feldstecher
Observe and record the behaviour of black-box systems through their HTTP API - without holding their credentials.
A Feldstecher is a pair of binoculars: you use it to watch something closely without disturbing it, and without getting close enough to be bitten. This one is meant to sit between you and an API you do not control - injecting credentials you never see, refusing to talk to any host you did not allowlist, scrubbing and recording every exchange, and tagging the test data you create so you can always tell your own tracks from the wild population.
Why
Sometimes the only documentation of an API is the API itself. Working it out means sending real requests to a real system, which raises three problems that the usual recording proxies do not solve:
- The credentials must not leak to whoever is driving the requests. That is especially true when the driver is an AI agent, but it is just as true for a shared debugging session or a CI job.
- The recordings are the deliverable, not a debug artifact. They need full bodies, query strings and timing, in a form you can reprocess offline months later.
- Writes to somebody else's system are permanent. Test data created while exploring stays there. You need it to be unique, recognisable, and written down.
feldstecher is built as a mitmproxy addon, so the proxying, TLS interception and flow persistence are handled by a mature and well-maintained tool, and feldstecher only adds the parts specific to careful observation.
What it is not
- Not a general-purpose secrets manager. It brokers credentials for observation sessions, nothing more.
- Not a mock server. It records what a system does; replaying that is a separate concern.
- Not a security boundary against a hostile process on the same machine. If the driver of the requests runs as the same user on the same host, it can read feldstecher's configuration. Isolation between the two is your job.
Development
This project uses uv and a src layout.
uv sync --group dev
uv run pytest unittests
Contributions are welcome via pull request against main.
Releases
Publishing to PyPI runs from .github/workflows/python-publish.yml on a GitHub release, using a
trusted publisher rather than a token. It needs a repository
environment named release, and the publisher registered on the PyPI side must name this repository and
this workflow file.
Metadata
Release files for feldstecher 0.1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| feldstecher-0.1.1.tar.gz | 74.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| feldstecher-0.1.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 82.1 kB
Release files / feldstecher-0.1.1.tar.gz
| Download URL | feldstecher-0.1.1.tar.gz |
|---|---|
| Size | 74.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
35806320094d33b89fe490d083b25bd279533426c2cbdb2697e14e3d1b6dcd24
|
|
BLAKE2b-256 checksum How to use checksums |
b3e8703e7fd36d8d6434f56a2a43edff2e75651fe7e03d6720948c31378e4022
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 21, 2026.
Transparency logRelease files / feldstecher-0.1.1-py3-none-any.whl
| Download URL | feldstecher-0.1.1-py3-none-any.whl |
|---|---|
| Size | 7.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
55d4d37c486ec2eb14cfde5a7350ae77af19ae5c288e34e414c7636878303fa9
|
|
BLAKE2b-256 checksum How to use checksums |
431d96df7d504e9494bd790ae3e440b7cecdc3608d3aed1b6804a7d06915b195
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 21, 2026.
Transparency log