Plunger
Unclog your API.
Your AI agent calls the API. Plunger shows you what it actually sent and what came back.
A tiny native API inspection tool for developers who just want to see what their pipeline is actually doing.
Make the request. See the JSON. Move on.
Get it from the Microsoft Store · Windows zip (about 3.6 MB, no installer, not code-signed) · Linux (command line and MCP server tested; the window is not yet) · MIT license
The real app: every request an agent sends appears in your window, tagged MCP, with secrets kept hidden. Setup and details.
Why?
Sometimes you don't need another platform. You just need to see what the API returned.
AI can write the code. AI can build the pipeline. We still look at the diff before we push. We still look at the logs when something feels wrong. And we still look at the JSON when an API doesn't do what we expected.
Seeing is believing. Plunger is for the moment between "I think it works" and "I can see it works."
We wanted a plunger. So we made one.
What is Plunger?
A small desktop app that sends an HTTP request and shows you what came back.
- Request: GET, POST, PUT, PATCH, DELETE, HEAD, OPTIONS. Params, headers and a Bearer token field.
- Body: JSON, form-urlencoded, raw text, or multipart form-data with real file uploads.
- Response: status, time and size, the headers, and the body as a collapsible JSON tree. Copy it or save it to a file.
- Variables:
{{name}}anywhere in the request, plus{{$uuid}},{{$timestamp}},{{$randomInt}}and{{$env:NAME}}for reading an OS environment variable at send time. A request with an undefined variable is refused, never sent with the placeholder in it. - Import and export: paste a curl command (bash or Windows cmd, including
-Fuploads) or a PowerShellInvoke-WebRequest/Invoke-RestMethodcommand, such as DevTools' Copy as cURL or Copy as PowerShell; or open a HAR file. Copy any request back out as curl (bash), curl (Windows cmd) or PowerShell with Ctrl+Shift+C or File > Export request, shown with syntax highlighting. - Keep what matters: local history, named saved requests (Ctrl+S) and tabs (Ctrl+T).
- Local HTTPS: skip certificate checks for a self-signed dev server, with a warning that stays visible while it's on.
- Behind a proxy: Plunger uses your system proxy settings and the
HTTP_PROXY,HTTPS_PROXYandNO_PROXYenvironment variables. - Find it again: the sidebar filter searches your whole history and saved requests by URL, method, name or status; right-click a value in a JSON response to copy its path or value.
It's a native program, not a web page, so it reaches whatever your machine can reach: localhost, a dev box on your network, an API that sends no CORS headers.
For AI agents
See the JSON, even when an AI sent the request.
Plunger is built to be driven safely by AI agents, not just clicked by people. The same plunger.exe is also a command-line API client and an MCP server, so an agent like Claude Code sends requests through Plunger's engine instead of running curl. No account, no cloud, no telemetry: now safe for your agents too.
One exe. Human GUI, agent CLI, agent MCP. The same safety guarantees in every mode.
{
"mcpServers": {
"plunger": { "command": "C:\\Tools\\plunger\\plunger.exe", "args": ["mcp"] }
}
}
Real Claude Code, using Plunger over MCP, unedited. See docs/agents.md for the setup and a look at the raw protocol traffic.
Run plunger install (or File > Set up AI agents... in the window) to register the MCP server in Claude Code, Cursor, Kiro, Codex, Windsurf, VS Code or Gemini CLI and write the always-on steering that tells the agent to use Plunger instead of curl. See docs/agents.md.
Why not just let the agent run curl?
- Undefined-variable safety. Plunger refuses to send a request with an undefined
{{variable}}. curl will happily send the placeholder text. - Credential isolation. The agent writes
{{token}}and never sees the value. Secrets you've chosen to remember are kept in Windows Credential Manager and filled in by Plunger; if a server echoes one back, it comes back as[redacted:token]. - Shared human and agent history. You testing in the window and an agent testing from the command line read and write the same saved requests and history.
