Skip to content

Responses

After you send an HTTP request, the response pane shows what came back and how it got there.

At the top of the response:

ItemMeaning
Status, e.g. 200 OKGreen for 2xx, blue for 3xx, amber for 4xx, red for 5xx. The text is the server’s own reason phrase when it sent one.
TimeThe total time, from starting the request to the last byte of the body
SizeThe body’s size after decompression. Hover it for the wire size, the bytes actually received.
ProtocolHTTP/1.1, HTTP/2 or HTTP/3
LockThe response came over TLS
N redirectsHow many redirects were followed
Save as exampleKeeps this response in the request. See Examples.
MockAdds a route that answers like this response to a mock API. See Mock servers.

Below it, warnings may appear:

  • Sent with undefined values: the {{variables}} (and empty :path variables) that weren’t defined and were sent as written. See Variables & environments.
  • A red line for each script that failed, with the script and the line. See Scripts & tests.
TabShownContents
BodyAlwaysThe body, in the views below
TestsWhen scripts ran testsPassed and failed tests. See Scripts & tests.
HeadersAlwaysEvery response header, with a count
CookiesAlwaysCookies this response set, with a count
TimingAlwaysThe timing waterfall
InfoAlwaysConnection, TLS certificate, redirects and the request that was sent
ConsoleWhen scripts logged something or failedconsole output and script errors

The tab you pick stays selected for that request tab.

The body toolbar has the view buttons, the content type, and four icons: Filter, Wrap lines (on by default), Copy body and Save to file….

ViewForShows
PrettyJSON (by Content-Type, or a body starting with { or [), up to 5 MBIndented JSON with syntax highlighting
RawAny textThe body exactly as received (after decompression), highlighted by content type (JSON, HTML, XML, JavaScript)
PreviewHTMLThe page, rendered in a sandbox where its scripts don’t run
PreviewImages (except SVG), up to 8 MBThe image, on a checkerboard for transparency
HexOther binary bodiesBinary · hex preview: offset, hex bytes and ASCII of the first 64 KB
  • Press Mod+F in the body to search it.
  • Text bodies show the first 10 MB. Beyond that, Only the first part is shown. Use Save to file to get the whole body.
  • An empty body shows Empty body.
  • A body cut at the size limit shows The response was larger than the size limit and was cut. Raise the limit in Settings. See Response size limit.

Filter (the funnel icon) opens a row above the body. Pick a language, type an expression, and the body shows only what matches, with the number of matches. Close it (or press Esc in the field) to see the whole body again. The expression stays when you send again, so you can watch the same part of the response.

LanguageForExample
JSONPath (RFC 9535)JSON$.items[?@.price > 10].name
jqJSON`.items[]
XPath 1.0XML and HTML//item[price > 10]/name, count(//li), //a/@href
  • JSON bodies offer JSONPath and jq; XML and HTML bodies offer XPath; other text offers all three.
  • JSONPath and jq run on the whole body, even when only the first 10 MB are shown. XPath runs on what is shown.
  • JSONPath shows its matches as a JSON array. jq shows each result on its own, like the jq command ([.items[].price] | add gives one number).
  • At most 10,000 results are shown. A mistake in the expression shows what is wrong in red, for example Not a valid jq expression: expected a closing bracket.
  • Copy body copies what the filter shows.

AI agents can use the same filters: send_request takes a filter (AI agents tools).

Save to file… (the download icon) writes the whole body to a file you choose, not just what is shown: all bytes of a large or binary response, after decompression.

Zorvik keeps the bodies of the last 30 responses (up to 512 MB together) for saving. For an older response it says That response is no longer available; send the request again.

Save as example (above the response) keeps the response in the request, as documentation of what it answers and for mocks:

  • The example gets the status as its name (200 OK, 200 OK (2)…), the status code, the response headers and the body. Framing headers, Date and Set-Cookie are left out: cookies can hold a session, and examples are saved in the workspace (and Git).
  • Bodies up to 1 MB of text are kept. Binary and larger responses can’t be examples; use Save to file.
  • A saved request with no other unsaved changes is saved at once. Otherwise the example waits with your other changes until you save.

The request’s Examples tab lists them: pick one to see its headers and body, rename it, change its status or body, or delete it.

Mock APIs built from a folder answer with the examples: an example saved while the URL had query parameters answers only requests with those parameters, and the first one without answers the rest.

