Mock every backend you depend on.
AirMock stands in for REST, SOAP, GraphQL, WebSocket, TCP, SMTP, MQTT, FTP, Kafka, SMPP, Diameter and JMS (AMQP 1.0) systems. It also includes an API client, a load tester and a certificate store. No runtime and no database to install.
airmock serve$ airmock serve ✓ admin ui http://localhost:8080 ✓ gateway :8081 ✓ engines 12 protocols ready
How it works
From nothing to a working mock.
Start the server
Run one command. The admin UI opens in your browser and the mock gateway starts listening.
airmock serveCreate a mock
Pick a protocol and a quick-start template, or import a WSDL, OpenAPI file, HAR capture or Postman collection.
REST · SOAP · MQTT · SMPP …Point your app at it
Change one host or port. Every hit appears in the log with its full request and response, live as it happens.
localhost:8081In the product
The real admin UI.
Nine screens of AirMock itself, each in a different one of its nine themes. They play on their own; hover to pause, use the arrows or thumbnails, or open any one full size.
Why AirMock is different
More than an HTTP stub.
Mock tools usually centre on HTTP. AirMock also covers the systems that talk SMS, billing, queues and mail, and keeps everything you need to test them in one place.
Twelve protocols, one tool
Telecom and enterprise protocols (SMPP, Diameter, AMQP 1.0, Kafka) sit beside REST and SOAP, with the same templates, rules and logs.
Mock, call and load test together
The built-in Postman-style client and load tester call your mocks or the real service, and every call lands in the same log.
Mocks that answer for a reason
A fixed ladder decides every response, from proxy to static body, so you can always tell why a reply came back.
Push to connected clients
See who is attached over TCP, WebSocket, MQTT, SMPP or JMS, then send a message down their socket on demand.
Callbacks that survive a restart
Async webhooks and emails are queued in the database with retries and backoff, so a restart does not lose them.
Record real traffic, promote it
Proxy to a real service, capture the exchange, and turn any captured hit into an editable mock in one click.
Built for
The systems that are hard to get a test account for.
SMS and charging
Fake an SMSC with delivery receipts, or a Diameter credit-control server that approves and rejects on demand.
Third-party APIs
Replace a partner sandbox with a mock that returns the errors, delays and edge cases you cannot trigger for real.
Queues and brokers
Exercise MQTT, Kafka and AMQP 1.0 (JMS) consumers without standing up a broker cluster.
Repeatable pipelines
Load mocks from a file at the start of a build, run the suite, and read every hit in the log afterwards.
One tool instead of six
Stop stitching tools together.
Testing a real integration usually means a mock server, an API client, a load tool, certificate scripts, a protocol simulator and a cron job. AirMock puts them behind one login.
12 protocol mocks
Rules, scenarios, weighted replies, validation and fault injection.
Collections and runner
Environments, chained requests, code snippets and Postman or SoapUI import.
Load tester with history
Percentiles per run, kept for comparison, with an offline HTML report.
Certificate store
Generate or import CAs and certs, then bind them to a mock with mTLS.
SMPP and Diameter
Delivery receipts and credit-control answers from the same place as your REST mocks.
Scheduled events
Fire templated requests on an interval, with counters and CSV rows.
One core
Twelve protocols orbit one engine.
Every protocol shares the same templates, rules, hit log, certificates and admin UI. Pick a node to jump to how that mock works.
The inner ring is HTTP-family, the middle ring is plain TCP-style protocols, and the outer ring is messaging and telecom.
Protocols
Pick the wire you need to fake.
Each protocol runs a real server on its own port, so existing clients connect without code changes. Choose one to see how a mock is shaped.
Response logic
Behaves like the real thing.
For REST, SOAP and GraphQL, AirMock walks this ladder on every request and answers at the first step that applies.
Bodies are Go templates with sprig, fake data, persisted counters and CSV rows, so a response can echo the request, count calls or rotate through test accounts.
- 1Proxy / record-replayForward to a real upstream, capture the exchange, promote it to a mock.
- 2ValidationRequired, type, pattern, range and enum checks return a 400 before any logic runs.
- 3Async callbackAcknowledge now, call back by webhook or email later, with retries.
- 4ScenarioStep through pending, shipped, delivered across calls from the same client.
- 5Weighted randomReturn one of several responses by probability.
- 6Conditional rulesMatch on body, header, query or XPath. First match wins.
- 7Static responseThe fallback body, status, headers and delay.
Try the ladder
A simulated payment mock with two conditional rules and a fallback. Change the request and see which step answers.
- 1 body.amount gt 1000
- 2 header.X-Region equals US
- 3 static response
Try fault injection
Set a mock's failure profile and see how 40 simulated calls would turn out. This runs in your browser, not on a real instance.
40 calls
Features
Everything in the box.
Realistic responses, on your terms
Conditional rules, stateful scenarios, weighted random replies, request validation, templated bodies and per-response delay. Version history keeps every edit, with field-level diffs and one-click restore.
- response rules
- scenarios
- weighted
- validation
- templates
- version history
Break it on purpose
Latency jitter, error rates and timeouts that drop the connection, per mock.
