---
url: https://blog.ogmabox.com/ogma-vs-caido.md
description: >-
  Compare Ogma and Caido for everyday web security testing, including free-tier
  access, AI assistants, workflows, API testing, scanning, and MCP integration.
---

# Ogma vs Caido

Ogma and Caido share a traffic-first approach to web security testing: capture a request, understand it, change it, and follow the result. Both use Rust in their backend and provide HTTP history, interception, replay, and automation. The useful comparison is not which tool has more tabs, but what you can accomplish without extra subscriptions, plugins, or setup.

**Ogma pairs lightweight design with a broad included toolkit.** The desktop application brings together manual testing, workflows, scanning, discovery, browser interaction, and an embedded MCP server. Its AI assistant is available without an Ogma subscription. Caido also emphasizes a lightweight Rust architecture; the more useful distinction is which tools are built in, which require plugins, and which need a paid plan.

## At a glance

| Capability | Ogma | Caido |
|---|---|---|
| Core interception and replay | Included | Included in Basic |
| Built-in AI assistant | Included; configure your own provider | Not included in Basic; paid Assistant |
| Project and workflow access | No paid-tier quota | Basic: 2 projects, 7 workflows |
| HTTP filtering | HTTPQL, presets, and Search | HTTPQL, presets, and Search |
| Payload-based testing | Native Automate | Native Automate |
| WebSocket testing | History, interception, dedicated WS Replay | Native WebSocket history and interception |
| Workflow automation | Passive, active, and convert graphs | Native workflow graphs |
| Vulnerability scanning | Built-in passive and active engines | Community Scanner plugin |
| Hidden-path discovery | Dedicated discovery tool | Automate wordlists and community crawler |
| Out-of-band testing | Built-in HTTP, HTTPS, DNS, SMTP listeners | Community integrations |
| External AI agents | Embedded MCP server | Community MCP server |
| Timing-sensitive tests | Dedicated Race tool, including HTTP/2 mode | Replay Pipelines |

Caido's tier information comes from its [plan comparison](https://www.caido.io/pricing/). Its [tool mapping](https://docs.caido.io/burp-suite/core/tools) distinguishes native features from community extensions, and its [scanning documentation](https://docs.caido.io/burp-suite/core/scans) describes the Scanner plugin. The difference is integration and access, not that Caido cannot perform these tasks.

## Free access and the AI assistant

**Caido Basic does not include the built-in Assistant. Ogma includes its assistant interface without a paid Ogma plan.** Caido documents Assistant access for Individual and Team subscriptions; it can explain traffic and help with attack ideas and proof-of-concept generation. [Caido Assistant](https://docs.caido.io/app/quickstart/assistant).

Ogma's Ask Bob assistant works alongside request inspection and editing. Provider configuration includes Anthropic, OpenAI, Google, OpenRouter, and a custom OpenAI-compatible endpoint. You choose the provider and credentials rather than purchasing an Ogma AI add-on.

Included integration does not mean unlimited free inference: a hosted provider may charge for API usage. Likewise, connecting an external AI client through MCP has its own model and account requirements. Ordinary interception, replay, and workflows do not require an AI provider.

For someone learning security testing or working independently, this means the assistant can be part of the same workspace as the scanner and automation tools from the start. For a team already using Caido, its paid offering may fit existing purchasing and support arrangements better.

## When a compact setup starts to grow

Caido Basic limits projects, workflows, plugins, saved filters, and simultaneous pipeline sessions; creating project backups also requires a paid plan. Those boundaries can become relevant as you keep more targets and reusable testing routines. Ogma's desktop projects, workflow library, and project archives are not gated by a paid feature tier. [Caido plan limits](https://www.caido.io/pricing/).

There is also a difference between extending a toolkit and assembling the tools you need before testing. Caido offers a community Scanner, crawler, and OAST integrations. Ogma includes targeted scanning, content discovery, and callback listeners in the application. If those are regular parts of an assessment, they are available without first choosing and configuring separate plugin packages. Plugins remain useful in both products for specialized tasks. [Caido scanning options](https://docs.caido.io/burp-suite/core/scans), [Caido tool mapping](https://docs.caido.io/burp-suite/core/tools).

