| Account |
None. |
None. Source |
| Where your work lives |
A file in your app data folder, or plain YAML files in a project folder in your repo, one per request. Secret values stay in your keychain. |
Plain-text files (.bru or YAML) in a folder you choose, shared through Git. Source |
| Open source |
No. |
Yes, MIT. Source |
| Secrets |
In your OS keychain. |
Secret variables stay on your machine, encrypted with OS-level encryption; secret managers on the Ultimate plan. Source |
| Protocols |
REST, GraphQL, gRPC, server-sent events, MCP. |
REST, GraphQL, gRPC, WebSocket, server-sent events. |
| gRPC protos |
Fetched from your proto repo and kept in sync (Buf workspaces too), FieldMask picker, warnings when the server sends fields your protos don't define. |
Server reflection, or .proto files on disk. Source |
| MCP servers |
Inspector: connect over stdio or HTTP, call tools, read resources and prompts, see every message. |
Not supported yet (an open feature request). Source |
| AI chat endpoints |
Chat view: replies streamed from OpenAI, Anthropic and Vercel AI SDK formats, with time to first token and tokens per second. |
Server-sent events shown as they arrive. Source |
| Chaining and checks |
Flows: steps use earlier responses ({{step1.id}}), with checks, repeats, inputs, and script steps in Python, JavaScript, Ruby, Bash or any command. A notebook or a canvas. |
Variables, declarative assertions, and JavaScript scripts and tests. Source |
| Running in CI |
The ofcors command runs flows and requests, with JSON output and exit codes. No JUnit or HTML reports yet. |
bru CLI with JUnit and HTML reports, and a GitHub Action. Source |
| Expiring tokens |
Any login request can feed a token variable; refreshed when it expires, retried once on a 401. |
OAuth 2 with automatic refresh; other logins through scripts. Source |
| The app |
Native: a Rust core in a Tauri shell. |
Electron. Source |