Group and isolate
Give a set of APIs its own base path, dedicated port and TLS settings.
Connected clients
List, disconnect and push messages to live TCP, WS, MQTT, SMPP and JMS sessions.
Callbacks
Webhook or email callbacks with fixed or extracted targets, retry and backoff.
Collections and environments
Folders, variables, bearer, basic and API-key auth, multipart, response extraction, a collection runner, code snippets in curl, JS, Python and Go, and an mTLS client-certificate picker.
- Postman
- SoapUI
- WSDL
- curl
- workspaces
Percentiles, history, reports
Up to 50 workers and 2000 requests for HTTP and WebSocket. Each run keeps p50 to p99, requests per second and error rate, with JSON, CSV and standalone HTML report downloads.
TLS and mTLS store
Generate or import PEM, DER and PKCS#12. Bind to the gateway, a project or a mock.
Scaffold from specs
WSDL, GraphQL SDL, OpenAPI, HAR, Postman and SoapUI become working mocks.
Fire on a timer
Send outbound requests on an interval with templated bodies and CSV data.
One log for everything
Inbound hits, proxy captures, client calls, callbacks and scheduled events in a filterable table with live tail, export and header redaction. A dashboard flags unused and error-prone mocks. Prometheus metrics at /metrics.
Admin login and workspace locks
Optional PIN or password login with rolling sessions and brute-force lockout, plus per-workspace locks that protect collections, environments and mocks.
Keep mocks in git
Export, list and apply mocks and scheduled events from a file. Apply matches by name, so it is safe in CI.
Move or restore everything
One JSON file holds mocks, certificates, collections, templates and events. Import merges without overwriting.
Nine themes
Four light and five dark themes with accents.
Ctrl/Cmd + K
Jump to any mock, request or page.
Chain inspector
Dial any host and see the chain, expiry and hostname checks.
Mocks as code
Review mocks in pull requests.
Export every mock to a file, commit it, and apply it from CI against any instance. --dry-run validates everything and saves nothing, --atomic applies nothing unless every mock passes, and an identical mock is reported as unchanged instead of rewritten.
# dump the current instance airmock mocks export -o mocks.yaml # create or update from the file airmock mocks apply -f mocks.yaml --dry-run airmock mocks apply -f mocks.yaml --atomic \ --url https://mocks.internal:8080 \ --password "$AIRMOCK_ADMIN_PASSWORD" # created Get order # unchanged Create payment # updated OCS granted units
Security
Closed by default, open on purpose.
The admin UI and API start on the loopback interface only, so a fresh install is not reachable from the network. Opening it up is one flag, and AirMock warns at startup if you do it with login off.
Loopback by default
The admin listener binds to 127.0.0.1. Use --admin-host 0.0.0.0 to reach it from other machines. The Linux package's service does, so check the startup log.
PIN or password login
One shared credential with rolling sessions and a 60-second lockout after 5 wrong tries from an address. PINs are 4 to 6 digits; use a longer password if the port is reachable.
Cross-site write protection
A web page you visit cannot create or change mocks on a locally running instance, even with login off. Changes must come from AirMock's own page, or from curl and the CLI.
Guarded imports
The import fetcher refuses loopback, link-local and cloud-metadata addresses on every connection and redirect, so it cannot be pointed at services on the AirMock host.
What it does not protect: the mock gateway and protocol ports (SMPP, Diameter, MQTT and the rest) have no authentication, by design, because the clients you are testing expect none. Keep them on a network you trust or firewall them to the machines that need them.
Install
Running in a minute.
State lives in an embedded SQLite file. Open http://localhost:8080 for the admin UI. Mocks answer on :8081.
sudo dpkg -i airmock_*.deb systemctl status airmock
sudo rpm -i airmock_*.rpm systemctl status airmock
tar xzf airmock_*.tar.gz ./airmock serve
Expand-Archive airmock_*_windows_amd64.zip .\airmock.exe serve
Check what you installed with airmock --version (it prints the version and commit). Upgrading a package never touches /var/lib/airmock. Packages and checksums are in Downloads.
Compatibility
What each protocol actually speaks.
So "twelve protocols" is something you can check. This is taken from the code, including what is not supported.