- Structured, typed output. Status, timing, size, headers and the parsed JSON body come back as separate fields, not text the agent has to pick apart.
- A local audit trail. Every agent request lands in the history you see in the window, tagged
MCPorCLI, as it happens. curl leaves no record unless you build the logging yourself.
Tools: send_request, import_curl, list_saved_requests, get_history, list_variables, export_curl. From a terminal: plunger send "Saved request name", plunger send --url ..., plunger history. Setup, every tool and option, exit codes and the fine print are in docs/agents.md.
Small by design
Built in Rust with egui because we wanted a small, fast, native application. No webview, no bundled browser: one exe of about 7 MB, which is also a command-line client and an MCP server for AI agents.
No account to create. No cloud to sync to. The only network traffic is the requests that get sent, by you or by an agent you've connected: no analytics, no telemetry, no update checks. History and saved requests live in one local folder, %APPDATA%\Plunger\data. Bearer tokens and secret variables are never written to a file unless you tick "remember", which keeps them in Windows Credential Manager. Credential-looking headers are blanked before history is saved. Details are in the privacy policy.
Open source
Plunger is MIT licensed. Read it, build it, change it.
A few promises, so you know what you're picking up:
- It will never require an account.
- It will never add telemetry.
- Existing features will never move behind a paywall.
Screenshots
Request, response, JSON. Saved requests and history on the left. |
Multipart uploads with real files. |
Variables, with secrets masked and kept off disk. |
Undefined variables stop the request instead of leaking a placeholder. |
Paste a curl command; it becomes a request. |
Local HTTPS with self-signed certificates. |
Light theme too. |
|
Install
Microsoft Store (signed by Microsoft, no warning, updates itself; it can trail the newest release by a few days): get it here, or
winget install 9P7WRKLN6WHR --source msstore
Scoop:
scoop bucket add metamug https://github.com/metamug/scoop-bucket
scoop install plunger
pip / uv (Windows, Linux, macOS), from 0.5.1:
pip install plunger-cli # puts a `plunger` command on your PATH
pipx install plunger-cli # same, in its own environment (use this if pip says "externally-managed-environment")
uvx plunger-cli mcp # or run the MCP server without installing anything
Zip:
- Download
plunger-windows.zipand unzip it anywhere. - Run
plunger.exe.
Windows 10 or 11, 64-bit. The zip isn't code-signed yet, so Windows may say "Windows protected your PC": click More info, then Run anyway. Or build it yourself.
To update the zip, replace the exe. To remove it, delete the exe and %APPDATA%\Plunger.
Usage
- Paste a URL, or import a curl command.
- Press Ctrl+Enter. While a request is in flight, press Escape to cancel waiting for it.
- Read the response.
Press Ctrl+L to focus the URL field and select its contents.
Press Ctrl+F to search the response body: Enter and Shift+Enter (or Next / Prev) step through the matches, Esc closes the box.
With multiple request tabs, Ctrl+Tab moves to the next tab and Ctrl+Shift+Tab moves to the previous one. Cycling wraps at either end.
Build from source
rustup toolchain install stable-x86_64-pc-windows-gnu
rustup default stable-x86_64-pc-windows-gnu
# plus mingw-w64 (gcc, windres, dlltool) on PATH, e.g. from WinLibs or MSYS2
cargo build --release # target/release/plunger.exe
cargo test
Set PLUNGER_DATA_DIR to run against a throwaway data folder instead of your real history.
Contributing
Issues and pull requests are welcome. Before adding a feature, ask: does this help someone quickly see what an API is doing? Would someone open Plunger specifically for it? If yes, it probably belongs. Accounts, sync, collaboration and platform features don't.
- CONTRIBUTING.md: what fits, how to build, how to send a change.
- design.md: how it's built and why.
- SECURITY.md: how to report a vulnerability privately.
- CODE_OF_CONDUCT.md and the CHANGELOG.
