GETTING STARTED

Workbench Overview

The central desktop cockpit for crafting, inspecting, and automating multi-protocol requests.

ForgeReq Workbench UI

The Workspace Layout

ForgeReq organizes your API development into three cohesive regions:

  • Left Sidebar: The collection explorer, request stashes, realms (environments), mock servers, and certificate manager.
  • Center Stage: Tabbed multi-protocol request editor with intuitive parameter builders, headers, body serialization, and auth handlers.
  • Right / Bottom Inspector: High-performance response viewer with formatted syntax highlighting, timing waterfalls, and test assertions.
Local-First Guarantee: Everything you save is stored locally on your disk in encrypted or JSON format. No requests, secrets, or payloads leave your machine unless explicitly sent to your target server.

Protocol Switching

Switching protocols is as simple as toggling the method selector dropdown. Choose between standard HTTP verbs (GET, POST, PUT, DELETE, etc.), gRPC, KAFKA, SOAP, or MCP without switching apps or context.

SECURITY

Encrypted Vault & Passphrase Backup

Protect secrets, API tokens, and private keys using hardware-backed OS keychain storage.

ForgeReq Vault Backup

Zero Cloud Storage

Traditional API clients store your credentials and tokens on remote cloud servers. ForgeReq encrypts all secrets using AES-256-GCM with keys managed by your OS Keychain (Keytar on macOS, Windows Credential Manager, or Secret Service API on Linux).

Passphrase-Protected Vault Exports

Need to migrate machines or share collection secrets securely with a teammate? ForgeReq lets you export a cryptographically sealed vault file:

  • Key derivation using Argon2id / PBKDF2 with 600,000 iterations.
  • Encrypted payload using authenticated AES-256-GCM.
  • Zero plaintext leakage during export or import.
ENVIRONMENTS

Stash & Realms

Organize variables, credentials, and endpoints across local, staging, and production environments.

Stash and Realms

Realms (Environment Management)

Realms provide isolated variable dictionaries. Use {{BASE_URL}}, {{AUTH_TOKEN}}, or {{CLIENT_ID}} anywhere in URLs, headers, payloads, and scripts. Switching realms instantly swaps all active values.

The Request Stash

Working on an exploratory query that doesn't belong in a permanent collection yet? Stash it in one click. Stashed requests remain accessible across sessions without polluting Git-tracked collection files.

PROTOCOLS

gRPC & Protobuf

Native gRPC execution with server reflection, .proto file imports, and bidirectional streaming.

gRPC Interface

Connecting to gRPC Endpoints

ForgeReq eliminates the need for separate CLI tools like grpcurl. Simply enter the host:port and load your service definitions:

  • Server Reflection: Click Reflect to automatically discover services, methods, and message schemas over the wire.
  • Proto File Loader: Import individual .proto files or directory trees with automated import resolution.
  • TLS & mTLS: Enable secure connections with custom client certificates and root CA bundles.
Sample gRPC Order Payload
{
  "order_id": "{{GEN_UUID}}",
  "customer_id": "cust_88291",
  "items": [
    { "sku": "FR-PRO-KEY", "quantity": 1 }
  ],
  "timestamp": 1773389021
}
PROTOCOLS

Kafka Event Streaming

Produce and consume messages from Apache Kafka clusters directly inside your workbench.

Kafka Interface

Producer & Consumer in One Window

Test distributed event pipelines without writing boilerplate scripts:

  • Produce: Send JSON, Avro, or String payloads to specific partitions with custom keys and headers.
  • Consume: Listen to topic streams in real time with offset seeking, consumer group assignment, and pause/resume controls.
  • Security: Full support for Plain, SSL, SASL/PLAIN, SASL/SCRAM-256, and SASL/SCRAM-512 authentication.
PROTOCOLS

SOAP & WSDL

Full-featured XML client with automated WSDL parsing and request envelope generation.

SOAP Interface

Automated WSDL Discovery

Enter any WSDL URL or load a local XML definition file. ForgeReq parses all bindings, operations, and data types, generating pre-filled SOAP 1.1 or 1.2 request envelopes ready for invocation.

PROTOCOLS

Model Context Protocol (MCP)

First-class desktop client for inspecting, testing, and debugging MCP servers.

MCP Workspace

Inspector-Grade MCP Capabilities

ForgeReq is a drop-in replacement for the official MCP Inspector, enhanced with variable substitution, vault secrets, and TLS rules:

  • Transports: Streamable HTTP (current spec) and legacy Server-Sent Events (SSE).
  • Tools: List tools, auto-generate dynamic JSON-Schema input forms, execute calls, and cancel long-running operations.
  • Resources & Prompts: Browse and preview server resources and prompt templates.
  • OAuth 2.1 & PKCE: Automatic discovery (RFC 9728 + 8414) and dynamic client registration with a single click.
  • Test with LLM: Integrated agentic playground that connects an LLM directly to your server tools with step-by-step trace auditing.
INTELLIGENCE

BYOK AI Assistant with Privacy Guard

Generate payloads, diagnose errors, and write test assertions using your own API keys.

AI Assistant

Supported Providers

  • OpenAI: GPT-4o, GPT-4-turbo, o1, o3-mini.
  • Anthropic: Claude 3.5 Sonnet, Claude 3.7 Sonnet.
  • Google Gemini: Gemini 2.0 Flash, Gemini 1.5 Pro.

Client-Side Privacy Guard

ForgeReq automatically detects and redacts private API keys, bearer tokens, and passwords from payloads before sending queries to your chosen LLM provider, guaranteeing your secrets stay local.

TESTING

Local Mock Servers

Zero-config offline mock servers for rapid frontend and integration development.

Mock Servers

Instant Local API Simulation

Configure custom HTTP mock routes on localhost:

  • Simulate HTTP status codes (200, 201, 400, 401, 404, 500).
  • Custom latency delay sliders to test UI loading states and timeouts.
  • Automatic CORS headers allowing browser apps to consume mocks seamlessly.
PERFORMANCE

Load Testing & Benchmarks

Stress test APIs with high concurrency and detailed latency percentiles.

Load Testing

Real-Time Latency & Concurrency

Run multi-threaded benchmarks right from your desktop:

  • Configure Virtual Users (VUs) and benchmark test duration.
  • Live charts for Requests Per Second (RPS) and throughput.
  • Precise statistical percentiles: p50, p90, p95, p99 latency breakdowns.
AUTOMATION

Request Chaining & Inheritance

Extract tokens from responses and propagate them automatically to downstream calls.

Chaining and Inheritance

Hierarchical Settings

Folder-level headers, auth mechanisms (Bearer, Basic, OAuth 2.0), and variables cascade down into every child request automatically. Set your authorization once at the collection root and all nested requests inherit it seamlessly.

TESTING

Assertion Rules Engine

Declarative testing rules for verifying responses without writing boilerplate code.

Rules Engine

Built-in Assertions

  • Status code equals 200 / in range 2xx.
  • JSONPath property checks (e.g. $.data.id is not null).
  • Response time is less than 200ms.
  • Header presence and regex matching.
SECURITY

Certificates & mTLS

Manage client certificates, private keys, and custom Root CAs for zero-trust architectures.

Certificates

Mutual TLS Made Simple

Attach client .pem, .crt, and .key certificates scoped per host domain. ForgeReq handles mutual TLS handshakes transparently across HTTP, gRPC, and Kafka connections.

AUTOMATION

Library Runner

Run regression tests across your entire API library in automated batches.

Library Runner

Batch Test Execution

Queue dozens or hundreds of requests in sequence with parameterized iterations, delay intervals, and aggregate pass/fail reporting.