An API client for REST, GraphQL and gRPC with a design tab for OpenAPI specifications, plus cloud sync of your collections across machines.
Build me the API client I actually need instead of paying for Insomnia: REST, GraphQL and gRPC in one place, with collections that live in my repository. Read this first: the fee buys cloud sync and team sharing. The better answer for a developer's collections is usually git — the requests live next to the code they exercise, they branch with it, and they are reviewed like anything else. That is the design here. STACK - Node 20+ with Fastify for a local server, and a small web interface — or a desktop shell if you want it in the dock - SQLite through better-sqlite3 for history and responses only. The collections themselves are files - Requests executed by the local process, which removes CORS entirely - Caddy in front only if it is shared COLLECTIONS AS FILES - One YAML or JSON file per request, in a directory tree that mirrors the API, committed to the repository - A human-readable format that diffs sensibly: a changed header is a one-line diff, not a re-serialised blob - Environments as files too, with secrets referenced by name and resolved from the OS key store or from a secrets manager — never written into the file - This is the whole design decision. Collections in a proprietary cloud are collections that go stale; collections beside the code are updated in the same pull request that changes the endpoint REST - Every method, headers, query parameters, path parameters, cookies - Bodies: JSON with formatting and validation, form-encoded, multipart with files, raw, binary - Authentication: basic, bearer, API key, digest, OAuth 1 and 2 with the common flows, AWS signature, mutual TLS - Inheritance from a folder, with the effective request shown before sending so nothing is mysterious - Response: pretty JSON with folding and a filter expression, headers, cookies, timings split into DNS, connect, TLS and transfer, and size - Save a response, compare two responses, and copy any request as curl GRAPHQL - Schema fetched by introspection and cached, with autocompletion and validation against it - A separate variables pane, and query and mutation both first-class - Subscriptions over WebSocket, with the stream displayed as it arrives - The schema diffed against the last fetch, so a breaking change is visible GRPC - Load a .proto file or use server reflection - Unary, server streaming, client streaming and bidirectional, all four, with the stream visible in both directions - Message composed as JSON and encoded from the descriptor, with the response decoded back - Metadata in and out, and deadlines set explicitly - This is the part few alternatives cover, and it is the reason to build rather than to switch WEBSOCKETS AND SERVER-SENT EVENTS - Connect, send frames, watch the log with timestamps - Reconnect, ping and pong, and a close code shown plainly DESIGN AND LINTING - An OpenAPI document opened in a design view: paths, operations, schemas, with validation as you type - Linting against a rule set kept in the repository — naming, required descriptions, response codes, security schemes - Requests generated from the specification, so the client and the contract agree - The lint runs in CI from the command line, which is where it actually enforces anything SCRIPTS AND TESTS - Pre-request and post-response scripts in a sandbox with a time limit, no filesystem and no ambient network - Assertions on status, headers, body and duration - A folder run: every request in order with variables carried between them, and a summary - The same run from the command line with an environment named, so it becomes a CI smoke test HISTORY - Every send recorded locally with the request as it was actually sent, secrets redacted, and the response body on disk with a retention policy - Searchable, and a response re-openable weeks later - Never synced anywhere by default SECURITY - Secrets resolved at send time from the key store or a secrets manager, and never written to a collection file, a history row or a log - Redaction by value match everywhere - If a shared instance is run, guard outbound requests: refuse private address ranges unless explicitly allowed, or the tool becomes a request forgery machine inside your network OPERATIONS - .env: DATABASE_PATH, COLLECTIONS_PATH, SESSION_SECRET - Migrations on boot, each once - Import from the common formats — OpenAPI, HAR, curl, and the exports of the popular clients — and export back - Health endpoint if it is served WHAT MATTERS MOST Files in the repository and the command-line runner. Build the file format and the runner first, put a folder of requests next to a real API, and run them in CI. That combination is what turns a request collection from a personal scratchpad into something the whole team can rely on — and it is what a cloud sync fee never gives you. Give me the repository, the CLI runner, the file format documented, importers, and a README with the design decision explained.
What you lose
- gRPC and WebSocket support in the same client as REST, which few alternatives cover
- Cloud sync and team sharing of collections
- An OpenAPI design view with linting against your own rules
If you would rather not build
- Hoppscotch, self-hosted
What it costs
read from their page 15 Aug 2026
| Plan | Billed monthly | Billed yearly | Last read |
|---|---|---|---|
| — | $12/mo | — | 15 Aug 2026 |
Their pricing page is where these came from. Seeing a different price? Tell us.
The escape hatch
open source · no votes, no paid placement
Why this verdict
our own opinion · changed only by a person
78/100
Verdict yes at 78. A linted OpenAPI file in CI does more for an API than any client, and it removes the reason to sync collections at all.
History
tracked since 10 Aug 2026 · nothing is ever overwritten
Questions about Insomnia
answered from the record above
Is Insomnia free?
No — the plan we track is $12 a month. Individual at around $12 per user per month billed monthly, cheaper annually; a free tier exists.
Can you replace Insomnia by building your own?
YES. Replaceable in one session with an AI coding agent. Replacement score 78 out of 100, build time one session. Read what you lose before you decide.
How much does Insomnia cost?
$12 a month on Individual — $144 a year. Recorded 10 Aug 2026.
What do you lose by replacing Insomnia?
gRPC and WebSocket support in the same client as REST, which few alternatives cover; Cloud sync and team sharing of collections; An OpenAPI design view with linting against your own rules. If any of those carry weight for you, keep paying.
Is there an open-source alternative to Insomnia?
Yes: Bruno, Spectral. The prompt on this page is for when you want it your way instead.
Related entries
same category first, most replaced first
Every week, something stops being worth paying for.
New verdicts, prices that moved, entries added. One email a week. Unsubscribe in one click. Nothing is being sent yet — your address is kept here, and the first issue is the first thing it is used for.
free forever · no tracking pixel · stored here, never passed to anyone

