New Flows: chain requests into one-click chores

Of CORS it works.

A fast, local-first API client for REST, gRPC, GraphQL, SSE and MCP. No account, no cloud lock-in, no bloat. Just a native app that gets out of your way.

Free · macOS, Windows & Linux · Built in Rust · Early access

Ofcors showing a gRPC UpdatePayment request: a form generated from the proto with a FieldMask picker, and a response warning that the server sent fields the local protos don't define. Protos synced from gitPrivate repos, your SSH keys FieldMask, Tab to completePaths straight from the schema Schema drift, caughtWhen the server knows fields you don't

The API client you don't have to fight.

No login wall

Open it and send a request. Your workspace is a file on your disk, it works offline, and nothing is uploaded unless you choose to share it.

Secrets stay in your keychain

Secret variables live in the macOS Keychain, Windows Credential Manager or Secret Service. Never in workspace files, never in exports, never in AI prompts.

Native, not a browser tab

Requests go out from a Rust core, so there's no CORS to fight. localhost just works, the app opens instantly, and it's light on memory.

REST

The everyday stuff, done properly.

Most of your day is plain HTTP, so that's where Ofcors is sharpest. Paste a cURL command into the URL bar and it's a request. Flip between local, staging and production with one click.

  • Every method. Query params and the URL stay in sync, and headers and params bulk-edit as plain text.
  • JSON, text, form and multipart bodies, in an editor that formats and folds.
  • Bearer, Basic and API-key auth, with tokens that refresh themselves.
  • Pretty or raw responses with status, timing and size at a glance. Any header or value is a right-click from your clipboard.
  • Collections, environments and a call log of every response, ready to reopen or replay.
A GET request to list charges with query params in a table and a pretty-printed JSON response showing 200 OK in 42 ms.

Flows

Turn the chores into one click.

Creating a sandbox account, seeding test data, walking an order through to "shipped": chain the requests once as a flow, then run it whenever you need it.

  • Save a value from one response, like {{merchantId}}, and use it in the next request. Mix REST, GraphQL and gRPC steps in one flow.
  • Checks on status, headers and body stop the flow at the first problem and tell you exactly what went wrong.
  • Inputs with random defaults, repeats for seeding data, and a summary to copy at the end.
  • Re-run a single step with the values from the last run. SSE steps wait for the event you name.
A flow called Sandbox merchant after a run: a Done banner with the summary, the first step showing its request and response with merchantId saved, and the captured values panel.

AI chat · SSE

Test your chatbot the way people use it.

Point Ofcors at any endpoint that streams its replies as server-sent events and just talk to it. Your messages go into the body as {{chat.messages}}, and every reply streams back token by token.

  • Reads OpenAI, Anthropic and Vercel AI SDK streams out of the box, works out which one it's talking to, and handles your own JSON with a path you choose.
  • Time to first token, total time and tokens per second on every reply.
  • Thinking, tool calls and errors show up as they arrive, with the raw event stream one click away.
  • Edit an earlier message and resend, regenerate the last reply, or stop it mid-sentence.
Chat mode on a support bot endpoint: a streamed reply with collapsed thinking, a lookup_order tool call card, and time to first token, tokens and tokens per second under each reply.

gRPC

gRPC that keeps up with your protos.

Point Ofcors at the repo your protos live in. It clones with your own SSH keys, understands Buf workspaces, and quietly syncs when the commit changes.

  • Forms generated from your messages, with your doc comments, enums, oneofs and maps. Flip to JSON any time.
  • FieldMask paths with Tab completion, straight from the message you're updating.
  • Schema drift detection: when a response carries fields or enum values your protos don't define, you'll know, and you're one click from syncing.
  • Unary, server, client and bidirectional streaming. Metadata, auth and environments as you'd expect.
  • Copy any call as grpcurl.
gRPC request form with FieldMask chips and a schema drift warning.

Auth

Tokens that refresh themselves.

