# Yaak: Desktop API Client for REST, GraphQL, gRPC, and WebSocket

> Yaak is an offline-first desktop API client built with Tauri and Rust that supports REST, GraphQL, gRPC, WebSocket, and Server-Sent Events on macOS, Windows, and Linux, with no telemetry and no cloud dependency.

**mountain-loop/yaak** — The most intuitive desktop API client. Organize and execute REST, GraphQL, WebSockets, Server Sent Events, and gRPC 🦬

- Repository: https://github.com/mountain-loop/yaak
- Website: https://yaak.app
- Stars: 19,272 · Forks: 823
- Language: TypeScript
- License: MIT
- Published: 2026-09-21 · Updated: 2026-09-21 · Language: en
- Canonical page: https://hysenlabs.com/projects/mountain-loop-yaak

## REST, GraphQL, gRPC, WebSocket, and SSE in One Client

Most API clients are built around HTTP request-response and treat WebSocket or gRPC as afterthoughts. Yaak treats them as first-class protocol types from the start. The client handles REST, GraphQL, gRPC, WebSocket, and Server-Sent Events (SSE) from a single interface. Engineers working on microservice architectures often switch between two or three tools to exercise the full surface of a system; Yaak reduces that to one.

Import support covers Postman, Insomnia, OpenAPI, Swagger, and Curl collections, so moving an existing workspace into Yaak does not require rebuilding requests by hand. For inspecting response payloads, Yaak provides JSONPath and XPath filters that apply directly to the response viewer. These are real extraction tools, not just search-in-page highlighting.

## The Tauri and Rust Architecture Behind Yaak

Yaak is built with Tauri, which uses a native OS WebView for the UI and a Rust binary for the application logic. The React frontend talks to the Rust backend through Tauri's IPC layer. This gives Yaak a small installation footprint compared to Electron applications, which bundle an entire Chromium instance.

The repository's Cargo.toml workspace reveals how the Rust side is split: yaak-http handles HTTP request execution, yaak-grpc handles gRPC, yaak-ws handles WebSocket, yaak-sse handles Server-Sent Events, and yaak-tls manages TLS configuration. yaak-crypto handles encrypted secrets, yaak-templates processes template tag expansion, yaak-git and yaak-sync together power filesystem-based workspace synchronization. Splitting these concerns into separate crates means changes to the HTTP layer do not touch the gRPC implementation and vice versa.

This architecture means that Yaak runs locally with no required cloud backend. Request payloads, API keys, and environment variables never leave the machine unless the user explicitly mirrors a workspace to a Git repository or Dropbox.

## Downloading Yaak and Sending a First Request

Yaak is distributed as a prebuilt binary for macOS, Windows, and Linux. The download page is at yaak.app/download; package manager options and alternative installation methods are documented in the official installation guide at yaak.app/docs/getting-started/installation. The README does not include an inline CLI install command.

Once installed, the workflow starts by creating a workspace and adding a folder for a set of related requests. Each request specifies a method, URL, headers, body, and authentication scheme. Environment variables let you define base URL, API keys, or bearer tokens once per environment and switch between dev, staging, and production profiles without editing individual requests. The response panel shows status, headers, and body, with the option to apply a JSONPath expression to pull a specific field out of a JSON response.

For gRPC, Yaak connects to a running server and loads the service definition. The gRPC crate (yaak-grpc) handles the protocol negotiation. For WebSocket, the client keeps a persistent connection open and lets you send and receive frames interactively.

## Authentication Plugins and Encrypted Secrets

Yaak ships authentication as a plugin layer rather than hard-coded logic. The plugins directory in the repository includes separate packages for auth-basic, auth-bearer, auth-jwt, auth-oauth1, auth-oauth2, auth-digest, auth-ntlm, and auth-aws. Each plugin handles its own token acquisition and request signing, and users can write custom auth plugins when none of the built-ins fit.

Sensitive values like API keys and client secrets can be marked as encrypted secrets. The yaak-crypto crate handles encryption, and secrets can be stored in the operating system keychain. This is a meaningful security boundary: a secret stored in the OS keychain does not appear in plaintext in the application database file on disk.

The trade-off is that encrypted secrets are local to the machine. If you mirror a workspace to a Git repository using filesystem sync, secrets are not included in the exported files. A teammate cloning the repository needs to supply their own credentials. The README does not document a way to share secrets across machines; that remains a manual coordination step.

