Match & Replace
Match & Replace automatically modifies traffic as it passes through the proxy, without pausing or requiring manual action on each request.
How Rules Work
Each rule defines what to look for and what to do with it. When a request or response matches the conditions, the rule applies its transformation immediately.
Rules apply in the order they appear in the list. If two rules target the same header, the first matching rule applies first, and subsequent rules see the result of that change.
Rule Fields
| Field | Description |
|---|---|
| Name | Label for the rule. Use a descriptive name to identify its purpose. |
| Direction | Whether the rule applies to requests, responses, or both |
| Operation | What transformation to perform (see operations table below) |
| Match mode | Literal, regex, or full content, depending on the operation |
| Match value | The string or pattern to find |
| Replace value | The value to substitute in |
| Enabled | Toggle to activate or deactivate the rule without deleting it |
| Filters | Optional method, host, path, and HTTPQL conditions limiting where the rule applies |
Operations
| Operation | What it does |
|---|---|
| Add header | Adds a new header with a fixed name and value |
| Remove header | Deletes a header by name |
| Replace header | Replaces the value of an existing header |
| Replace body | Replaces a portion of the body using the match value |
| Path / query / query parameter | Changes the request path or query values |
| Request / response line | Changes the selected HTTP start-line component |
| Status code | Changes a response status |
| Raw message | Transforms the HTTP start line, headers, and body together |
| WebSocket payload | Replaces matching client/server message content |
| Workflow | Runs an enabled Convert workflow against the selected content |
Match Modes
Literal matches the exact string. Use this for fixed tokens, header names, or specific values.
Regex matches using a regular expression. Use this when the target varies - for example, to match a token that changes with each session, or to capture and reuse a group in the replacement.
In regex replacements, use capture groups with $1, $2, etc. to reference matched portions in the replace value.
Full passes the entire selected content to the transformation rather than looking for a substring. Some operations, such as adding/removing a named header, use a literal name instead and do not offer all modes.
Transforming a Complete Response Body
- Create and enable a Convert workflow, then validate it with test input.
- Create a Match & Replace rule with direction Response and operation Workflow (Body).
- Choose Full match mode and select the workflow.
- Narrow the rule with an HTTPQL filter, for example:
text
req.host.eq:"cdn.example.com" AND (req.path.cont:".js" OR resp.headers["Content-Type"].value.cont:"javascript")The workflow receives the whole body; its output replaces that body. Workflow (Header) transforms a named header, whereas Workflow (Headers Raw) transforms the header block. These are different inputs from the response body.
HTTPQL filters are checked in the available request/response context. A request-direction rule cannot rely on a response that has not arrived yet. Disable workflow logging when the rule produces high-volume runs; enable it temporarily to diagnose a transformation.
Reordering Rules
Drag a rule row to reposition it in the list. Order matters when rules modify overlapping parts of the same request or response.
AI Assist
Click AI Assist on the rule editor and describe what you want to change in plain language. Ogma generates the rule fields based on your description. Review and adjust the generated values before enabling the rule.
Examples of prompts that work well:
- "Remove the X-Frame-Options header from all responses"
- "Replace the Authorization header value with my test token"
- "Add a header named X-Debug with value true to all requests"
Testing a Rule
Before enabling a rule for live traffic, test it with a sample request:
- Open the rule editor.
- Paste a raw HTTP request into the Test panel.
- Click Apply rules. The panel shows the result and which rules applied.
- Verify the output matches what you expect.
- Enable the rule.
The Test panel also has a Response target with status, headers, and body inputs. Check the applied-rule list: this tests the applicable rules, not just an isolated editor field.
Match & Replace vs. Intercept
Match & Replace is automatic. Once a rule is enabled, it transforms every matching request or response without any action from you.
Intercept pauses traffic and waits for a manual decision. Use Intercept when the right change depends on context you need to evaluate per-request. Use Match & Replace when the same transformation should apply every time without review.
Common Uses
- Swap a session cookie across all requests to test another account.
- Add a header that enables a debug or admin mode.
- Remove security headers from responses to evaluate client-side behavior.
- Replace a hardcoded host in redirect responses.
- Rewrite a request path prefix.