| Protocol | Supported | Not supported | TLS |
|---|---|---|---|
| REST | Any method, path parameters, HEAD for GET mocks, CORS preflight, request bodies to 10 MB, gzip request bodies | Request bodies over 10 MB (413) | Gateway or per project, with mutual TLS |
| SOAP | SOAP 1.1, routing by SOAPAction or body element, WSDL and SoapUI import | SOAP 1.2 specific handling | As REST |
| GraphQL | POST with JSON, operation matching, inline arguments and variables, SDL import | Schema enforcement, subscriptions | As REST |
| WebSocket | Greeting, text frames, match by contains, exact or regex, server push | Binary reply frames | As REST |
| TCP | Banner, custom line delimiter, interactive or one-line login, idle timeout | Telnet option negotiation | Per mock, with mutual TLS |
| SMTP | EHLO, HELO, MAIL FROM, RCPT TO, DATA, RSET, NOOP, QUIT; refusal at sender, recipient or message stage | STARTTLS, AUTH, pipelining | Implicit TLS, with mutual TLS |
| MQTT | CONNECT, SUBSCRIBE, UNSUBSCRIBE, PUBLISH, PINGREQ, DISCONNECT; + and # topics; delivery at QoS 0 | QoS 2, retained messages, persistent sessions, authentication | None |
| FTP | USER, PASS, SYST, TYPE, PWD, CWD, NOOP, QUIT, PASV, LIST, NLST, RETR, STOR | Active mode (PORT), directories | None |
| Kafka | Single node: ApiVersions v0 to 2, Metadata v0 to 8, Produce v0 to 8, Fetch v0 to 11, ListOffsets v1 to 5 | Consumer groups, transactions, multiple partitions | None |
| SMPP | v3.4 SMSC: bind_transceiver, enquire_link, submit_sm, unbind; deliver_sm replies and pushes | bind_transmitter and receiver, submit_multi, query_sm, long messages | None |
| Diameter | CER/CEA, DWR/DWA, CCR to CCA. Reads Session-Id, Origin-Host and Realm, CC-Request-Type and Number, Subscription-Id-Data, and the MSCC Rating-Group and Service-Identifier. Answers with Result-Code and, per rule, MSCC with Granted-Service-Unit (CC-Total-Octets, CC-Time, CC-Service-Specific-Units), Validity-Time and Final-Unit-Indication | Other Diameter applications and commands (Gx, Rx, S6a and so on) | None |
| JMS (AMQP 1.0) | Open, Begin, Attach, Flow, Transfer, Disposition (accepted), Detach, End, Close. Match on address and payload | SASL, transactions, link resumption, queueing without credit | None |
Know the limits
What AirMock is not.
- One shared admin credential. No user accounts, teams or API keys.
- Self-hosted only. No hosted or shareable public-URL mode.
- Kafka has no consumer groups. MQTT is QoS 0 with no retained messages.
- Per-mock TLS is available for HTTP, TCP and SMTP only.
- Sessions and cookie jars are in memory and reset on restart.
- The mock gateway, protocol ports and
/metricshave no authentication. Keep them on a trusted network or firewall them.
Downloads
Get the latest release from GitHub.
This list is read live from the latest GitHub release, so it always shows the newest version. Verify a download against the SHA-256 below, or with sha256sum -c checksums.txt.
| Package | Platform | Size | SHA-256 |
|---|---|---|---|
| This table needs JavaScript. Use the latest release on GitHub. | |||
What's new
Recent changes.
v1.0.0 first open source release
- First open source release, under the MIT licence, with its source and releases on GitHub
- Twelve protocols in one binary: REST, SOAP, GraphQL, WebSocket, TCP, SMTP, MQTT, FTP, Kafka, SMPP, Diameter and JMS (AMQP 1.0)
- Built-in API client with collections and environments, a load tester with percentiles and history, and a certificate store for HTTPS and mTLS
- Nine themes, an admin UI that listens on loopback by default, and an optional PIN-protected workspace
- Packages for Linux (.deb, .rpm, tarball), Windows (installer and zip) and macOS (app and archive), built by GitHub Actions from the tag
Open source
Free, open and yours to change.
AirMock is open source under the MIT licence. Read the code, build it yourself, run it anywhere and send changes back. There are no accounts, no licence keys and no telemetry.
MIT licensed
Use it at work, in CI or in your own products, with no fees and no seat limits.
Read the source
One Go module and one Svelte UI. Browse the code on GitHub.
Contribute
Found a bug or need a protocol feature? Open an issue or send a pull request.
Questions
Before you install.
Do I need a database or runtime?
No. AirMock is a single Go binary with the web UI embedded. It stores everything in a SQLite file in its data directory.
Which ports does it use?
The admin UI and API use 8080. REST, SOAP, GraphQL and WebSocket mocks answer on 8081 by default, or on a dedicated port if you put them in a project. Every other protocol mock binds the port you give it. All are configurable.
Can I run it in CI?
Yes. Start it headless with airmock serve --headless, then load your mocks with airmock mocks apply -f mocks.yaml. Apply updates by name, so repeated runs are safe.
Is it secure to leave running on a network?
The admin UI and API listen on loopback only unless you pass --admin-host, and you can protect them with a PIN or password. Cross-site writes are refused and imports cannot reach local services. The mock gateway and protocol ports are unauthenticated, so firewall them to the machines that need them.
Will my mocks survive a restart?
Yes. Mocks, scenarios, counters, queued callbacks and the hit log persist. Live sessions, cookie jars and Kafka topic contents reset.
Can I move my setup to another machine?
Export a full backup as one JSON file, including certificates, collections and templates, then import it elsewhere. Imports merge and never overwrite.
Which operating systems are supported?
Linux packages (.deb, .rpm and tarball), a Windows installer and zip archives, and a macOS app and archives are built for amd64 and arm64. The Linux packages are the best tested.
Stop waiting. Start testing.
Download AirMock, open the browser UI, and have your first mock answering in minutes.
Go to downloads