Documentation
The sidecar runs on your machine. It is a local proxy on 127.0.0.1:9001. The console is http://127.0.0.1:9000. Only traffic you send through that proxy can be recorded or blocked.
1. Create an account
Sign up on the home page. The account page shows the setup key. With no seats, the sidecar answers 402 and refuses traffic. Seats are turned on after payment. One running sidecar is one seat, and it only accepts one local program at a time.
2. Download and start
macOS 12 or newer (Apple silicon or Intel), or Linux amd64 or arm64. Windows is not a download yet.
curl -fsSL https://terrtekk.com/install.sh | sh -s -- YOUR_ACCOUNT_KEY
Or download the binary for your machine from the account page, then:
chmod +x sidecar ./sidecar setup YOUR_ACCOUNT_KEY
That registers this computer. Open the console at http://127.0.0.1:9000/.
3. Send traffic through the sidecar
The proxy does not need a browser. In the console, Open test browser looks for Chrome, Chromium, Edge, or Brave. There is no specific version. If none is installed, the console prints a command you can run yourself, and anything else can use http://127.0.0.1:9001 as an HTTP proxy.
open -na "Google Chrome" --args \ --user-data-dir="$HOME/.filter-chrome" \ --proxy-server=http://127.0.0.1:9001 \ --proxy-bypass-list='<-loopback>' \ --ignore-certificate-errors-spki-list="$(./sidecar ca -spki)"
The SPKI hash trusts only this sidecar’s certificate. Print it with ./sidecar ca -spki.
Docker
On a Linux server or a pod, build the image from the sidecar repo. The container has no browser.
docker build -t filter . docker run -d --name filter \ -p 9001:9001 \ -v filter-data:/root/.traffic-sidecar \ -e ACCOUNT_KEY=YOUR_ACCOUNT_KEY \ filter
Point the process you want to filter at http://<host>:9001. Publish port 9000 only when you want the console.
4. Record, then allow or block
- In the console, click Start recording.
- Load the site in the proxied Chrome.
- Allow or Block the rows you care about. Prefer a path over blocking the whole host.
- Click Apply to browser, then reload that Chrome tab.
Rows are HTTP requests. Images painted inside the page as data:image/... never leave the browser, so they do not appear as rows and cannot be blocked on their own. To stop those, block the stylesheet or script that contains them.
5. If you already have a paid proxy
Point Chrome at the sidecar, and point the sidecar at your proxy:
./sidecar setup YOUR_ACCOUNT_KEY --upstream host:port:user:password
6. Analyze a recording
Record a browse first. The sidecar remembers which request set a cookie, which request sent it, which URL referred which, and which redirect led where. Cookie values are not stored.
In the console, click Connect Cursor or Connect Claude. Leave the sidecar running. Open a new chat and ask it to read the latest recording and block what that page does not need. It keeps the requests that result depends on.
Quit Claude and open it again after connecting. Reload the proxied Chrome to test the rules. Record again after updating the sidecar; older recordings do not have the dependency links.
Back