12 PROTOCOLS open source, one binary, one admin UI

Mock every backend you depend on.

AirMock stands in for REST, SOAP, GraphQL, WebSocket, TCP, SMTP, MQTT, FTP, Kafka, SMPP, Diameter and JMS (AMQP 1.0) systems. It also includes an API client, a load tester and a certificate store. No runtime and no database to install.

airmock serve
terminalairmock
$ airmock serve
✓ admin ui    http://localhost:8080
✓ gateway     :8081
✓ engines     12 protocols ready
localhost:8080 / Dashboard (illustrative)
Mocks24
Sessions7
p9512ms
GET/orders/{id}200
SMPPsubmit_sm → 15551234DELIVRD
MQTTsensors/+ → alerts/1live
DIACCR initial2001
Illustrative preview. Real screenshots are further down. 9 themes 12 protocols
12protocols, each on a real listener
1static binary with the UI embedded
0external databases or runtimes
50concurrent workers in the load tester

How it works

From nothing to a working mock.

Start the server

Run one command. The admin UI opens in your browser and the mock gateway starts listening.

airmock serve

Create a mock

Pick a protocol and a quick-start template, or import a WSDL, OpenAPI file, HAR capture or Postman collection.

REST · SOAP · MQTT · SMPP …

Point your app at it

Change one host or port. Every hit appears in the log with its full request and response, live as it happens.

localhost:8081

In the product

The real admin UI.

Nine screens of AirMock itself, each in a different one of its nine themes. They play on their own; hover to pause, use the arrows or thumbnails, or open any one full size.

Why AirMock is different

More than an HTTP stub.

Mock tools usually centre on HTTP. AirMock also covers the systems that talk SMS, billing, queues and mail, and keeps everything you need to test them in one place.

Twelve protocols, one tool

Telecom and enterprise protocols (SMPP, Diameter, AMQP 1.0, Kafka) sit beside REST and SOAP, with the same templates, rules and logs.

Mock, call and load test together

The built-in Postman-style client and load tester call your mocks or the real service, and every call lands in the same log.

Mocks that answer for a reason

A fixed ladder decides every response, from proxy to static body, so you can always tell why a reply came back.

Push to connected clients

See who is attached over TCP, WebSocket, MQTT, SMPP or JMS, then send a message down their socket on demand.

Callbacks that survive a restart

Async webhooks and emails are queued in the database with retries and backoff, so a restart does not lose them.

Record real traffic, promote it

Proxy to a real service, capture the exchange, and turn any captured hit into an editable mock in one click.

Built for

The systems that are hard to get a test account for.

Telecom

SMS and charging

Fake an SMSC with delivery receipts, or a Diameter credit-control server that approves and rejects on demand.

Integration

Third-party APIs

Replace a partner sandbox with a mock that returns the errors, delays and edge cases you cannot trigger for real.

Messaging

Queues and brokers

Exercise MQTT, Kafka and AMQP 1.0 (JMS) consumers without standing up a broker cluster.

CI

Repeatable pipelines

Load mocks from a file at the start of a build, run the suite, and read every hit in the log afterwards.

One tool instead of six

Stop stitching tools together.

Testing a real integration usually means a mock server, an API client, a load tool, certificate scripts, a protocol simulator and a cron job. AirMock puts them behind one login.

a mock server→ in AirMock

12 protocol mocks

Rules, scenarios, weighted replies, validation and fault injection.

an API client→ in AirMock

Collections and runner

Environments, chained requests, code snippets and Postman or SoapUI import.

a load-testing tool→ in AirMock

Load tester with history

Percentiles per run, kept for comparison, with an offline HTML report.

openssl scripts→ in AirMock

Certificate store

Generate or import CAs and certs, then bind them to a mock with mTLS.

SMS and billing simulators→ in AirMock

SMPP and Diameter

Delivery receipts and credit-control answers from the same place as your REST mocks.

cron plus curl→ in AirMock

Scheduled events

Fire templated requests on an interval, with counters and CSV rows.

One core

Twelve protocols orbit one engine.

Every protocol shares the same templates, rules, hit log, certificates and admin UI. Pick a node to jump to how that mock works.

