WebSocket & SSE Tester
An online WebSocket and event-stream client — straight from your browser to your server.
Connection
Close with a code and reason
Send a message
Server-Sent Events only flow from the server to you; there is nothing to send. Use fetch() mode with POST to send a request body when connecting.
Messages
Messages and connection events appear here, newest at the bottom.
About the WebSocket & SSE Tester
Test a real-time API without writing code. Enter a WebSocket address (wss://…), optionally with subprotocols such as graphql-transport-ws, connect, and send text, JSON or binary frames (typed as hex or Base64). Every frame in both directions lands in a timestamped log with its size, which you can filter by text or regular expression, pretty-print, copy and export as JSON Lines or text. Turn on auto-reconnect with exponential back-off, or a keep-alive message that is sent at a fixed interval, and close the connection with your own close code and reason.
For Server-Sent Events, use the browser’s EventSource (simple GET, optional cookies) or the fetch() mode, which can send request headers such as Authorization, use POST with a body (as many streaming AI APIs need) and shows the HTTP status, every event type, comments and retry: hints. The connection goes straight from your browser to the server: MySmartCoPilot never sees your messages or tokens.
How to use it
- Choose WebSocket or Server-Sent Events and enter the address, e.g.
wss://echo.example.com/socketorhttps://api.example.com/events. - For WebSocket, add subprotocols if the server expects them, and tick auto-reconnect or keep-alive if you need them. For SSE, pick EventSource or fetch() and, in fetch() mode, add headers or a POST body.
- Press Connect. The status line shows the negotiated subprotocol and extensions; the log shows the connection events.
- Type a message, pick Text, JSON (checked before sending), Binary (hex) or Binary (Base64), and press Send or Ctrl+Enter.
- Filter the log by text or
/regex/, show only received or sent frames, and export it when you are done. Press Disconnect — or use Close with a code and reason.
Examples
wss://stream.example.com/ws
Send (JSON): {"type":"subscribe","channels":["ticker"]}↑ out · 46 B {"type":"subscribe","channels":["ticker"]}
↓ in · 112 B {"type":"ticker","price":"64210.5", …}Send (hex): 01 00 05 48 65 6C 6C 6F
↑ out · 8 B — sent as one binary frame
Received binary frames are shown in hex, or as text when they contain UTF-8 text.
POST https://api.example.com/v1/stream
Authorization: Bearer …
Body: {"prompt":"Hi","stream":true}HTTP 200 · text/event-stream
↓ in [message] {"delta":"Hel"}
↓ in [message] {"delta":"lo!"}Common uses
- Checking that a WebSocket server accepts connections, the right subprotocol and your messages before wiring up a front end.
- Debugging a chat, notification, trading or multiplayer back end by watching the raw frames.
- Testing a Server-Sent Events endpoint, including authenticated and POST-based streaming APIs.
- Reproducing a disconnect: reading the close code, testing auto-reconnect and keep-alive behaviour.
- Capturing a session as JSON Lines to attach to a bug report.
What a browser can and cannot do here
- Only secure addresses from this page. It is served over HTTPS, and browsers block insecure
ws://andhttp://connections from secure pages (mixed content); the page trieswss:///https://instead and tells you. To test a local server, give it a TLS certificate your browser trusts (for example with mkcert) or expose it through an HTTPS tunnel. - Origin checks and CORS. A WebSocket handshake sends this page’s
Originheader, and some servers reject unknown origins. Event streams are normal HTTP requests, so the server must allow this site with CORS (Access-Control-Allow-Origin); custom headers in fetch() mode also need a preflight. - No custom WebSocket headers. Browsers do not let pages add headers (such as Authorization) to a WebSocket handshake; servers usually take a token in the query string, a cookie, a subprotocol or the first message instead.
- No ping frames. Browsers answer the server’s ping frames automatically, but a page cannot send its own (RFC 6455 control frames are not exposed to scripts). The keep-alive sends an ordinary message of your choice, e.g.
{"type":"ping"}. - No error details. When a connection fails, browsers deliberately report only “error” and close code 1006, so the log lists the usual causes instead.
Close codes
RFC 6455 (§7.4.1) and the IANA close-code registry define the codes you will see: 1000 normal closure, 1001 going away (server restart or page left), 1002 protocol error, 1003 unsupported data, 1006 abnormal closure (no close frame — network failure, refused connection or a failed handshake; never sent by servers), 1007 invalid payload (e.g. text that is not UTF-8), 1008 policy violation, 1009 message too big, 1011 internal server error, 1012 service restart, 1013 try again later. Codes 4000–4999 are for applications to define. A page may close with 1000 or 3000–4999 only, with a reason of at most 123 bytes (WHATWG WebSockets Standard).
EventSource or fetch()?
EventSource is the browser’s built-in client: it reconnects by itself and resumes with the Last-Event-ID header, but it can only make GET requests, cannot add headers, and delivers named events (event: update) only to listeners registered for that name — list them under “Also listen for these event types”. fetch() mode reads the raw stream with the parsing rules of the HTML Standard (“Interpreting an event stream”), so it shows every event, comment line and retry: value, and it can send any method, headers and body. It reconnects only when you tick the option, sending the last event ID it saw.
Limitations
- Insecure ws:// and http:// endpoints cannot be reached from this HTTPS page (see above); use wss:// and https://.
- Other real-time protocols built on top — Socket.IO, SignalR, STOMP, MQTT over WebSocket — work only as far as you type their frames yourself; the page does not speak those protocols for you.
- The log keeps the newest 5,000 entries (and shows the newest 1,500); export earlier if you need everything from a long session.
- Messages and request headers are not saved; reloading the page ends the connection.
Privacy
The page connects directly from your browser to the address you enter — never through MySmartCoPilot. Messages, headers and tokens are not stored; only the address (without its query string) and your settings are remembered in this browser.
Frequently asked questions
Why does the connection fail immediately with code 1006?
1006 means the connection closed without a close frame, and browsers do not say why. Check the address and port, open the same host as https:// in a tab to see whether its certificate is trusted, check that the server accepts this site’s Origin and the subprotocols you listed, and look at the server’s own logs.
Can I connect to ws://localhost?
Not from this HTTPS page: browsers allow only secure WebSocket connections from secure pages, and this site’s security policy upgrades insecure ones. Run your local server with TLS (mkcert makes a trusted development certificate) and connect to wss://localhost:PORT, or use an HTTPS tunnel to it.
How do I send an authentication token?
Browsers cannot add an Authorization header to a WebSocket handshake. Use whatever your server supports: a token in the query string (wss://host/ws?token=…), a cookie for the server’s own domain, a subprotocol value, or an authentication message sent right after connecting. For Server-Sent Events, use fetch() mode and add the header.
Is my data private?
Yes. The page connects directly from your browser to the server you enter; nothing passes through MySmartCoPilot. Messages, headers and the query string of the address are not stored; only the address itself (without its query) and your settings are remembered in this browser.
What is a subprotocol?
An application protocol name agreed during the handshake (the Sec-WebSocket-Protocol header), such as graphql-transport-ws, mqtt or v12.stomp. The browser sends your list and the server picks one; the status line shows which one was chosen. If the server picks none of them, the browser closes the connection.