth 2.0 done properly
Authorization code with PKCE, client credentials, password and refresh. The browser opens, the loopback redirect answers, the state is checked. The token goes in the header or the query; the pane says how long it is good for and refreshes on the next send.
The other auths
Digest with MD5, MD5-sess, SHA-256 and SHA-256-sess, challenged and retried on 401. AWS Signature v4 with a session token. OAuth 1.0 with HMAC-SHA1, HMAC-SHA256, PLAINTEXT and RSA-SHA1. Inherit walks folders and the project, and the pane says where the effective auth came from.
Settings per request
Follow redirects, verify TLS, a timeout, gzip on or off to see exactly what the server sends, the cookie jar on or off. Incognito: no history, no jar, the answer not kept. Stop cancels a send mid-flight.
Read the answer, do not just look at it.
Seven tabs: Body, Headers, Timing, Spec, Cookies, Tests, Console. The pane brings the right one forward — the Console when a script stopped, the Tests when a check failed.
Table view
Objects as key and value rows, arrays of objects as columns, nested arrays folded into sub-tables you open in place. Filter rows, resize columns. Copy as CSV. Export to Excel as a relational workbook: a root sheet and one sheet per nested path, with row numbers and parent columns so it joins back.
Types from the shape
One click turns the answer into a TypeScript interface, a JavaScript shape, a Go struct, a Python dataclass or C# classes. Array shapes are merged, nullable and optional fields inferred, integers told from floats, dates recognised.
Timing
A waterfall of DNS, connect, TLS, send, wait and download, with percentages. The remote address, HTTP/1.1 or HTTP/2, the TLS version, the redirect count, and whether the connection was reused.
Keep every send, diff any two
Every send of the session becomes a tab you can rename. Diff with any other send in a side-by-side or inline view. The last known answer is kept per request and shown when a send fails.
The JSON path bar
The path at the cursor, copy path, copy value. Bookmark a path so it survives a longer answer. Save a value as a variable. Add a check from the value in one click: equals this, exists, is this type. Inspect a JWT found in the body.
Spec drift
With an OpenAPI document attached, the Spec tab reads the real answer against it: a content type that differs, schema problems, fields the spec does not list, documented headers that did not come.
Proxies, certificates, cookies.
Set once on the Network page, honoured by every protocol Sonda speaks over TLS — HTTP, WebSocket, SSE, gRPC-Web, MQTT, Kafka, RabbitMQ, NATS, AMQP, Redis, FIX, HL7, STOMP, MCP.
Proxy
The system's, none, or a custom http or socks5 proxy with a bypass list.
Certificates
Extra CA files on top of the system store. Client certificates for mutual TLS per host pattern — an exact host or a domain suffix. HTTP/2 by default.
Cookie jar
Browser-like: host-only and domain cookies, paths, expiry, Secure. Kept per workspace, sealed with it. A Cookies pane to list, filter, add and clear; a per-request switch to leave the jar out.