Consider an ordinary sequence: find an API endpoint, replay it, run a focused check, save supporting evidence, and prepare a report. Ogma keeps those steps in one workspace. That is a convenience for a tester who wants a ready-to-use toolset, not a claim that extensions are inherently worse or that every built-in check matches Burp's scanner depth.

## Daily testing: history, replay, and live traffic

Ogma combines HTTPQL filtering, saved filters, Search, and a virtualized HTTP History table. Inspect request and response data, select interesting entries, and send them directly to Replay, Automate, or an active workflow. A workflow can process selected assets without rewriting its own filters for every target.

Replay keeps collections and individual attempts, including the request sent for each attempt. Structured editing supports convenient payload inspection; Raw and Hex modes preserve HTTP/1.x bytes for malformed-request testing rather than silently repairing framing. These exact-byte modes intentionally bypass normal request transformations. [Ogma Replay](https://docs.ogmabox.com/app/replay).

Caido also records replay attempts and integrates environment variables and workflow placeholders into request editing. Those are meaningful capabilities, not paid-scanner substitutes. [Caido Replay](https://docs.caido.io/app/quickstart/replay), [workflows in Replay](https://docs.caido.io/app/guides/replay_workflows).

Ogma adds separate WebSocket and SSE histories, StreamQL filtering, and a dedicated WebSocket Replay conversation view. You can reconnect, edit a message, send it, and inspect subsequent replies. Managed Socket.IO mode handles supported Engine.IO 4 / Socket.IO 3-4 control exchanges; raw mode remains available for other protocols. Neither mode can regenerate an application's signed tokens or bypass its authentication rules. [Ogma WebSocket Replay](https://docs.ogmabox.com/app/ws-replay).

## Workflows that can become reusable tools

Both products offer visual workflow automation. Caido documents multi-step conversions and actions, JavaScript and Shell nodes, and authentication-refresh examples. [Caido Workflows](https://docs.caido.io/app/quickstart/workflows).

Ogma's passive workflows inspect captured traffic, active workflows perform explicit actions, and convert workflows transform values. Definitions are workspace-shared by default, with a project-specific option. HTTP fixtures let you test active and passive workflows; convert workflows have their own test input. Runs and logs can be enabled when diagnosing a problem and disabled for high-volume processing.

A practical example is exporting interesting JavaScript assets. Match & Replace can filter traffic with HTTPQL and pass the full response body to a convert workflow. An active workflow can save assets through `sdk.fs.writeFile`, use `sdk.fs.exists` to avoid overwriting, and assemble paths through `sdk.path.join`. These are supported SDK methods, not a promise that every Node.js module works unchanged. [Ogma Workflows](https://docs.ogmabox.com/app/workflows), [Match & Replace](https://docs.ogmabox.com/app/match-replace), [backend SDK](https://docs.ogmabox.com/plugins/backend-sdk).

## Scanning, discovery, and API coverage

Ogma includes passive analysis and targeted active checks. The current active engine covers SQL injection, reflected XSS, path traversal, command injection, SSTI, SSRF, open redirect, XXE, and insecure upload. Findings link back to the supporting traffic. Detection remains something to validate, especially for timing-based or reflection-based results; a category name is not a guarantee of complete coverage. [Ogma Scanner](https://docs.ogmabox.com/app/utilities/scanner).

Caido's community Scanner supports active and passive testing and custom checks. It is inaccurate to say Caido has no scanning capability; the difference is that Ogma includes the engine in the application rather than requiring that plugin. [Caido Scans](https://docs.caido.io/burp-suite/core/scans).

Ogma's API importer generates Replay requests from self-contained OpenAPI 3.x documents, Postman collections, GraphQL introspection results, and WSDL. It handles request-body examples or schema-derived values, supported parameters and authentication templates, and typed insertion-point metadata. OpenAPI server variables and internal references are supported; external references are not fetched. Generated requests still need valid credentials and meaningful application-specific values. [Ogma API import](https://docs.ogmabox.com/app/replay#importing-api-definitions).