Tell a variable which request logs you in and where the token is in the response. When the JWT expires, Ofcors runs the login for you before your request goes out, and retries once if anything still says 401 or UNAUTHENTICATED.

  • No more switching tabs to fetch a fresh token every hour.
  • Reads JWT exp or an expires_in field. The cached token is a secret in your keychain.
  • Environments switch in one click; unknown {{variables}} are flagged before you send.
Environment editor with an auto-refreshing token variable tied to a login request.

MCP

Build MCP servers with the lights on.

Connect to any Model Context Protocol server over stdio (Ofcors launches it) or Streamable HTTP, and see exactly what it does.

  • Tools, resources and prompts, with forms generated from each tool's JSON Schema.
  • Every JSON-RPC message, notification and stderr line in a timed traffic log.
  • Results rendered as text, JSON, images and resources.
  • One click to copy the client config for Claude Desktop and friends.
MCP inspector connected to a server: tool list, a generated tool form, and the JSON-RPC traffic log.

Test data

Stub data on tap.

Type rand. anywhere for around seventy generators: names, emails, ULIDs, ISO dates, prices, Luhn-valid test card numbers, rand.pick(a, b, c) and more. Fresh values on every send.

  • Works in URLs, headers, bodies, gRPC forms and the quick-call bar.
  • Hover any variable to see its value and where it comes from.
Autocomplete listing rand.name and other random data generators with live examples.

Speed

Keyboard first. Mouse optional.

Jump to any request, gRPC method, recent call or command with ⌘K. Fire a one-liner from the quick-call bar. Every call lands in the log with its response, ready to reopen or replay.

›GET /health
200 OK12 ms
Command palette searching across requests, gRPC methods, recent calls and commands.

Copy anything, as anything.

Paste a cURL command into the URL bar and it becomes a request. Take any request back out in the form you need.

Free for everything you do on your machine.

Pay only for what involves other people or our servers. Small teams shouldn't need a budget meeting.

Free

$0 forever

  • Every protocol: REST, gRPC, GraphQL, SSE, MCP
  • Flows: chain requests into one-click chores
  • Chat mode for streaming AI endpoints
  • Git-synced protos, FieldMask picker, drift detection
  • Environments, keychain secrets, auto-refreshing tokens
  • Random data, snippets, call log, ⌘K
  • No account, works offline
Download

Pro Coming soon

For one developer, many machines

  • Encrypted sync between your devices
  • Cloud history and backup
  • AI help: requests from docs, explain this error
  • Hosted mock servers
Join the waitlist

Get early access to Teams

One email when it's ready. No newsletter.

Download Ofcors

Free for macOS, Windows and Linux. Updates install themselves.

macOS

Apple silicon and Intel

Coming with the first release

Windows

Windows 10 and 11, x64

Coming with the first release

Linux

AppImage, .deb and .rpm

Coming with the first release

Questions

Is Ofcors really free?

Yes. Everything you do on your own machine is free, with no account and no time limit. Paid plans will cover things that involve other people or our servers, like real-time team workspaces and device sync.

Where is my data stored?

In a JSON file in your app data folder, plus secret values in your operating system's keychain. Nothing is sent anywhere unless you use a sharing feature.

Does it phone home?

The only request Ofcors makes on its own is checking for updates. There's no analytics or tracking in the app. We count downloads and update checks per day to know roughly how many people use it, without storing IP addresses or any identifier.

Can it load protos from a private repo?

Yes. Ofcors uses your system git, so your SSH keys, agent and credential helpers just work. It reads buf.yaml and ships the common Buf registry dependencies (googleapis, protoc-gen-validate, protovalidate) for repos that don't vendor them.

Can I import my Postman collections?

Not yet. Paste any cURL command (Postman can export them) and it becomes a request. Collection import is on the roadmap.

Does it work on Linux with NVIDIA and Wayland?

Yes. Ofcors applies the known WebKitGTK workaround for NVIDIA + Wayland automatically, so it starts cleanly without any setup.