MITM proxy
Route IDE tools such as Antigravity, Kiro, and GitHub Copilot through DurinDoor with a local certificate and DNS redirect.
Some IDEs only talk to their vendor's own API host. The MITM proxy lets those IDEs use any provider or model in DurinDoor anyway. Open Dashboard → MITM Proxy (/dashboard/mitm); CLI Tools links to it.
MITM intercepts HTTPS traffic from IDE tools through a local certificate authority. It may break the tool's terms of service, and the vendor can restrict the account.
How it works
An IDE request takes this path:
- The IDE resolves its API host. DNS redirect points that host at
127.0.0.1, so the request reaches the local MITM server on port 443. - The MITM server presents a certificate signed by the DurinDoor root CA, which the OS trusts after setup, and reads the request.
- The request goes to DurinDoor with the base URL and API key set on the MITM card. The IDE's model name is swapped for the DurinDoor model you mapped to it.
- DurinDoor's response goes back to the IDE.
Prepare and enable interception
Before starting, close the IDE, test the target model directly through DurinDoor, and configure the MITM card's base URL and API key. You need administrator access for certificate trust, port 443, and hosts-file changes.
- Generate the certificate. Start the server once; it creates the root CA if it does not exist.
- Trust the certificate. Click Trust Cert. This adds the root CA to the system keychain or certificate store, so it needs your sudo password (UAC on Windows).
- Start the server. It listens on port 443. If another process holds 443, the card names the owner and asks before stopping it.
- Turn on DNS for a tool. Each tool card adds that tool's hosts to the hosts file as
127.0.0.1. - Map models. On the tool card, pick a DurinDoor model for each model name the IDE sends.
The card's Cert, Trusted, and Server indicators show which steps are done. On Windows, keep DurinDoor in standard-user mode; UAC is requested only for the system configuration steps.
Check the redirected hosts
| Tool | Hosts |
|---|---|
| Antigravity | daily-cloudcode-pa.googleapis.com, cloudcode-pa.googleapis.com |
| GitHub Copilot | api.individual.githubcopilot.com |
| Kiro | runtime.us-east-1.kiro.dev, q.us-east-1.amazonaws.com, codewhisperer.us-east-1.amazonaws.com |
For Antigravity the MITM proxy does not need an Antigravity provider connection; it only needs the models you map to. Provider-side details are on Antigravity.
Recovery steps for a stuck redirect, a lock error, or a missing root CA are on Troubleshooting.
Verify and remove interception
Reopen the selected IDE and send a short request. Confirm its mapped model and request in Dashboard → Usage. A green server indicator alone does not prove the IDE accepted the certificate or reached the mapped model.
To return the IDE to its vendor route, disable that tool's DNS redirect and stop the MITM server. Remove the DurinDoor CA from the OS trust store if you no longer use interception. Restart the IDE and verify normal vendor access. For a failed cleanup, use the linked troubleshooting procedure rather than deleting arbitrary hosts-file entries.