Workbench Overview
The central desktop cockpit for crafting, inspecting, and automating multi-protocol requests.
The Workspace Layout
ForgeReq organizes your API development into three cohesive regions:
- Left Sidebar: The collection explorer, request stashes, realms (environments), mock servers, and certificate manager.
- Center Stage: Tabbed multi-protocol request editor with intuitive parameter builders, headers, body serialization, and auth handlers.
- Right / Bottom Inspector: High-performance response viewer with formatted syntax highlighting, timing waterfalls, and test assertions.
Protocol Switching
Switching protocols is as simple as toggling the method selector dropdown. Choose between standard HTTP verbs (GET, POST, PUT, DELETE, etc.), gRPC, KAFKA, SOAP, or MCP without switching apps or context.
Encrypted Vault & Passphrase Backup
Protect secrets, API tokens, and private keys using hardware-backed OS keychain storage.
Zero Cloud Storage
Traditional API clients store your credentials and tokens on remote cloud servers. ForgeReq encrypts all secrets using AES-256-GCM with keys managed by your OS Keychain (Keytar on macOS, Windows Credential Manager, or Secret Service API on Linux).
Passphrase-Protected Vault Exports
Need to migrate machines or share collection secrets securely with a teammate? ForgeReq lets you export a cryptographically sealed vault file:
- Key derivation using Argon2id / PBKDF2 with 600,000 iterations.
- Encrypted payload using authenticated AES-256-GCM.
- Zero plaintext leakage during export or import.
Stash & Realms
Organize variables, credentials, and endpoints across local, staging, and production environments.
Realms (Environment Management)
Realms provide isolated variable dictionaries. Use {{BASE_URL}}, {{AUTH_TOKEN}}, or {{CLIENT_ID}} anywhere in URLs, headers, payloads, and scripts. Switching realms instantly swaps all active values.
The Request Stash
Working on an exploratory query that doesn't belong in a permanent collection yet? Stash it in one click. Stashed requests remain accessible across sessions without polluting Git-tracked collection files.
gRPC & Protobuf
Native gRPC execution with server reflection, .proto file imports, and bidirectional streaming.
Connecting to gRPC Endpoints
ForgeReq eliminates the need for separate CLI tools like grpcurl. Simply enter the host:port and load your service definitions:
- Server Reflection: Click Reflect to automatically discover services, methods, and message schemas over the wire.
- Proto File Loader: Import individual
.protofiles or directory trees with automated import resolution. - TLS & mTLS: Enable secure connections with custom client certificates and root CA bundles.
{
"order_id": "{{GEN_UUID}}",
"customer_id": "cust_88291",
"items": [
{ "sku": "FR-PRO-KEY", "quantity": 1 }
],
"timestamp": 1773389021
}
Kafka Event Streaming
Produce and consume messages from Apache Kafka clusters directly inside your workbench.
Producer & Consumer in One Window
Test distributed event pipelines without writing boilerplate scripts:
- Produce: Send JSON, Avro, or String payloads to specific partitions with custom keys and headers.
- Consume: Listen to topic streams in real time with offset seeking, consumer group assignment, and pause/resume controls.
- Security: Full support for Plain, SSL, SASL/PLAIN, SASL/SCRAM-256, and SASL/SCRAM-512 authentication.
SOAP & WSDL
Full-featured XML client with automated WSDL parsing and request envelope generation.
Automated WSDL Discovery
Enter any WSDL URL or load a local XML definition file. ForgeReq parses all bindings, operations, and data types, generating pre-filled SOAP 1.1 or 1.2 request envelopes ready for invocation.
Model Context Protocol (MCP)
First-class desktop client for inspecting, testing, and debugging MCP servers.
Inspector-Grade MCP Capabilities
ForgeReq is a drop-in replacement for the official MCP Inspector, enhanced with variable substitution, vault secrets, and TLS rules:
- Transports: Streamable HTTP (current spec) and legacy Server-Sent Events (SSE).
- Tools: List tools, auto-generate dynamic JSON-Schema input forms, execute calls, and cancel long-running operations.
- Resources & Prompts: Browse and preview server resources and prompt templates.
- OAuth 2.1 & PKCE: Automatic discovery (RFC 9728 + 8414) and dynamic client registration with a single click.
- Test with LLM: Integrated agentic playground that connects an LLM directly to your server tools with step-by-step trace auditing.
BYOK AI Assistant with Privacy Guard
Generate payloads, diagnose errors, and write test assertions using your own API keys.
Supported Providers
- OpenAI: GPT-4o, GPT-4-turbo, o1, o3-mini.
- Anthropic: Claude 3.5 Sonnet, Claude 3.7 Sonnet.
- Google Gemini: Gemini 2.0 Flash, Gemini 1.5 Pro.
Client-Side Privacy Guard
ForgeReq automatically detects and redacts private API keys, bearer tokens, and passwords from payloads before sending queries to your chosen LLM provider, guaranteeing your secrets stay local.
Local Mock Servers
Zero-config offline mock servers for rapid frontend and integration development.
Instant Local API Simulation
Configure custom HTTP mock routes on localhost:
- Simulate HTTP status codes (200, 201, 400, 401, 404, 500).
- Custom latency delay sliders to test UI loading states and timeouts.
- Automatic CORS headers allowing browser apps to consume mocks seamlessly.
Load Testing & Benchmarks
Stress test APIs with high concurrency and detailed latency percentiles.
Real-Time Latency & Concurrency
Run multi-threaded benchmarks right from your desktop:
- Configure Virtual Users (VUs) and benchmark test duration.
- Live charts for Requests Per Second (RPS) and throughput.
- Precise statistical percentiles: p50, p90, p95, p99 latency breakdowns.
Request Chaining & Inheritance
Extract tokens from responses and propagate them automatically to downstream calls.
Hierarchical Settings
Folder-level headers, auth mechanisms (Bearer, Basic, OAuth 2.0), and variables cascade down into every child request automatically. Set your authorization once at the collection root and all nested requests inherit it seamlessly.
Assertion Rules Engine
Declarative testing rules for verifying responses without writing boilerplate code.
Built-in Assertions
- Status code equals
200/ in range2xx. - JSONPath property checks (e.g.
$.data.idis not null). - Response time is less than
200ms. - Header presence and regex matching.
Certificates & mTLS
Manage client certificates, private keys, and custom Root CAs for zero-trust architectures.
Mutual TLS Made Simple
Attach client .pem, .crt, and .key certificates scoped per host domain. ForgeReq handles mutual TLS handshakes transparently across HTTP, gRPC, and Kafka connections.
Library Runner
Run regression tests across your entire API library in automated batches.
Batch Test Execution
Queue dozens or hundreds of requests in sequence with parameterized iterations, delay intervals, and aggregate pass/fail reporting.