AI agents (MCP)¶
Quena can run a Model Context Protocol server, so an AI agent such as Claude Code can read the capture and, if you allow it, control Quena. The agent can look at failing requests, set mock rules and breakpoints, send requests and replay them.
Turn it on¶
- Open Options → AI agents (MCP) and check Enable MCP server. Quena creates a random token the first time.
- Choose what agents may do:
- …only read sessions, rules and statistics (the default). Agents can list, search and read sessions and bodies, and see rules and breakpoints.
- …also change rules and breakpoints, capture and send requests. Quena checks this on every call; without it the changing tools say Needs full control and refuse, so granting it later works without reconnecting the agent.
- Click OK. The tab then shows Running at http://127.0.0.1:8867/mcp.
-
Copy the Claude Code line and run it in a terminal:
claude mcp add --transport http quena http://127.0.0.1:8867/mcp \ --header "Authorization: Bearer <token>"Other MCP clients need the same three things: the URL, the transport Streamable HTTP and the
Authorizationheader.
The settings of the tab:
| Setting | Default | Meaning |
|---|---|---|
| Enable MCP server | off | listen on 127.0.0.1 while Quena runs |
| Port | 8867 | the server's port; another program on it makes the start fail (Quena says so after OK) |
| Agents may | only read | read only, or full control (see above) |
| Show credentials and tokens to agents unredacted (unsafe) | off | see What agents see and touch |
| Folder for agent files | empty (mcp-files in the data folder) |
the only folder agents read files from and write files to |
| Token | generated | Copy, or New token to lock out every client that has the old one |
To stop all agents at once, uncheck Enable MCP server.
Check the connection¶
curl -s http://127.0.0.1:8867/mcp -H "Authorization: Bearer <token>" \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"status","arguments":{}}}'
401 means a wrong or missing token, 403 a Host or Origin that is not
127.0.0.1/localhost, connection refused that the server is off or on another port.
What agents see and touch¶
- Secrets are replaced. An agent sends what it reads to its model provider. Unless
Show credentials and tokens to agents unredacted is checked, Quena replaces
AuthorizationandCookievalues, token and API-key headers, secret URL parameters and secret body fields (password,access_token, JWTs …) in everything it hands out — rows, headers, bodies, previews, and also in the files it writes for agents (exports,.httpcollections; no private environment file). Quena itself still sends and records the real values. E-mail addresses and other personal data are not replaced; use sanitized export when that matters. - One folder for files. Exports,
.httpcollections (and their body files) and files served by mock rules created by agents must lie in Folder for agent files (empty:mcp-filesin the data folder;statusnames it). Relative paths are taken from there.{{$processEnv}}is not available to agents. - Captured traffic is foreign content. A response can contain text written to mislead an agent. With full control an agent can send requests (also into a VPN), change rules and write files in its folder. Grant full control for a task you watch, and switch it off again.
- Searching (
search_sessions) runs as its own job and never cancels your Find Sessions.
The server only listens on 127.0.0.1. It rejects requests without the token, and requests
whose Host or Origin is not a loopback name (that blocks web pages using DNS
rebinding). New token makes the old token useless once you click OK. The server runs
apart from the proxy, so agent calls never slow down forwarding.
Tools¶
| Tool | Needs full control | What it does |
|---|---|---|
status |
capture state, listen address, upstream, number of sessions, breakpoints | |
list_sessions |
compact rows; filter (see syntax), since_id, paging |
|
get_session |
request and response heads, timers, bodies as text (decoded, cut at 16 KB by default) | |
get_body |
a piece of a body: offset, length, decoded or raw |
|
search_sessions |
text or regex in URLs, headers, bodies | |
statistics |
bytes, status codes, content types, hosts | |
list_mock_rules, get_breakpoints |
rules with hit counts; breakpoints and paused sessions | |
list_rewrite_rules |
rewrite rules with hit counts | |
preview_rewrite |
apply a rewrite rule to a captured body without sending anything | |
set_capture |
✓ | start or stop capturing |
clear_sessions |
✓ | remove sessions matching a filter, or all |
send_request |
✓ | send a request through Quena and return the session |
replay_sessions |
✓ | send captured requests again |
add_mock_rule, update_mock_rule, remove_mock_rule, set_mock_options |
✓ | Mock Rules |
mock_from_sessions |
✓ | rules that answer with recorded responses |
add_rewrite_rule, update_rewrite_rule, remove_rewrite_rule, set_rewrite_options |
✓ | change real requests and responses (JSONPath, regex, headers, status) |
set_breakpoints, resume_session, resume_all |
✓ | breakpoints |
list_http_requests |
the requests of a .http file, resolved for an environment |
|
run_http_file |
✓ | send a .http collection (or some of its requests) through Quena |
sessions_to_http_file |
✓ | write captured sessions as a .http file with environment files |
export_archive |
✓ | save sessions as .har or .saz in the agents' folder (existing files only with overwrite) |
Lists return at most 200 rows and bodies at most 1 MB per call (reading from up to 8 MB into
a body), so an agent never pulls a whole capture at once. A tool error comes back as a result with isError, so the agent sees
the message, for example a filter syntax error.
Examples for an agent¶
- "Which requests to
api.example.comfailed in the last minutes? Show me the response of the first one." - "Answer
GET https://api.example.com/v1/configwith a 503 and check how the app behaves." - "Pause every POST to
/ordersand show me the body before it goes out." - "Append a broken element to every list in the responses of
/api/and tell me which requests the app sends afterwards."