/ SONDA · PROTOCOLS

The request you know. The answer, read properly.

REST, GraphQL, SOAP, JSON-RPC and XML-RPC from one request pane. Nine ways to authenticate, every body type, and an answer pane that tells you what the status code cannot: whether the call actually worked, where the time went, and what changed since the last send.

7 METHODS 9 AUTH TYPES 10 BODY MODES TYPES IN 5 LANGUAGES

At a glance

BodiesNone, form-data with files, URL-encoded, raw JSON / text / XML / HTML / JavaScript, binary, GraphQL, SOAP 1.1 and 1.2, JSON-RPC 2.0, XML-RPC.
AuthInherit, none, bearer, basic, API key, OAuth 2.0, OAuth 1.0, Digest, AWS Signature v4. A bearer that is a JWT gets an Inspect button.
AnswerPretty, raw, table, JSON↔XML, YAML, HTML preview. Timing waterfall. Spec drift. Diff against any earlier send.
OutTypes in TypeScript, JavaScript, Go, Python, C#. A relational Excel workbook from any answer. CSV.
CodecURL, raw HTTP, JavaScript fetch, Go, Python requests. Paste a cURL line and it becomes a request.
/ THE REQUEST

Everything a request can be.

Path variables as /users/:id, rows you tick on and off, the headers Sonda adds shown and unticked at will, a Host header that overrides the host.

GraphQL, with the schema beside you

Fetch the schema with the request's own auth. A side panel lists types and fields; click one and it lands at the cursor. Completions for fields, arguments, enum values and variables. With GET, the document goes in the URL.

SOAP, JSON-RPC, XML-RPC

SOAP 1.1 and 1.2: you write the Header and Body, Sonda wraps the envelope and sets SOAPAction. JSON-RPC 2.0 with an automatic id or notifications. XML-RPC with parameters typed on the way out. A request left on GET is corrected to POST.

A verdict, not just a status

A 200 with a SOAP Fault in it is a failure. Sonda reads the body and says so: SOAP Fault, JSON-RPC error with its code, XML-RPC fault, a FHIR OperationOutcome named by its worst issue, an OData error, a Bundle with its count and a Next page button.

OAuth 2.0 done properly

Authorization code with PKCE, client credentials, password and refresh. The browser opens, the loopback redirect answers, the state is checked. The token goes in the header or the query; the pane says how long it is good for and refreshes on the next send.

The other auths

Digest with MD5, MD5-sess, SHA-256 and SHA-256-sess, challenged and retried on 401. AWS Signature v4 with a session token. OAuth 1.0 with HMAC-SHA1, HMAC-SHA256, PLAINTEXT and RSA-SHA1. Inherit walks folders and the project, and the pane says where the effective auth came from.

Settings per request

Follow redirects, verify TLS, a timeout, gzip on or off to see exactly what the server sends, the cookie jar on or off. Incognito: no history, no jar, the answer not kept. Stop cancels a send mid-flight.

/ THE ANSWER

Read the answer, do not just look at it.

Seven tabs: Body, Headers, Timing, Spec, Cookies, Tests, Console. The pane brings the right one forward — the Console when a script stopped, the Tests when a check failed.

Table view

Objects as key and value rows, arrays of objects as columns, nested arrays folded into sub-tables you open in place. Filter rows, resize columns. Copy as CSV. Export to Excel as a relational workbook: a root sheet and one sheet per nested path, with row numbers and parent columns so it joins back.

Types from the shape

One click turns the answer into a TypeScript interface, a JavaScript shape, a Go struct, a Python dataclass or C# classes. Array shapes are merged, nullable and optional fields inferred, integers told from floats, dates recognised.

Timing

A waterfall of DNS, connect, TLS, send, wait and download, with percentages. The remote address, HTTP/1.1 or HTTP/2, the TLS version, the redirect count, and whether the connection was reused.

Keep every send, diff any two

Every send of the session becomes a tab you can rename. Diff with any other send in a side-by-side or inline view. The last known answer is kept per request and shown when a send fails.

The JSON path bar

The path at the cursor, copy path, copy value. Bookmark a path so it survives a longer answer. Save a value as a variable. Add a check from the value in one click: equals this, exists, is this type. Inspect a JWT found in the body.

Spec drift

With an OpenAPI document attached, the Spec tab reads the real answer against it: a content type that differs, schema problems, fields the spec does not list, documented headers that did not come.

/ NETWORK

Proxies, certificates, cookies.

Set once on the Network page, honoured by every protocol Sonda speaks over TLS — HTTP, WebSocket, SSE, gRPC-Web, MQTT, Kafka, RabbitMQ, NATS, AMQP, Redis, FIX, HL7, STOMP, MCP.

Proxy

The system's, none, or a custom http or socks5 proxy with a bypass list.

Certificates

Extra CA files on top of the system store. Client certificates for mutual TLS per host pattern — an exact host or a domain suffix. HTTP/2 by default.

Cookie jar

Browser-like: host-only and domain cookies, paths, expiry, Secure. Kept per workspace, sealed with it. A Cookies pane to list, filter, add and clear; a per-request switch to leave the jar out.

cURL pasteCode generationJWT inspectorHTTP/2Mutual TLSSOCKS5Incognito10 MB answers
/ LOCKFLARE SONDA

Free forever up to 20 seats. Every line of this included.

All 74 protocols, listed →