Examples are imported from Postman collections (a request’s saved responses) and are written to the request’s file:

examples:
- name: 200 OK
status: 200
headers:
- { key: Content-Type, value: application/json }
body: '{"id": 7, "name": "Rex"}'
- name: Not found
status: 404
url: "{{baseUrl}}/pets/999?include=owner"
body: '{"error": "not found"}'

Headers lists every response header in the order received, one row per header line. Hover a row and choose the copy icon to copy its value.

Cookies lists the cookies set by this response’s Set-Cookie headers: Name, Value, Domain, Path, Expires (or Session) and Flags (Secure, HttpOnly, SameSite). The cookies the workspace has stored are in the title bar’s Cookies dialog. See Cookies.

The Timing tab is a waterfall of where the time went. Each phase is a bar placed after the previous one, with its duration on the right:

PhaseMeasures
RedirectsTime spent on earlier redirect hops (only when there were redirects)
DNS lookupResolving the host name
TCP connectOpening the connection, including a proxy tunnel
TLS handshakeNegotiating encryption (https:// only)
Waiting (TTFB)From sending the request until the first byte of the response: mostly the server’s processing time
DownloadReceiving the body
TotalThe whole request

For HTTP/3, QUIC handshake replaces TCP connect and TLS handshake, because QUIC does both at once.

Every request uses a fresh connection, so DNS, connect and TLS are always measured, never hidden by a reused connection. Behind a proxy, DNS lookup is the lookup of the proxy’s name. See Proxies.

SectionShows
ConnectionURL (the final one, after redirects), Remote address (IP and port), Protocol, Proxy (when one was used) and the size of the Response headers
SecurityTLS version, Cipher, ALPN, and the server certificate’s Subject, Issuer, Valid dates, Names and Serial. Plain HTTP shows Not encrypted. See TLS & certificates.
RedirectsEach hop: status, method, URL and where it pointed
Request sentThe method, body size, URL and every header that was really sent, including those Zorvik added (User-Agent, Content-Type, Authorization, Cookie, …)

Request sent is the place to check what your auth, inherited headers and cookie jar really produced.

If no response arrives, the pane shows what went wrong, the error message and how long it took:

TitleTypical causeHint shown
Could not resolve hostDNS lookup failedCheck the host name, your network or VPN, and DNS settings
Could not connectNothing listening, or blockedIs the server running and reachable on that port?
TLS / certificate errorCertificate not trusted, wrong name or expiredAdd the CA in Settings → Certificates, or turn off verification for this request (with Open settings)
Proxy errorProxy unreachable, refused or needs credentialsCheck Settings → Proxy (with Open settings)
Request timed outA timeout was reachedIncrease the timeout in the request’s Settings tab or in Settings
Too many redirectsMore redirects than Max redirects
Undefined variableThe URL’s host is an undefined {{variable}}Open environments
Pre-request script failedA pre-request script threw an error; nothing was sentFix the script in the request’s, its folder’s or the workspace’s Scripts tab
Invalid requestFor example an invalid URL, method or header value
Request cancelledYou chose Cancel

See Troubleshooting for more.

Every HTTP request you send from a tab (GraphQL included) is recorded in the workspace’s history. Open History in the left rail.

  • Entries are grouped by day (Today, Yesterday, then dates), newest first. Each shows the method, the URL, the status (or Failed), the time taken and the time of day.
  • Search history finds entries whose URL or method contains the text. The list shows the newest 300 matching entries; search to reach older ones.
  • Click an entry to open that request in a new, unsaved tab, exactly as it was when you sent it (its name, or “From history”). Send it again or save it.
  • The trash icon, Clear history, deletes all entries of this workspace after you confirm.
Detail
What is recordedThe request as you wrote it (with its {{variables}}, so secret values from environments aren’t stored), the URL as sent, the status or error, the duration, the body size and the time. Response bodies are not stored.
Secrets in URLsValues of secret variables in the sent URL (such as an API key in the query) are replaced by {{name}}
Failed requestsRecorded, with their error. Cancelled requests and requests stopped by a pre-request script are not.
Not recordedCollection runs, requests from the network tools, GraphQL subscriptions, and other request kinds (WebSocket, Socket.IO, SSE, gRPC, TCP, UDP, DNS, MQTT)
How manyThe newest 500 per workspace. Change it in Settings → Data & privacy → History size (10 to 100000).
Wherehistory.sqlite3 in the app data folder, readable only by your user on macOS and Linux. Never in the workspace.