The inner ring is HTTP-family, the middle ring is plain TCP-style protocols, and the outer ring is messaging and telecom.

Protocols

Pick the wire you need to fake.

Each protocol runs a real server on its own port, so existing clients connect without code changes. Choose one to see how a mock is shaped.

try it

Response logic

Behaves like the real thing.

For REST, SOAP and GraphQL, AirMock walks this ladder on every request and answers at the first step that applies.

Bodies are Go templates with sprig, fake data, persisted counters and CSV rows, so a response can echo the request, count calls or rotate through test accounts.

  1. 1
    Proxy / record-replayForward to a real upstream, capture the exchange, promote it to a mock.
  2. 2
    ValidationRequired, type, pattern, range and enum checks return a 400 before any logic runs.
  3. 3
    Async callbackAcknowledge now, call back by webhook or email later, with retries.
  4. 4
    ScenarioStep through pending, shipped, delivered across calls from the same client.
  5. 5
    Weighted randomReturn one of several responses by probability.
  6. 6
    Conditional rulesMatch on body, header, query or XPath. First match wins.
  7. 7
    Static responseThe fallback body, status, headers and delay.

Try the ladder

A simulated payment mock with two conditional rules and a fallback. Change the request and see which step answers.

  1. 1 body.amount gt 1000
  2. 2 header.X-Region equals US
  3. 3 static response
response200

Try fault injection

Set a mock's failure profile and see how 40 simulated calls would turn out. This runs in your browser, not on a real instance.

15%
5%
200 ms

40 calls

okerror statustimeout

Features

Everything in the box.

MOCK ENGINE

Realistic responses, on your terms

Conditional rules, stateful scenarios, weighted random replies, request validation, templated bodies and per-response delay. Version history keeps every edit, with field-level diffs and one-click restore.

  • response rules
  • scenarios
  • weighted
  • validation
  • templates
  • version history
FAULT INJECTION

Break it on purpose

Latency jitter, error rates and timeouts that drop the connection, per mock.

PROJECTS

Group and isolate

Give a set of APIs its own base path, dedicated port and TLS settings.

SESSIONS

Connected clients

List, disconnect and push messages to live TCP, WS, MQTT, SMPP and JMS sessions.

ASYNC

Callbacks

Webhook or email callbacks with fixed or extracted targets, retry and backoff.

API CLIENT

Collections and environments

Folders, variables, bearer, basic and API-key auth, multipart, response extraction, a collection runner, code snippets in curl, JS, Python and Go, and an mTLS client-certificate picker.

  • Postman
  • SoapUI
  • WSDL
  • curl
  • workspaces
LOAD TESTER

Percentiles, history, reports

Up to 50 workers and 2000 requests for HTTP and WebSocket. Each run keeps p50 to p99, requests per second and error rate, with JSON, CSV and standalone HTML report downloads.

CERTIFICATES

TLS and mTLS store

Generate or import PEM, DER and PKCS#12. Bind to the gateway, a project or a mock.

IMPORT

Scaffold from specs

WSDL, GraphQL SDL, OpenAPI, HAR, Postman and SoapUI become working mocks.

SCHEDULED EVENTS

Fire on a timer

Send outbound requests on an interval with templated bodies and CSV data.

OBSERVABILITY

One log for everything

Inbound hits, proxy captures, client calls, callbacks and scheduled events in a filterable table with live tail, export and header redaction. A dashboard flags unused and error-prone mocks. Prometheus metrics at /metrics.

SECURITY

Admin login and workspace locks

Optional PIN or password login with rolling sessions and brute-force lockout, plus per-workspace locks that protect collections, environments and mocks.

MOCKS AS CODE

Keep mocks in git

Export, list and apply mocks and scheduled events from a file. Apply matches by name, so it is safe in CI.

BACKUP

Move or restore everything

One JSON file holds mocks, certificates, collections, templates and events. Import merges without overwriting.

UI

Nine themes

Four light and five dark themes with accents.

PALETTE

Ctrl/Cmd + K

Jump to any mock, request or page.

TLS TOOL

Chain inspector

Dial any host and see the chain, expiry and hostname checks.

Mocks as code

Review mocks in pull requests.