## Workspaces, Filesystem Sync, and Environment Switching

Yaak organizes requests into workspaces, which can contain nested folders. This mirrors the folder structure you might use in Postman or Insomnia, and import from those tools preserves the folder hierarchy. Within a workspace, environment variables define values that change across deployment targets. Switching the active environment updates every request that references a variable, so no request needs to be edited individually when moving from a local dev server to a staging endpoint.

The filesystem mirror feature, backed by the yaak-sync and yaak-git crates, writes workspace contents to a directory you choose. The files can then be committed to a Git repository or synced via Dropbox, giving a team a shared source of truth for request collections without requiring a cloud API service. This approach has one practical limitation: conflicts must be resolved manually if two people edit the same workspace file at the same time and sync at different moments.

The MCP server plugin (in plugins-external/mcp-server) extends the template tag system with Model Context Protocol integration. The Faker plugin (plugins-external/faker) adds template tags that generate realistic test data such as names, emails, or UUIDs.

## Yaak vs Postman, Insomnia, and Bruno

Postman is a commercial SaaS API client with cloud-hosted collection storage, a hosted mock server feature, and paid team tiers. Yaak's position is the opposite: no accounts required, no data sent to Yaak's servers, and a simple license purchase for commercial use instead of a subscription.

Insomnia, now owned by Kong, shifted toward cloud synchronization in 2023, which prompted many users to look for alternatives. Yaak acknowledges this directly on its website with a dedicated comparison page. The two clients support similar protocol sets, but Insomnia's cloud sync has been a source of concern for teams that keep sensitive request data local.

Bruno stores collections as plain files in the repository from the start, making it a Git-native workflow. Yaak achieves a similar result through the filesystem mirror feature, but the underlying storage is still Yaak's own database until a mirror is created. Bruno's file format is directly readable without launching the app; Yaak's is not. For teams that want requests to live as committed files with no intermediate step, Bruno's model is more direct. Yaak's advantage is richer protocol support and a more polished desktop interface.

The README's contribution policy notes that community pull requests are currently limited to bug fixes. Feature proposals require explicit maintainer approval via the feedback tracker.

## Licensing, Beta Status, and Commercial Use

The Yaak source code is MIT licensed, which means it can be built and run for free for personal and commercial purposes. The prebuilt binaries have separate terms: free for personal use, with a license required for commercial use. The project is funded by these community-purchased licenses rather than venture capital or advertising.

As of September 2026, Yaak ships under the v2026.9.0-beta series. The beta label means breaking changes are possible before a 1.0 release. The plugin API, template tag format, and workspace file schema are areas where changes during beta could affect integrations or custom plugins. The last push to the repository was on 2026-09-28, which confirms ongoing active development.

Contributing to Yaak requires reading CONTRIBUTING.md for the policy and DEVELOPMENT.md for local setup. The maintainer, gschier, explicitly asks contributors to link a pre-approved feedback item before opening a feature pull request. Bug fixes are accepted without that requirement.

## Conclusion

Yaak suits engineers who want a locally-stored, multi-protocol API client that works offline and never sends usage data to a third party. It is the wrong choice for teams that require cloud-based collection sharing, hosted test pipelines, or real-time collaboration features. Before committing to a commercial license, verify that gRPC reflection, OAuth 2.0 flows, and filesystem sync all work as expected for your stack. The project ships beta releases under the v2026.9.0 series, so plugin APIs may still change before 1.0.

## FAQ

### What protocols does Yaak support?

Yaak supports REST, GraphQL, gRPC, WebSocket, and Server-Sent Events. It can import existing collections from Postman, Insomnia, OpenAPI, Swagger, and Curl.

### How does Yaak store and protect sensitive credentials?

Yaak can mark values as encrypted secrets, which the yaak-crypto crate encrypts before storing. Secrets can be stored in the operating system keychain. They are not exported when a workspace is mirrored to the filesystem.

### Is Yaak free for commercial use?

The source code is MIT licensed and free to build for any purpose. The prebuilt binaries are free for personal use but require a purchased license for commercial use. Licenses fund the project's development.

## Sources

- [License: MIT](https://github.com/mountain-loop/yaak/blob/main/LICENSE)
- [mountain-loop/yaak on GitHub](https://github.com/mountain-loop/yaak)
- [Project website](https://yaak.app)
- [README](https://github.com/mountain-loop/yaak/blob/main/README.md)
- [Releases](https://github.com/mountain-loop/yaak/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/mountain-loop-yaak
