mrkeyoor.com_
Wed 30 Sept 03:05 UTC
Dev Toolsevaluationupdated 30 Sept 2026

keploy review

Keploy records an application's network traffic and turns the calls into API tests and dependency mocks. It watches HTTP, databases, queues, and other protocols through eBPF, letting a team replay realistic integration flows without adding a Keploy SDK to the application.

Verdict

Our Keploy run passed all 132 Go tests after an 86-second install and 194-second build, giving the repository a stronger baseline than most traffic-recording tools we test. Use it when replacing a web of live databases, queues, and APIs with recorded integration fixtures would save real CI time. Keep independent assertions around critical flows, especially gRPC, and prove the eBPF permissions on the same runner you will use in production CI.

We ran it

Lab card: what happened when we ran keployScreenshot of keploy (keploy.io)
Install✓ · 86s802 packages
Build✓ · 194s
Tests✓ · 271s132 passed · 0 failed of 132 (go test)
Repo1100 files~300,198 lines of source · 12.9 MB · 52 CI workflows · Dockerfile · tests dir

Answers from our run

Does keploy build from source?

Dependencies installed in 86 seconds (802 packages), and the build succeeded in 194 seconds. We cloned commit 037dcfd into a clean Debian container with 3 CPUs and no project-specific setup.

Do keploy's tests pass?

Yes: 132 of 132 passed when we ran the project's own test command (go test). Some failures need services or credentials a bare container does not have.

Who should not use keploy?

Locked-down runners that cannot attach eBPF programs or expose tracepoints: open issue 3832 documents capture failing in an unprivileged Docker container without the required capabilities.

What are the alternatives to keploy?

WireMock, Hoverfly, Testcontainers for Java. Our Keploy run passed all 132 Go tests after an 86-second install and 194-second build, giving the repository a stronger baseline than most traffic-recording tools we test.

Setup3/5Build and tests pass, while eBPF makes host setup consequential
Docs4/5Clear record and replay path with protocol and CI guidance
Community5/518,509 stars, a September 29 push, and same-day release
Maturity4/5132 tests passed, but replay and CLI correctness issues remain

Who it’s for

Backend teams that want integration tests from traffic their application already handles.
Developers who need database, queue, and external-API mocks alongside HTTP tests.
Go, Java, Node.js, Python, or other stacks where a language-specific recorder would be awkward.
CI teams willing to validate Keploy's matchers and grant the capture process the required host access.

Who it’s NOT for

Locked-down runners that cannot attach eBPF programs or expose tracepoints: open issue 3832 documents capture failing in an unprivileged Docker container without the required capabilities.
Teams that need every gRPC assertion enforced today: open issue 4609 reports that replay ignores the assertion field for gRPC cases.
CI pipelines that rely on utility-command exit codes without checking output: open issue 4531 reports sanitize, normalize, templatize, export, and import returning status 0 after errors.
Organizations whose policy forbids recording real request, database, or queue payloads into test fixtures.
Projects that only need a small HTTP stub server and do not want a network-capture agent around the application.

Setup reality

Our sandbox installed commit 037dcfd in 86 seconds, covering 802 packages. The build succeeded in 194 seconds, and go test finished in 271 seconds with 132 passed and 0 failed out of 132.

The quick start installs a Keploy agent, then starts your application through keploy record and keploy test. Useful recordings require real application traffic and the dependencies you want captured. CI also needs a place to keep generated tests and mocks.

Keploy's eBPF approach avoids application code changes but moves setup into the host. Restricted containers may need extra capabilities or a different execution model. Our unprivileged lab run verified installation, compilation, and repository tests; it did not attach Keploy to a sample application or record traffic.

The 132 passing tests cover the recorder's repository

Keploy's 132 passing repository tests sit behind a simple promise: put the agent around an application, exercise real API paths, then keep the resulting calls as tests and dependency mocks. Its eBPF capture works at the network layer, so the application does not need a Keploy SDK. The README says it can record HTTP, database traffic, Kafka, RabbitMQ, and other dependencies. That makes it broader than a mock HTTP server and potentially more useful for integration suites that currently need a crowded Docker Compose file.

Our repository run passed all 132 Go tests, which is a solid result for the recorder's own code. It does not prove that your service's protocol mix will replay correctly. A captured test contains assumptions about matching, ordering, time, and which fields may vary. Keploy can freeze time and supply generated mocks, but a team still has to inspect the first recordings and decide whether a passing replay represents the business behavior it cares about.