Export every mock to a file, commit it, and apply it from CI against any instance. --dry-run validates everything and saves nothing, --atomic applies nothing unless every mock passes, and an identical mock is reported as unchanged instead of rewritten.

shellidempotent
# dump the current instance
airmock mocks export -o mocks.yaml

# create or update from the file
airmock mocks apply -f mocks.yaml --dry-run
airmock mocks apply -f mocks.yaml --atomic \
  --url https://mocks.internal:8080 \
  --password "$AIRMOCK_ADMIN_PASSWORD"
#   created   Get order
#   unchanged Create payment
#   updated   OCS granted units

Security

Closed by default, open on purpose.

The admin UI and API start on the loopback interface only, so a fresh install is not reachable from the network. Opening it up is one flag, and AirMock warns at startup if you do it with login off.

Loopback by default

The admin listener binds to 127.0.0.1. Use --admin-host 0.0.0.0 to reach it from other machines. The Linux package's service does, so check the startup log.

PIN or password login

One shared credential with rolling sessions and a 60-second lockout after 5 wrong tries from an address. PINs are 4 to 6 digits; use a longer password if the port is reachable.

Cross-site write protection

A web page you visit cannot create or change mocks on a locally running instance, even with login off. Changes must come from AirMock's own page, or from curl and the CLI.

Guarded imports

The import fetcher refuses loopback, link-local and cloud-metadata addresses on every connection and redirect, so it cannot be pointed at services on the AirMock host.

What it does not protect: the mock gateway and protocol ports (SMPP, Diameter, MQTT and the rest) have no authentication, by design, because the clients you are testing expect none. Keep them on a network you trust or firewall them to the machines that need them.

Install

Running in a minute.

State lives in an embedded SQLite file. Open http://localhost:8080 for the admin UI. Mocks answer on :8081.

Debian / Ubuntusystemd service
sudo dpkg -i airmock_*.deb
systemctl status airmock
Fedora / RHELsystemd service
sudo rpm -i airmock_*.rpm
systemctl status airmock
Linux or macOStarball
tar xzf airmock_*.tar.gz
./airmock serve
Windowszip
Expand-Archive airmock_*_windows_amd64.zip
.\airmock.exe serve

Check what you installed with airmock --version (it prints the version and commit). Upgrading a package never touches /var/lib/airmock. Packages and checksums are in Downloads.

Compatibility

What each protocol actually speaks.

So "twelve protocols" is something you can check. This is taken from the code, including what is not supported.

Supported and unsupported features of each protocol, with TLS options
ProtocolSupportedNot supportedTLS
RESTAny method, path parameters, HEAD for GET mocks, CORS preflight, request bodies to 10 MB, gzip request bodiesRequest bodies over 10 MB (413)Gateway or per project, with mutual TLS
SOAPSOAP 1.1, routing by SOAPAction or body element, WSDL and SoapUI importSOAP 1.2 specific handlingAs REST
GraphQLPOST with JSON, operation matching, inline arguments and variables, SDL importSchema enforcement, subscriptionsAs REST
WebSocketGreeting, text frames, match by contains, exact or regex, server pushBinary reply framesAs REST
TCPBanner, custom line delimiter, interactive or one-line login, idle timeoutTelnet option negotiationPer mock, with mutual TLS
SMTPEHLO, HELO, MAIL FROM, RCPT TO, DATA, RSET, NOOP, QUIT; refusal at sender, recipient or message stageSTARTTLS, AUTH, pipeliningImplicit TLS, with mutual TLS
MQTTCONNECT, SUBSCRIBE, UNSUBSCRIBE, PUBLISH, PINGREQ, DISCONNECT; + and # topics; delivery at QoS 0QoS 2, retained messages, persistent sessions, authenticationNone
FTPUSER, PASS, SYST, TYPE, PWD, CWD, NOOP, QUIT, PASV, LIST, NLST, RETR, STORActive mode (PORT), directoriesNone
KafkaSingle node: ApiVersions v0 to 2, Metadata v0 to 8, Produce v0 to 8, Fetch v0 to 11, ListOffsets v1 to 5Consumer groups, transactions, multiple partitionsNone
SMPPv3.4 SMSC: bind_transceiver, enquire_link, submit_sm, unbind; deliver_sm replies and pushesbind_transmitter and receiver, submit_multi, query_sm, long messagesNone
DiameterCER/CEA, DWR/DWA, CCR to CCA. Reads Session-Id, Origin-Host and Realm, CC-Request-Type and Number, Subscription-Id-Data, and the MSCC Rating-Group and Service-Identifier. Answers with Result-Code and, per rule, MSCC with Granted-Service-Unit (CC-Total-Octets, CC-Time, CC-Service-Specific-Units), Validity-Time and Final-Unit-IndicationOther Diameter applications and commands (Gx, Rx, S6a and so on)None
JMS (AMQP 1.0)Open, Begin, Attach, Flow, Transfer, Disposition (accepted), Detach, End, Close. Match on address and payloadSASL, transactions, link resumption, queueing without creditNone

