Paste a request.
Watch it go .
Your third-party API mocks are probably wrong. Stubsmith records how the API really behaves, failures included, and turns that into deterministic integration tests. Every value is masked fail-closed before it leaves your process, so only the fields you explicitly keep ever reach us. The playground below runs entirely in this page, on your machine. Nothing is sent anywhere.
Start free →Capture runs through the Python SDK today, and the SDK is open source. Node, Go and Java come later.
This playground demonstrates the email, UUID and card substitutions. In the SDK they are opt-in: set STUBSMITH_MASK_SALT and give the field's mask rule a type. Without that, every string collapses to <masked>, every number to 0 and every boolean to false.
Masked values keep their type
Every value becomes a placeholder of the same type: a string <masked>, a number 0, a boolean false. Opt in to shape-preserving placeholders and a masked value keeps its format too: a UUID stays a parseable UUID, a timestamp stays ISO 8601, an amount stays a non-zero decimal, and a stub then parses and routes the way the real payload did.
Fields your tests branch on need a keep rule
A masked status or error.code is a synthetic token that tells a test nothing, and for the smallest value spaces, a currency code, a country code, a boolean, the SDK will not generate a lookalike at all, because a handful of candidates is a lookup table. So keep them on purpose. You review the field names, approve the keep rule, and those values arrive as sent. Everything you did not name stays masked.
The fingerprint is real
Method and path template, plus a blake2b-64 digest over the request's sorted key-paths, query names and content type. By default no value is an input; opt a field in as a variant key and only that value joins the hash. The Fingerprint tab shows exactly what goes in.
How it works
From real traffic to test fixtures in four steps, with privacy preserved throughout.
Capture real traffic
Add the Stubsmith Python SDK to your service with a single line. It intercepts outbound HTTP calls and records request/response pairs into a local capture buffer. Python is the only language with capture support today.
SDK masks at the edge, before data leaves
Before a byte leaves your infrastructure, the SDK applies your masking rules. Unless a keep rule explicitly permits a value through, every value is replaced with a placeholder of the same type: strings become
<masked>, numbers become 0, booleans become false. What leaves your process is masked structure, not content.Stubsmith stores masked samples and fingerprints
Stubsmith persists the masked body and a structural fingerprint of the request/response shape. The fingerprint contains no payload data, only enough structure to detect duplicates and organize stubs.
Generate stubs, fixtures, and replay in CI
Export stubs as OpenAPI, JSON fixtures, WireMock mappings, or MSW handlers. Wire them into your test suite and replay against your CI pipeline. No live API calls needed, no token leaks, deterministic results.
Built for the privacy-conscious team
Every design decision starts with the question: what happens to production data?
Edge masking, before data leaves
Masking runs in the SDK, inside your own infrastructure. Stubsmith's servers receive masked bodies and field names. The only raw values that ever arrive are the ones you reviewed and gave a keep rule; by default, there are none.
Stubs from real traffic
Capture the APIs your service actually calls, not an approximation. Stubs reflect real schemas, status codes, and error shapes, including the failures you cannot reproduce on demand.
Fingerprint deduplication
Stubsmith deduplicates traffic by structural fingerprint, so you get one canonical stub per API shape, not thousands of near-identical captures.
EU-sovereign hosting
Hosted on UpCloud and Scaleway, with all data stored in Amsterdam, NL.
Privacy stance
We don't want your customers' data
Most API tools process production traffic on their servers. Stubsmith is built around the opposite premise: your users' personal data should never reach us in the first place.
Masked before it leaves
The SDK replaces every value with a placeholder of the same type inside your own infrastructure: a string becomes
<masked>, a number 0, a boolean false. Enable shape-preserving placeholders and an email becomes a synthetic address on your placeholder domain instead. Masking runs before any network call is made.Structure, plus only what you keep
Stubsmith's servers receive masked bodies and field names. We see that you have a field called
receipt_emailof type string. We never see the email address it contained, unless you approve a keep rule for that exact field.Fail-closed by default
Every unknown value is masked. A new field in an API response is masked until you explicitly add a keep rule for it. The conservative path is the automatic path, which is why the handful of fields your tests assert on are a deliberate decision you make once, per field.