An 802-package install led to a clean build

Our fresh Debian sandbox installed commit 037dcfd in 86 seconds and covered 802 packages. Compilation took 194 seconds. The checkout itself contained 1,100 files, about 300,198 lines of source, and occupied 12.9 MB. That is a substantial Go project, yet the setup did not stall or require secrets. The repository also had a Dockerfile, a tests directory, and 52 CI workflow files in our scan.

The quick start is shorter than the operating setup. You install the agent, launch the application through keploy record, send traffic, and later run it through keploy test. Those commands need the application command, its reachable dependencies during capture, and storage for generated YAML tests and mocks. A developer can try that locally. CI adoption also needs fixture review, stable paths, artifact retention, and a policy for refreshing recordings when an API intentionally changes.

What happened when we ran it

Our run built Keploy successfully in 194 seconds, then go test completed in 271 seconds with 132 passed and 0 failed out of 132. The sandbox had 3 CPUs, 8 GB of RAM, Go 1.24 on Debian, no secrets, and no elevated privileges. Installation had already succeeded in 86 seconds. Our test method covered repository setup, compilation, and its Go suite, not end-to-end traffic capture.

We did not grant the container eBPF capabilities, start a sample API under Keploy, or replay calls against Postgres, Kafka, or RabbitMQ. That boundary matters because the product's value begins where our repository test stops. The clean 132-test result earns confidence in the codebase, while protocol behavior and host permissions still need a pilot on the target environment. A one-service trial with a known failure is more useful than recording a large production trace first.

Open v3 reports put matcher output under scrutiny

Keploy v3.6.82 shipped on September 29, 2026, with a fix that keeps mocks after a partial or unanswered replay. Nearby open issues show why replay output deserves careful reading. Issue 4636 reports a case where the printed Testrun passed banner can disagree with the assertion verdict returned by the matcher. A related open pull request exists, but the issue remained open when checked.

The gRPC path has a more direct gap. Open issue 4609 says test-case assertions are decoded but not read by the gRPC matcher, so a case can pass regardless of the assertion values. HTTP users have a different concern: issue 4531 reports that five utility commands can log an error and still exit with status 0. Until those reports close in a release you have verified, CI should check machine-readable results or artifacts rather than trusting one banner or shell status.

Host access can stop capture before matching begins. Open issue 3832 shows Keploy v2.5.2 failing to attach tracepoints inside an unprivileged Docker container without CAP_BPF, CAP_NET_ADMIN, or CAP_SYS_ADMIN. It is an older report, so it does not prove every current container needs that exact capability set. It does prove that eBPF changes the deployment conversation. Test the current release under your runner's real security profile instead of assuming a successful binary install settles it.

The September 29 release shows an actively changing tool

GitHub listed 18,509 stars and 759 open issues and pull requests on September 30, 2026. The repository was pushed on September 29, the same day v3.6.82 was released. Current issues and pull requests were also active that week, including fixes around matcher verdicts, Postman import, and replay behavior. Keploy is being maintained quickly, which is reassuring for a low-level recorder but makes version pinning important.

Choose Keploy when its unusual strength matches the problem: one recording layer can replace several live dependencies during an integration run. WireMock is easier when only HTTP needs a stand-in, and Testcontainers is more faithful when a real database or broker is affordable. Keploy sits between those choices. Our 132 passing tests justify a serious pilot. Captured fixtures and independent business assertions belong in that pilot from the start.

Alternatives

ProjectWhat it isPick it when
WireMockA mature HTTP service simulator with explicit request matching and response stubs.pick this instead when HTTP mocking is the whole job and you prefer authored stubs over network-level recording.
HoverflyA lightweight proxy for capturing and simulating HTTP or HTTPS services.pick this instead when proxy-based service virtualization is enough and database or queue capture is outside scope.
Testcontainers for JavaA Java library that starts disposable real services in containers for tests.pick this instead when running real databases and brokers is preferable to replaying captured interactions.

What people are saying

  1. [github-trending] keploy/keploy

Sources

  1. Keploy README
  2. Keploy repository
  3. Keploy v3.6.82 release
  4. Issue 4636: printed result can disagree with assertions
  5. Issue 4609: gRPC assertions ignored
  6. Issue 4531: utility commands exit 0 on failure
  7. Issue 3832: eBPF tracepoint permissions

More dev tools reviews

retrofit · go-redis · Kaku · kordoc · hey · wechat-miniapp-radar · the whole board →