Run cargo test and cargo clippy --all-targets before sending a PR. Maintainers: releases are GitHub releases with plunger-windows.zip attached (push a v* tag).
We didn't want another ecosystem. We wanted a plunger.
Unclog your API.
Metadata
Release files for plunger-cli 0.5.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| plunger_cli-0.5.2.tar.gz | 3.1 MB | Details |
Built distributions (wheels)
| File | Reset | |||
|---|---|---|---|---|
| plunger_cli-0.5.2-py3-none-win_amd64.whl | Python 3 | none | Windows x86-64 | Details |
| plunger_cli-0.5.2-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl | Python 3 | none | Linux glibc 2.17+ x86-64 | Details |
| plunger_cli-0.5.2-py3-none-macosx_11_0_arm64.whl | Python 3 | none | macOS 11.0+ ARM64 | Details |
| plunger_cli-0.5.2-py3-none-macosx_10_12_x86_64.whl | Python 3 | none | macOS 10.12+ x86-64 | Details |
Total release size: 19.4 MB
Release files / plunger_cli-0.5.2.tar.gz
| Download URL | plunger_cli-0.5.2.tar.gz |
|---|---|
| Size | 3.1 MB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
bb8e663447ffc715ec49b26b49e7196582b0ef078a7254dbbd606b16e5b840fb
|
|
BLAKE2b-256 checksum How to use checksums |
fb7f0529fdb3a16f0f4c29378b2122912da7118ad15318017b45eb3f6f61637a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 9, 2026.
Transparency logRelease files / plunger_cli-0.5.2-py3-none-win_amd64.whl
| Download URL | plunger_cli-0.5.2-py3-none-win_amd64.whl |
|---|---|
| Size | 3.9 MB |
| Tags | Python 3 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
567c5cb8dc2796dea07afe06f27272d82cf1bf182d6674304a8d2b160319bbb2
|
|
BLAKE2b-256 checksum How to use checksums |
ab3c16bb15e771014daae156071961bb138ef03cf0947170fba22bbebdcd14ac
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 9, 2026.
Transparency logRelease files / plunger_cli-0.5.2-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
| Download URL | plunger_cli-0.5.2-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
|---|---|
| Size | 5.0 MB |
| Tags | Linux glibc 2.17+ x86-64 Python 3 |
|
SHA-256 checksum How to use checksums |
26c7037c3d565027f37bb4c8be593295cff7273a483a745e0c9e7a5815f05770
|
|
BLAKE2b-256 checksum How to use checksums |
1a90871f68d3046edb6d92b9356b43b661e972fab236e754ed32541f51845b11
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 9, 2026.
Transparency logRelease files / plunger_cli-0.5.2-py3-none-macosx_11_0_arm64.whl
| Download URL | plunger_cli-0.5.2-py3-none-macosx_11_0_arm64.whl |
|---|---|
| Size | 3.7 MB |
| Tags | Python 3 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
dcf042f1145445770296f9010fb0b15e0ef271fec539e80bc5656c56d063cbf6
|
|
BLAKE2b-256 checksum How to use checksums |
a5c918108bf51710316edfada55c8f82e5d8aabdba26e5791d2e73e5bae7b3ad
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 9, 2026.
Transparency logRelease files / plunger_cli-0.5.2-py3-none-macosx_10_12_x86_64.whl
| Download URL | plunger_cli-0.5.2-py3-none-macosx_10_12_x86_64.whl |
|---|---|
| Size | 3.8 MB |
| Tags | Python 3 macOS 10.12+ x86-64 |
|
SHA-256 checksum How to use checksums |
7e0262edf3c96164efec76594bb7e135f796f785af7542dda4f8de3abcac4325
|
|
BLAKE2b-256 checksum How to use checksums |
79bae0cc644cb58ba3de20ebfddc074229df8fa04d3504b32e801effd2598e49
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 9, 2026.
Transparency log