Open-source project
putyy/res-downloader avatar
putyy/res-downloader

putyy/res-downloader: a Go + Wails proxy sniffer for WeChat Channels, Douyin and Xiaohongshu media

视频号、小程序、抖音、快手、小红书、直播流、m3u8、酷狗、QQ音乐等常见网络资源下载!

20,310 stars2,522 forksGoApache-2.0

At a glance

What is it?
res-downloader is a cross-platform desktop tool that intercepts traffic through a local proxy on 127.0.0.1:8899 and lists downloadable video, audio, image and m3u8 resources. It is built for people who want the output of Fiddler or Charles without reading a packet log.
Who is it for?
Adopt res-downloader if you already understand that it is a local MITM proxy and you want a filtered resource list instead of a raw packet capture, and if a beta release with a maintainer who says maintenance time is limited is acceptable to you. Do not adopt it if you need a documented headless CLI, a stable non-beta release, or an Android build; the README points Win7 users at 2.3.0 and the repository ships desktop binaries only.
Can I use it commercially?
Yes. Apache-2.0 is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 2 days ago.
What is it written in?
Mainly Go, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The problem res-downloader solves, and who it is actually for

Media served inside WeChat Channels, mini programs, Douyin, Kuaishou, Xiaohongshu, Kugou and QQ Music is not usually offered as a download link. The bytes travel over HTTPS and the page gives you a player, not a file. The README states the tool works by acting as a proxy to capture network traffic and filter usable resources, and that it is similar in principle to Fiddler, Charles and browser DevTools but presents the results in a friendlier form. That sentence is the whole product thesis: the packet capture already existed, the filtering and the interface did not.

The intended audience is therefore not a backend engineer. The README's own walkthrough is written for someone who opens an app, clicks a button labelled 启动代理, then goes to the external page in a normal browser and comes back to a list. Someone comfortable with mitmproxy would find the filtering layer redundant. Someone who has never installed a root certificate will find the certificate step the hardest part of the whole process, and the README treats it as a one-line precondition rather than a topic.

How the proxy interception and resource filtering work

The repository layout makes the architecture legible without running anything. main.go and wails.json sit at the top level, core/ holds the Go logic, frontend/ holds the UI that Wails embeds, and build/ holds packaging assets. The go.mod file shows github.com/elazarl/goproxy v1.7.2 as a direct dependency, which is the HTTP proxy implementation, and github.com/wailsapp/wails/v2 v2.12.0, which binds the Go backend to a webview frontend. Logging goes through github.com/rs/zerolog, and github.com/vrischmann/userdir is used to locate platform directories, which is consistent with a tool that writes configuration and downloaded files into per-user locations.

So the data flow is: the app starts a local proxy, the operating system is pointed at it, requests from the browser or the desktop client pass through goproxy, the core package inspects them and decides which responses look like media, and the matches are pushed to the frontend list. The README does not document the matching rules, so what counts as a usable resource is not something you can predict from the documentation. The default listening address is given in the troubleshooting section as 127.0.0.1 with port 8899, and that same entry is the first thing to check when the software fails to intercept anything.

One design consequence is worth naming. Because interception happens at the proxy layer, the tool is protocol-agnostic in a way a per-site scraper is not: anything the machine requests through that proxy can be examined. That is also why the README can list seven unrelated platforms without seven separate integrations. It is a strength and it is the reason the certificate step is unavoidable.

Installing res-downloader and capturing a first resource

There is no package manager install. The README lists GitHub releases as the primary download and a Lanzou cloud mirror with the password 9vs5 as an alternative, and it notes that Win7 users should download version 2.3.0. The Electron-based older version lives on the old branch, and a separate repository, putyy/resd-mini, is described as a Mini version that renders its UI in the default browser.

The first step is the one people skip. The README says that during installation you must allow the certificate file and allow network access. Nothing else works if that is refused, because the proxy cannot read HTTPS without it.

After launching, the sequence in the README is: click 启动代理 in the top left of the home page, choose which resource types to capture (the default is all of them), open the resource page in an external application, then return to the home page to see the list.

If the list stays empty, the README's diagnostic is to confirm the system proxy is set correctly. The address it gives is 127.0.0.1 and the port is 8899. That pair appears in the README's FAQ rather than in an installation section, which is a documentation gap: it is the single value you need when anything goes wrong, and it is filed under a question instead of under setup.

For m3u8 resources the README does not download the stream itself. It points to m3u8play for online preview and m3u8-down for downloading, and for live streams it recommends recording with OBS. For slow downloads or large files that fail, it recommends Neat Download Manager or Motrix. For WeChat Channels material specifically, the README says that after downloading you can click 视频解密(视频号) in the action column. That decryption step is a real part of the workflow and it only applies to that one platform.