The test-fixture problem has a privacy problem
Most teams solve the test-fixture problem by copying production data. That copies PII, credentials, and confidential payloads into developer laptops, CI logs, and staging databases, where they stay indefinitely.
Stubsmith's approach is different: masking happens at the SDK, before the data leaves your network. The server sees structure and masked values, not content. Your stubs are accurate without your users' personal data ever reaching our infrastructure.
If you already record with VCR.py or pytest-recording, this is the same replay model without the cassettes. Their filters are opt-in and fail open, so one field you forgot to enumerate lands in version control. Here the recording is masked before it is written, and the only values that survive are the ones you named. See how the tools compare.
- No production data in CI. Masked values contain no useful information. Types are preserved; content is replaced before anything leaves your process.
- Accurate stubs, not hand-crafted mocks. Generated from the real API, so schema drift is caught at the next record cycle, not six months later in a prod incident.
- Retention windows, not indefinite storage. Stubsmith keeps a fixed number of recent samples per response variant, set by your plan, and deletes older ones as new ones arrive. Nothing expires on a clock. Fingerprints and stubs are yours to keep.
Frequently asked questions
- Does Stubsmith see my API request/response bodies?
- Not unless you ask us to. The SDK masks every request and response body fail-closed: values are replaced with typed placeholders before anything leaves your infrastructure. Stubsmith receives masked bodies and field names. The only values that arrive in the clear are those on fields you reviewed and gave a keep rule, and by default there are none.
- If everything is masked, will my tests still exercise the right code paths?
- Only for the fields you keep, and that is the deliberate part. Default masking wipes the values a test branches on: a status, an error code, a currency, a flag. Masking them is no help either. A masked status becomes a synthetic token that tells a test nothing, and for the smallest value spaces, a currency code, a country code, a boolean, the SDK refuses to generate a lookalike at all, because a handful of candidates is a lookup table for anyone holding the output. So you keep them on purpose: open the fingerprint, review the field names, and approve a keep rule for each scalar your tests assert on. Everything you did not name stays masked, and a new field that appears later is masked until you decide otherwise.
- What's a fingerprint?
- A fingerprint is a structural signature of a request/response shape: the method and path template plus a digest over the sorted key-paths, query-parameter names and content type of the request. Values are not an input unless you opt a specific field in as a variant key. Path segments that look like identifiers are collapsed into a template, so /v1/charges/ch_123 and /v1/charges/ch_456 are one shape, not two. Optional fields are a different matter: a request carrying an extra query parameter is a different shape, so an endpoint with several optional filters can produce several fingerprints. Stubsmith deduplicates traffic by fingerprint and caps them per plan. At the cap, new shapes are no longer stored and you get a clear error and a dashboard banner, while existing fingerprints keep capturing. Fingerprints are never deleted by us; they are your durable asset.
- How long are samples kept?
- Stubsmith keeps a rolling window of the most recent masked samples for each distinct response a request shape returns: 3 per response variant (Free), 5 (Solo), 10 (Team), 25 (Business). Older samples are deleted as newer ones arrive, so the window is bounded by count rather than by age: an endpoint you exercise once a quarter keeps its samples, and a high-traffic one cannot crowd out a rare error response. Fingerprints, request types, and generated stubs are kept indefinitely; they are the output, not temporary data.
- Where is my data hosted?
- All infrastructure runs in the EU. Compute is on UpCloud infrastructure in Amsterdam (nl-ams); the database is UpCloud Managed PostgreSQL in the same region. UpCloud is a Finnish company. Object storage is on Scaleway in Amsterdam. No data transits to US-based services.
- How does billing and VAT work?
- Prices are shown including VAT by default. Checkout and billing run through Creem, our merchant of record: Creem is the seller of record, charges the VAT that applies to your billing country, remits it, and emails your receipt. You can cancel any time from the dashboard. Annual plans are available at a discount.
Start with the free plan
One project, 50 fingerprints, no credit card required. Evaluate the full flow on a single service.