Know the limits

What AirMock is not.

  • One shared admin credential. No user accounts, teams or API keys.
  • Self-hosted only. No hosted or shareable public-URL mode.
  • Kafka has no consumer groups. MQTT is QoS 0 with no retained messages.
  • Per-mock TLS is available for HTTP, TCP and SMTP only.
  • Sessions and cookie jars are in memory and reset on restart.
  • The mock gateway, protocol ports and /metrics have no authentication. Keep them on a trusted network or firewall them.

Downloads

Get the latest release from GitHub.

This list is read live from the latest GitHub release, so it always shows the newest version. Verify a download against the SHA-256 below, or with sha256sum -c checksums.txt.

AirMock packages with platform, size and SHA-256 checksum
PackagePlatformSizeSHA-256
This table needs JavaScript. Use the latest release on GitHub.

What's new

Recent changes.

  1. v1.0.0 first open source release

    • First open source release, under the MIT licence, with its source and releases on GitHub
    • Twelve protocols in one binary: REST, SOAP, GraphQL, WebSocket, TCP, SMTP, MQTT, FTP, Kafka, SMPP, Diameter and JMS (AMQP 1.0)
    • Built-in API client with collections and environments, a load tester with percentiles and history, and a certificate store for HTTPS and mTLS
    • Nine themes, an admin UI that listens on loopback by default, and an optional PIN-protected workspace
    • Packages for Linux (.deb, .rpm, tarball), Windows (installer and zip) and macOS (app and archive), built by GitHub Actions from the tag

Open source

Free, open and yours to change.

AirMock is open source under the MIT licence. Read the code, build it yourself, run it anywhere and send changes back. There are no accounts, no licence keys and no telemetry.

MIT licensed

Use it at work, in CI or in your own products, with no fees and no seat limits.

Read the source

One Go module and one Svelte UI. Browse the code on GitHub.

Contribute

Found a bug or need a protocol feature? Open an issue or send a pull request.

Questions

Before you install.

Do I need a database or runtime?

No. AirMock is a single Go binary with the web UI embedded. It stores everything in a SQLite file in its data directory.

Which ports does it use?

The admin UI and API use 8080. REST, SOAP, GraphQL and WebSocket mocks answer on 8081 by default, or on a dedicated port if you put them in a project. Every other protocol mock binds the port you give it. All are configurable.

Can I run it in CI?

Yes. Start it headless with airmock serve --headless, then load your mocks with airmock mocks apply -f mocks.yaml. Apply updates by name, so repeated runs are safe.

Is it secure to leave running on a network?

The admin UI and API listen on loopback only unless you pass --admin-host, and you can protect them with a PIN or password. Cross-site writes are refused and imports cannot reach local services. The mock gateway and protocol ports are unauthenticated, so firewall them to the machines that need them.

Will my mocks survive a restart?

Yes. Mocks, scenarios, counters, queued callbacks and the hit log persist. Live sessions, cookie jars and Kafka topic contents reset.

Can I move my setup to another machine?

Export a full backup as one JSON file, including certificates, collections and templates, then import it elsewhere. Imports merge and never overwrite.

Which operating systems are supported?

Linux packages (.deb, .rpm and tarball), a Windows installer and zip archives, and a macOS app and archives are built for amd64 and arm64. The Linux packages are the best tested.

Stop waiting. Start testing.

Download AirMock, open the browser UI, and have your first mock answering in minutes.

Go to downloads