SReverseby Simpa Labs

Android API reverse engineering

Reconstruct the API an Android app actually uses.

You already know you need mobile or API reverse engineering. We take the app from its static code and its runtime together, and rebuild the calls it makes so you can make them yourself.

Static analysis Runtime capture JNI Signing Sessions
B
Fig. 01 · from dex and traffic back to a reproducible request

Static analysis

The dex holds the endpoints.

The compiled classes describe how the app talks. We read the dex to find Retrofit interfaces, OkHttp interceptors, base URLs, request models and where each value comes from. Reverse engineering an Android API starts here, because the code names the calls even when a UI never shows them.

What we read out of the dex

  • Retrofit service interfaces
  • OkHttp interceptors
  • Base URL constants
  • Endpoint paths
  • Request / response models
  • Header builders
  • Serializers
  • Auth tokens
  • WebSocket setup
  • GraphQL queries
ApiService.java (decompiled)
@POST("/v2/orders")
Call<OrderResponse> createOrder(
    @Header("Authorization") String auth,
    @Body OrderRequest body);

@GET("/v2/status/{id}")
Call<StatusResponse> status(@Path("id") String id);

Fig. 02 · an interface like this names the path and the shape before any traffic is captured

Runtime capture

Static code shows the shape. Traffic shows the moment.

Static paths give us the map. Runtime capture shows the actual request a session produces, including the headers, cookies and body the app wrote at that moment. We combine the two so a captured request becomes a rule, not a single frozen copy.

Static alone

  1. Names the path
  2. Names the model
  3. Omits the runtime values
  4. Misses session state

Static + runtime

  1. Path and model
  2. Fresh timestamp and nonce
  3. Signature built over both
  4. Session carried as the app does

Fig. 03 · the app's own request, reconstructed as a repeatable process

Native / JNI

Some logic never reaches the dex.

When a signing routine or a derived value resolves inside a native .so, the Java layer only shows the call site. We follow it into the native library and reconstruct the exact bytes and operations. Android private API reverse engineering is rarely one discipline; it is usually several.

Native / JNI analysis

Signals that the logic is native

  • System.loadLibrary()
  • An empty Java method marked native
  • Strings resolved from a table
  • Checks on a device value
  • Obfuscated exports
  • Pointer-heavy data

How it is delivered

You get the reconstructed API, not a writeup.

Python

Running code

A requests layer that signs, authenticates and keeps the session alive.

TypeScript

Typed client

Node or browser, matching the payloads the app sends.

Postman

Fork ready

Endpoints, environments and the pre-request signing script.

Docs

Reference

Endpoints, schemas, auth flow and ordering constraints.

Custom

Your shape

A module or a method in a framework you already use.

All deliverables

Start a project

Point us at the API you need.

Send the app and tell us which calls matter. We'll plan the static and runtime work and return a fixed quote.

Projects start at $120. Most are delivered in 24 to 72 hours.

One full APK. One complete delivery.

Projects start at $120. Most are delivered in 24 to 72 hours.

Every format included

Python, JavaScript/TypeScript, Postman and complete API documentation cover the same full endpoint set. Your team runs the clients in its own server or system.

Ready in 24–72 hours

The delivery window starts after we receive the APK and any account access needed to run it. The fixed quote states the deadline. Most projects finish sooner.

Deployment checked before the quote

The package includes signing, encryption, decryption and session handling. We verify device-bound keys and server integrity checks during review and document runtime requirements before you commit.

30 days of fixes

Report a defect within 30 days of delivery. We fix any delivered call that does not match the tested APK at no extra cost.

Before you send the APK

What your team needs to know

Send the full APK through WhatsApp or email. We reply within one hour.

What does the delivery include?

Every endpoint, protection mechanism and backend workflow in the APK, delivered as Python, JavaScript/TypeScript, Postman and complete API documentation.

How long does it take?

The 24–72 hour clock starts when we receive the APK and any account access the app requires. Most projects finish sooner. Your fixed quote confirms the deadline.

Where does the finished API run?

It runs on your server or inside your system. We include setup instructions and review the deployment with your team.

Will the finished API need Android?

We check this during review. Software-generated values run in the clients. Hardware-backed keys and server-required integrity proofs have device dependencies; the quote states the deployment requirements.

What happens if a delivered call fails?

Report it within 30 days of delivery. We fix any delivered call that does not match the tested APK at no extra cost.

Start your full APK reconstruction

Send the full APK

Projects start at $120. Choose WhatsApp or email, then attach the APK in the app that opens. We reply within one hour with the next step and send the fixed quote after review.

Want us to contact you?