Scripting in Fiddler Everywhere
Scripting is currently a BETA feature, as indicated by the BETA badge next to the Scripting tab. Behavior, available hooks, and limits may change in future releases.
Scripting lets you write short C# scripts that hook into the traffic pipeline and application lifecycle of Fiddler Everywhere. Unlike the Rules tab, which uses a visual condition/action builder, the Scripting tab lets you write imperative code to inspect and modify sessions, WebSocket messages, and certificate validation results, and to react to Fiddler Everywhere being attached, detached, started, or shut down.
Scripting is useful when your logic is difficult or impossible to express with the Rules Builder—for example, computing a value from multiple headers, keeping state across requests, or applying conditional logic with several branches.
The Scripting Tab
Open the Scripting tab to manage your scripts. The tab shows a list of scripts with the following controls:
- Add — creates a new script (prefilled with the sample script template) and opens it in the script editor.
- Enabled toggle (per script) — enables or disables an individual script. Enabling a script automatically disables the previously active one—only one script can be active at a time. If you enable a script that fails validation, the toggle reverts and an error notification is displayed.
- Double-click a row, or use the row's context menu Edit command, to open the script in the editor.
- Duplicate (context menu) — creates a copy of the selected script.
- Delete (context menu, or multi-select and delete) — removes the selected script(s) after a confirmation dialog.
- Rename — click the script name to edit it inline.
- Drag to reorder — changes the display order of scripts in the list.
A top-level Enabled switch controls scripting overall; when it is off, no hooks are dispatched even if a script is marked as enabled.
Editing a Script
Double-clicking a script (or choosing Edit) opens it in a dedicated pop-out editor built on the Monaco editor (the same editor that powers Visual Studio Code), with:
- C# syntax highlighting.
- Inline validation diagnostics (red squiggles for errors, yellow for warnings) that update as you type.
- Autocomplete suggestions (triggered by typing
.) for members available on the current expression's type. - A Save action (also available via the editor's command palette, or the Ctrl+S/Cmd+S keyboard shortcut) that validates the script before saving. The shortcut only saves when the script form is valid and has unsaved changes, and it is scoped to the script editor pop-out window - it has no effect outside that window. A script with errors cannot be saved while it is enabled without first fixing the reported errors.
The Sample Script
Every new script starts from a bundled sample template that demonstrates all the available script hooks, including OnBeforeRequest, OnBeforeResponse, OnPeekAtRequestHeaders, OnPeekAtResponseHeaders, OnSessionCompleted, OnAttach, OnDetach, OnBoot, OnShutdown, OnValidateServerCertificate, and OnWebSocketMessage. Use it as a starting point and remove the hooks you do not need.
Validation and Enabling Scripts
Before a script can be enabled or saved while active, Fiddler Everywhere:
- Parses and compiles the script.
- Runs a set of security guardrail checks (see Scripting Security Considerations).
- Confirms that every hook method is synchronous (asynchronous hook methods are rejected).
If any check fails, the script is not enabled/saved, and the editor highlights the reported errors. For more information about runtime behavior, timeouts, and how Fiddler Everywhere protects itself from a misbehaving script once it is running, see Scripting Settings and Limits.