The server Block

The server Block: url, cleartext and Schemes

Capacitor 243,123 serves the bundled files from an origin it invents: https://localhost on Android and capacitor://localhost on iOS. hostname (default localhost), androidScheme (default https) and iosScheme (default capacitor) set its parts. Leave them alone unless you migrate from Cordova 129 : localhost is a secure context for APIs such as geolocation, and the origin keys localStorage and IndexedDB, so changing it in a shipped app makes stored data vanish (Scheme Change and Data). allowNavigation lists outside hosts the WebView may open in place; errorPath names a local error page.

url and cleartext are for development: url loads a dev server instead of the bundle, so each save reloads the app, and cleartext: true lifts Android's default block on plain http:// (in force since API 28):

The server block added to capacitor.config.ts for live reload
  server: {
    url: 'http://localhost:5813', // forwarded to the dev machine by adb reverse
    cleartext: true,               // allow plain http:// (development only)
  },
Serving, forwarding the port, and syncing the new configShell
npx vite --host 0.0.0.0 --port 5813 --strictPort &
adb -s emulator-5580 reverse tcp:5813 tcp:5813
npx cap sync android
grep -o 'android:usesCleartextTraffic="true"' \
  android/capacitor-cordova-android-plugins/src/main/AndroidManifest.xml
Output
...
android:usesCleartextTraffic="true"

So cleartext is a manifest attribute that sync writes into the Cordova plugins module and Gradle 19,597 merges into the app. After a rebuild, the page shows the dev server's origin and the bridge still works. On a real phone, use the computer's LAN address.

The same app loaded from its bundle and from a live-reload dev server
The same app loaded from its bundle and from a live-reload dev server