Dedicated content discovery and extracted-endpoint views complement the sitemap. This is useful when the captured browser traffic is only part of the attack surface: inspect observed routes, generate requests from a definition, then probe paths with a wordlist. It is not a claim that discovery can infer every business-logic path.

## Browser sessions and external agents

Ogma embeds its browser in the desktop workspace. Its MCP tools can inspect accessible page elements, fill multiple fields, click, wait for an expected result, and collect bounded snapshots or changes-only updates. Login journeys provide reusable steps, verification through URL, DOM, cookies, or a request, and manual MFA checkpoints. Multiple role-labelled journeys help organize identity-based testing; authorization decisions still need explicit tests. [Ogma Browser](https://docs.ogmabox.com/app/browser).

The MCP integration also covers captured traffic, findings, Replay, workflows, and WebSocket replay transcripts. Checkpoints, activity history, and resume tools help an agent recover project context after a long session or handoff. Agents can discover relevant contracts rather than rely on a static list of tool names.

Caido has a community MCP server documented on its own site, providing access to traffic, replay, findings, projects, and other operations. Caido explicitly distinguishes it from an officially affiliated server. Ogma's difference is that MCP is part of its own backend. [Caido MCP tutorial](https://docs.caido.io/app/tutorials/mcp).

## Specialized testing and reporting

Ogma includes Race, Decoder recipes, Comparer, JWT tools, token analysis, and OAST. Its callback listeners need a reachable domain and suitable network routing when the target is remote; starting a local listener alone does not make it reachable from the internet. [Ogma OAST](https://docs.ogmabox.com/app/utilities/oast).

Caido's Replay Pipelines support sequential execution, last-byte synchronization, and HTTP/2 single-packet attacks. This is a real native option for race testing, not something available only through plugins. [Caido Replay Pipelines](https://docs.caido.io/app/guides/replay_test_race_conditions).

Ogma keeps findings, notes, replay sessions, and captured traffic associated with projects. Export traffic as HAR, JSON, CSV, or raw HTTP according to the relevant view. Findings support HTML and Markdown reports, with a print-to-PDF path, so a tester can prepare a readable handoff without first building an external reporting pipeline. Project archives support moving project data between installations; workspace-shared workflows are exported separately. [Ogma Exports](https://docs.ogmabox.com/app/exports).

Caido provides native Findings and traffic exports, but its documentation directs users to external reporting tools or integrations rather than built-in formatted HTML/XML report generation. This distinction matters when the deliverable is a readable assessment report, not just a traffic archive. Ogma's reporting should not be confused with Burp's XML scan-report format. [Caido reporting](https://docs.caido.io/burp-suite/core/reporting).

## Performance and the right choice

Ogma uses an asynchronous Rust backend, SQLite project storage, Vue, and an Electron desktop shell. Virtualized traffic rendering and on-demand detail loading are intended to keep ordinary inspection responsive as history grows. For a laptop or VM workflow, avoiding unnecessary rendering and body loading is a meaningful design priority.

Caido also positions itself as a lightweight Rust alternative to Burp. Performance is therefore a shared design goal, not a defensible reason to describe Caido as heavy. Ogma's stronger distinction here is the breadth of its included tools and fewer paid-tier boundaries. Electron and the embedded browser still consume resources, and a speed or memory ranking would require testing the same traffic, settings, plugins, and hardware. [Caido's architecture positioning](https://www.caido.io/compare/burpsuite/).

Choose **Ogma** when you want a broad included toolkit, assistant access without an Ogma subscription, reusable workflows, built-in scanning, and first-party MCP/browser integration.

Choose **Caido** when its interface and plugin ecosystem suit your workflow, or you need its paid shared-instance and licensing options. Its free core remains a capable manual-testing workspace; the Assistant and tier limits are the distinctions to consider. [Caido plans](https://www.caido.io/pricing/).

**Last reviewed: October 3, 2026.** Ogma capabilities were checked against the current application code; competitor capabilities were checked against the official sources linked above.
