Skip to content

Interception Cockpit

The Cockpit is a communication workbench, not a dashboard, assessment wizard, or report presentation.

Start it with:

ait server start --listen 127.0.0.1:8790

The server prints a random local token. Signing in exchanges that token for an HttpOnly, SameSite=Strict cookie. The server and data-plane listeners bind to loopback unless the operator explicitly configures otherwise.

The one-screen workspace

At desktop sizes the screen has three persistent panes:

  • Connections: saved connections, running sessions, break conditions, and enabled live rules.
  • Messages: pending traffic and forwarded history with direction, operation, transport, route, and decision state.
  • Editor: the actual structured payload, optional raw bytes, exact changed pointers, receiving-agent response, and message decisions.

The header contains connection health, Start/Stop, Intercept on/off, and the pending count. Forward modified, Forward original, Drop, and Duplicate remain visible with the selected message. At widths below 1100 px the inspector can collapse without discarding selection; desktop operation is optimized for 1280×800 and larger.

The compact strip below the header derives one current next step from local session state: connect, enable interception, generate traffic, select, edit, or forward. It never performs the action automatically. How to use opens the six-step screen reference without leaving the workbench. See the Interception screen guide for the complete state and evidence reference.

Connect agents

Quick Connect uses a saved protocol/upstream pair and proposes a loopback listener. Discover inspects an Agent Card at an explicitly supplied origin. Manual exposes listener, upstream, TLS references, executable arguments, and bounds.

After start, the dialog and notice show the only required routing change: point the sending agent at AIT's listener. The receiving agent stays on its original endpoint.

Work with messages

Pending messages appear first. Selecting one never changes merely because a poll or resumable event update arrived. Structured JSON is the default editor; Raw is an explicit toggle. Invalid edits show a parse error while retaining the original message.

After delivery, History shows:

  • original and delivered content;
  • changed JSON pointers;
  • the operator decision and copy count;
  • protocol and lifecycle correlation;
  • the receiving-agent response when correlated.

Choose Apply to future on a successful manual edit to create an enabled, bounded live rule. Toggle it in the left pane. The rule applies automatically to later exact matches without reopening the editor.

Data loading

The primary Cockpit calls only connection and interception resources. Messages are paginated/bounded and detail remains local. It does not load findings, paths, or research APIs.

Select Advanced tools to deliberately enter the historical assessment and research workbench. The advanced=1 URL state is the boundary; without it, Advanced APIs are never requested.

Shutdown

A paused message waits unless the session was started with --pending-timeout and an explicit timeout action. Stop asks whether pending messages are forwarded unchanged or dropped before the listener and owned children stop. The dialog never chooses for the operator.

See Direct agent communication interception for the full workflow and Local API reference for automation.