Hoppscotch

hoppscotch.iocontributed by Samuele Ongaro

YES

Replaceable in one session with an AI coding agent.

An API client that runs in a browser with no installation, covering REST, GraphQL and WebSockets, with a self-hosted option for teams.

Promptfree, for everyone, and the only version there is
Build me the API client workspace I actually need instead of a hosted Hoppscotch: collections and environments shared with a team, with control over who sees which secrets.

Read this first: Hoppscotch is open source and self-hosting it is a real answer — the fee buys a hosted instance and access control. Build this when the requirement is a team sharing collections without anyone's production credentials being in a file that syncs to everybody.

STACK
- Node 20+ with Fastify, server-rendered HTML with vanilla JS for the request pane
- SQLite through better-sqlite3, WAL mode
- Requests executed by the server, not by the browser — which sidesteps CORS entirely and is the main reason to have a server at all
- Caddy in front

THE DATA MODEL
- workspaces: id, name, slug; workspace_members: workspace_id, user_id, role
- collections: id, workspace_id, parent_id, name, position, auth_json, headers_json — auth and headers inherited by children
- requests: id, collection_id, name, method, url, headers_json, query_json, body_kind, body, auth_json, scripts_json, position
- environments: id, workspace_id, name, is_shared, variables_json, secrets_encrypted, visible_to_roles_json
- runs: id, request_id, environment_id, actor_id, status_code, duration_ms, request_snapshot_json, response_headers_json, response_body_path, response_bytes, error, at
- history kept per user, and shared runs kept per workspace
- tests: part of the request — assertions with their results per run

THE REQUEST
- Every method, arbitrary headers, query parameters as a table, path parameters
- Bodies: JSON with a formatter and a validator, form-encoded, multipart with file upload, raw text, binary, GraphQL with its own query and variables panes
- Authentication: none, basic, bearer, an API key in a header or a query, OAuth 2 with the client credentials and authorisation code flows, and the token stored where secrets go
- Inheritance from the parent collection, with the effective value shown so it is never a mystery which header is being sent
- The response: pretty-printed JSON with folding, headers, cookies, timings broken into DNS, connect, TLS and transfer, and the size. Save it, copy it, download it
- Generate a curl command from any request, and import one by pasting it

SECRETS, WHICH IS WHAT THE PAID TIER IS FOR
- Environment variables are of two kinds: plain, which everyone in the workspace sees, and secret, which is encrypted at rest and readable only by the roles allowed
- A secret's value is never sent to a browser that may not see it. The request runs on the server, where the value is resolved — so a developer can call the staging API without ever holding its key
- Secrets redacted from every stored run, every log and every shared response by key name and by value match
- An audit entry for every read of a secret and every change to one
- Personal environments that are never shared, for the credentials that belong to one person

RUNNING FROM THE SERVER
- The server makes the request, which removes CORS as a concern entirely
- Guard it: an allow-list or a block-list of destinations, and a hard refusal to call private address ranges unless explicitly permitted. A tool that fetches any URL an authenticated user types is a server-side request forgery machine, and it sits inside your network
- Timeouts, a response size cap, and a redirect limit
- Optionally through a local agent, so a developer can call something only their machine can reach — with the agent making the request and the workspace only holding the definition

SCRIPTS AND TESTS
- A pre-request script and a test script per request, in a sandbox with a time limit, no filesystem and no network of its own
- Set and read variables, and assert on status, headers, body and duration
- A collection run: every request in order, with variables carried between them, and a pass or fail summary
- Run a collection from the command line with an environment named, which makes it a smoke test in CI

SHARING
- Roles: admin, editor, viewer. A viewer can run a request but cannot see a secret or change a collection
- A shared link to one request or a whole collection, read-only, revocable
- Import and export in the common formats — OpenAPI, and the shapes the popular clients use — so nothing here is a one-way door

OPERATIONS
- .env: DATABASE_PATH, STORAGE_PATH, BASE_URL, ENCRYPTION_KEY, SESSION_SECRET, ALLOWED_DESTINATIONS
- Migrations on boot, each once
- Response bodies stored on disk with a retention policy and a sweeper
- Nightly backup off the machine, restore script
- Health endpoint

WHAT MATTERS MOST
Secret scoping and the outbound request guard. Build server-side execution with the private-address refusal first — it is the difference between a useful internal tool and a hole in your own network — and then make sure a viewer can run a request against production without ever being able to read the key that authorised it.

Give me the repository, migrations, .env.example, a seed workspace with two environments, the CLI runner, and a README with deploy steps behind Caddy and the network guard explained.

What you lose

  • A shared workspace with collections and environments synced across a team
  • A hosted instance kept updated
  • Access control on who can see which environment

If you would rather not build

  • Hurl or curl in a shell script

What it costs

as published on their pricing page

PlanBilled monthlyBilled yearlyLast read
—$19/mo——

Their pricing page is where these came from. Seeing a different price? Tell us.

The escape hatch

open source · no votes, no paid placement

Hoppscotch

$0

The product itself, self-hostable with Docker.

hoppscotch/hoppscotchfree · open source

Bruno

$0

Collections as plain files, versioned alongside the code.

usebruno/brunofree · open source

Why this verdict

our own opinion · changed only by a person

88/100

Verdict yes at 88. Self-hosting is a container, and moving collections into the repository is usually better than either option.

History

tracked since 10 Aug 2026 · nothing is ever overwritten

Interest · last 30 dayspeak 2/day
views01230 Aug4 Sept9 Sept14 Sept19 Sept24 Sept28 Sept
— views— prompt copies none yet— votes none yet

Questions about Hoppscotch

answered from the record above

Is Hoppscotch free?

No — the plan we track is $19 a month. Cloud team plans from around $19 per user per month; the software is free to self-host.

Can you replace Hoppscotch by building your own?

YES. Replaceable in one session with an AI coding agent. Replacement score 88 out of 100, build time one session. Read what you lose before you decide.

How much does Hoppscotch cost?

$19 a month on Team — $228 a year. Recorded 10 Aug 2026.

What do you lose by replacing Hoppscotch?

A shared workspace with collections and environments synced across a team; A hosted instance kept updated; Access control on who can see which environment. If any of those carry weight for you, keep paying.

Is there an open-source alternative to Hoppscotch?

Yes: Hoppscotch, Bruno. The prompt on this page is for when you want it your way instead.

Related entries

same category first, most replaced first

All 56 in Dev tools

Not sending yet

Every week, something stops being worth paying for.

New verdicts, prices that moved, entries added. One email a week. Unsubscribe in one click. Nothing is being sent yet — your address is kept here, and the first issue is the first thing it is used for.

free forever · no tracking pixel · stored here, never passed to anyone

Esc