---
url: https://docs.ogmabox.com/guide/projects-data.md
description: >-
  Understand Ogma instances, projects, local data storage, backups, exports,
  imports, and certificate management.
---

# Projects and Data

Ogma is local-first. Project data, captured traffic, findings, exports, backups, plugin packages, and local settings live on the workstation running Ogma.

## Instances

An instance represents a running Ogma proxy and API process.

Typical defaults:

| Listener | Default |
| --- | --- |
| Proxy | `127.0.0.1:8080` |
| API | `127.0.0.1:8181` |
| Data directory | `./ogma-data` for local CLI/dev runs, platform-specific app data for packaged desktop builds |

Use the launcher to start, stop, open, edit, or remove local instances.

## Projects

Projects separate testing data. Use one project per client, application, assessment phase, or lab target.

Project-scoped data includes:

* HTTP history.
* WebSocket and SSE history.
* Findings.
* Replay sessions.
* Automate sessions and runs.
* Project-specific workflows and project execution data.
* Scope presets.
* Custom passive rules.
* Exports and imported data.
* Notes and project environment variables.

## Workspace Sharing and Switching

A workspace is the data directory that contains your projects and shared CA material. Workflows are workspace-shared by default: enable **Project-specific** in a workflow's configuration to restrict that definition to the current project. Global environment variables also apply across the workspace; project variables override matching global names. Notes remain separate for each project.

Use the project switcher to select another project. Captured traffic is written to the database automatically; taking a backup is not required to preserve it when switching or closing Ogma. A backup is a manual snapshot for later restoration or transfer. A temporary session is intended for disposable work; create or open a persistent workspace for an engagement you need to keep.

## Backups and Exports

Backups are for restoring Ogma project state. Exports are for reporting, review, or tool interop.

| Artifact | Purpose | Treat as sensitive |
| --- | --- | --- |
| Project backup | Restore local Ogma state | Yes |
| HAR export | Share captured HTTP traffic | Yes |
| Findings report | Reporting and triage | Yes |
| Raw HTTP export | Reproduce or audit requests | Yes |
| CSV/JSON exports | External analysis | Yes |

Review exports before sharing when you need to remove cookies, bearer tokens, passwords, internal hostnames, or personal data.

Project backups include stored secret variable values. UI masking does not remove them from an archive. Export workspace-shared workflows separately if you need to transfer them with a project.

## Imports

Ogma supports importing traffic and assessment data from several sources, including HAR, Burp exports, API specifications, and findings imports.

Use imports to:

* Bring previous test evidence into a project.
* Seed targets from an API specification.
* Continue analysis from another proxy or capture source.
* Normalize findings into Ogma's reporting workflow.

## Project Organization

Recommended setup:

* Use a dedicated project per assessment.
* Use clear names for projects, exports, and backups.
* Keep evidence, notes, and findings linked inside the same project.
* Store backups next to the engagement or lab materials they belong to.
* Review plugin logs before sharing diagnostics.
* Clear browser data when switching between unrelated targets.

## Certificates

Ogma manages local CA material for HTTPS inspection. Certificate settings include CA download, backup/import, regeneration, named CAs, and TLS diagnostics.

Use certificate profiles to separate work between projects or environments when that makes the setup easier to reason about.
