Spot inspection signals
Compare macOS trust with an independent public certificate baseline. See confirmed, suspected, and unknown results in context.
See the trust behind your traffic. Uncover TLS inspection signals, explore certificates, and understand your network. Right from your Mac’s menu bar.
Free & open source · macOS 14+ · Apple Silicon

Domain inspection ratio
No matching domains.
Connect a certificate authority to the domains where it appears. Review its identity, validity, and trust evidence.
Built for your Mac. Built to be understood.
Feels right at home.
Open for everyone.
On your own Mac.
Download and explore.
From a network signal to the certificate behind it. Everything you need to follow the evidence.
Compare macOS trust with an independent public certificate baseline. See confirmed, suspected, and unknown results in context.
Explore issuers, validity dates, fingerprints, and the domains that share a certificate authority.
Search observed domains, inspect probe results, and trace connection details without leaving your menu bar.
Interactive preview · Sample data
A compact view of observed domains and their classifications. Open a certificate to understand the detail behind a signal.
Domain inspection ratio
No matching domains.
Connect a certificate authority to the domains where it appears. Review its identity, validity, and trust evidence.
Illustrative preview. Independent probes do not establish which certificate another app received.
Your network observations belong on your Mac. No central analysis service. No account to create.
Probes connect to discovered hosts. Some metadata and logs are not encrypted.
How your data is handledA simple flow from observation to understanding, right on your Mac.
Install on macOS 14 or later with Apple Silicon. Open the app from your menu bar.
Import accessible Chromium browser history and discover domains through available network metadata. TLS probes gather trust evidence.
Review domains, certificate details, and classifications. Follow a signal at your own pace.
Read the code. Question the evidence. Help make network trust a little easier to understand.
Explore the sourceWe’re collecting feedback from the people using swg bar. Tried it on your network? Share what you found.
Share your experienceCompletely free and open source under the MIT license. All the essentials, without a subscription.
Completely free & open source
Straight answers, from the project itself.
It compares native macOS trust with an independent public certificate baseline to surface TLS inspection signals. Classification depends on collected evidence and rules. A repeated certificate authority alone is not proof of inspection.
No. swg bar examines available connection metadata and certificates, and makes its own TLS probes. It is not a VPN, traffic blocker, or decryption proxy. A probe cannot prove which certificate another application received.
The published v1.7.0 installer requires macOS 14 or later and an Apple Silicon Mac (M1 or later). An Intel installer is not included in this release.
The current release uses ad-hoc signing. It is not Developer ID signed or notarized by Apple. After reviewing the source and download, follow the app-specific option in System Settings → Privacy & Security if macOS blocks it. Managed Macs may restrict installation.
It reads macOS certificate trust, imports hostnames from accessible Chromium browser histories, and uses network metadata where permissions allow. Observations stay local; probes make outbound TLS connections. Some fields are encrypted, but metadata and logs are not fully encrypted.
Yes. Current classification is scoped to supported IPv4 HTTPS evidence. Missing handshakes, unavailable capture permissions, unsupported traffic, and other gaps may leave results unknown or excluded. Treat the app as an evidence tool, not a guarantee.
The current application resets its local database, rules, encryption key, and archived logs when it detects a newer version. Back up ~/Library/Application Support/SWGBar/ and ~/Library/Logs/SWGBar/ before upgrading if you need existing records.
Start with your next connection.