Where res-downloader breaks, and when it is the wrong tool

The certificate is the first failure mode and the most consequential. A local proxy that terminates TLS requires a trusted root certificate on the machine. The README asks for it in a single bullet and does not describe what happens on a machine with certificate pinning, a corporate TLS inspection appliance, or a browser that ships its own trust store. Those environments can defeat the interception entirely, and the README offers no guidance for them.

The second failure mode is the one the README documents directly: closing the software can leave the system without internet access, and the fix it gives is to turn the system proxy setting off by hand. That is a rough edge, not a bug report, but it means the tool takes over a machine-wide setting and does not always hand it back cleanly.

The third is scope. The README's FAQ sends m3u8 downloads, live stream recording and large-file transfers to other programs. res-downloader finds resources; it is not a download manager and does not claim to be one. If your actual problem is transferring a 4 GB file reliably, the tool you want is the one the README names, not this one.

Finally, the project status section is candid: the maintainer writes that personal matters have limited the time available for maintenance, so issue replies, PR review and releases may be slower than before, and community contributions are welcome. The last push was on 2026-09-19, and the most recent releases are 4.0.0-beta.5 from 2026-09-14, 4.0.0-beta.4 from 2026-09-08 and 4.0.0-beta.3 from 2026-09-01. The current line is beta. If you need a version with a settled interface, the README's own pointer to 2.3.0 for Win7 is the closest thing to a stability recommendation it makes.

res-downloader compared with mitmproxy and yt-dlp

The honest comparison is with mitmproxy, because the README already admits the mechanism is the same. mitmproxy gives you a scriptable Python addon API, a console interface and a replay facility, and it expects you to write the filter that decides which flows matter. res-downloader ships that filter as a GUI and gives you no scripting surface. The trade is expressiveness for time to first result. If you need to capture a flow, mutate it and replay it, res-downloader is the wrong layer.

yt-dlp is a different kind of alternative. It is a command-line extractor with per-site logic, so it does not need a system proxy or a root certificate, and it can be scheduled and scripted. It also only works on sites someone has written an extractor for, and the platforms named in this README are not the ones yt-dlp is built around. The difference is architectural: yt-dlp knows the sites, res-downloader knows the traffic. That is why res-downloader covers mini programs and in-app players that no extractor targets, and why it cannot be automated the way yt-dlp can.

Licence, upgrade cost and what the repository does not promise

The project is Apache-2.0, which permits commercial use, modification and redistribution provided the licence and notices are preserved and any modified files carry prominent change notices. The README's own disclaimer is narrower than the licence and contradicts it in spirit: it states the software is for study and research only, forbids commercial or illegal use, and disclaims liability. A disclaimer in a README is not a licence term, and nothing here is legal advice, but the gap between an Apache-2.0 grant and a README that says study only is worth reading before you build anything on top of it.

The upgrade cost is the beta cadence. Three beta releases landed in September 2026 alone, which means the surface is still moving and a pinned version is the safer choice if you depend on the workflow. Because the app writes a system proxy setting and installs a certificate, upgrading is not a pure file swap: you should expect to re-check the proxy state and the certificate after an update. The README does not document an upgrade path or a rollback procedure, so there is nothing to follow there.

Editorial conclusion

Adopt res-downloader if you already understand that it is a local MITM proxy and you want a filtered resource list instead of a raw packet capture, and if a beta release with a maintainer who says maintenance time is limited is acceptable to you. Do not adopt it if you need a documented headless CLI, a stable non-beta release, or an Android build; the README points Win7 users at 2.3.0 and the repository ships desktop binaries only. Verify two things before relying on it: that your system trusts the certificate the installer asks you to allow, and that you can turn the system proxy back off by hand, because the README's own troubleshooting entry for losing internet access after closing the app is to disable the system proxy setting manually.

Frequently asked questions

How do I use res-downloader to capture a resource?

Install it allowing the certificate and network access, open the app and click 启动代理 in the top left of the home page, choose the resource types you want (all by default), open the resource page in an external application, then return to the home page to see the list.

Is res-downloader safe to use?

It works as a local proxy that captures network traffic, which is the same mechanism as Fiddler, Charles and browser DevTools, and it requires you to allow a certificate file and network access during installation. The README states it is for study and research only and disclaims liability for other uses.

Do you have to pay for res-downloader?

The README lists downloads through GitHub releases and a Lanzou cloud mirror with the password 9vs5, and does not describe a paid tier or a licence key.

Is a video downloader legal?

The README does not answer this. It states only that the software is for study and research, that commercial or illegal use is forbidden, and that the author accepts no liability for legal consequences.

Official sources

  1. License: Apache-2.0
  2. Project website
  3. putyy/res-downloader on GitHub
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/putyy-res-downloader.svg)](https://hysenlabs.com/projects/putyy-res-downloader)