SReverseby Simpa Labs

Capabilities · DRM & Media

Reconstruct the media request, not the keys.

We trace the manifest, entitlement, playback-token and license request flow, then rebuild the callable network path around Media3 and MediaDrm.

MediaDrm Media3 / ExoPlayer License request Manifest Entitlement
trace · playback start
GET  /manifest.mpd    (content + keys)
MediaDrm.generateKeyRequest(session)
POST /license          (signed request)
MediaDrm.provideKeyResponse(session, resp)
play

The playback context

ExoPlayer shows you where the media API is

ExoPlayer and Media3 are the network and playback layer. They fetch the manifest, hand the DRM system a request, and pipe the response back. They are not the protection. That is why tracing them is useful: they name the API calls you want.

01

Manifest request

How the app asks for content metadata, and what headers or token it sends.

02

DRM session

The MediaDrm instance, the scheme, and the request it generates for a license.

03

Entitlement

The check that decides whether the account may play, and the token that proves it.

The point

The request is the subject. The protection stays where it is.

The request family

What a media app asks the server

  • Manifest fetch
  • License request
  • Authorization / entitlement
  • Token refresh for playback
  • Segment and key URL resolution
  • DRM scheme selection
  • Header and session setup
  • Playback telemetry

Schemes

Widevine, ClearKey, PlayReady

Widevine

The common Android scheme

MediaDrm issues a key request for a licence; the request is the part you can read and reproduce for integration.

ClearKey

The open test scheme

ClearKey uses a defined key format without proprietary key wrapping. The keys still come from the content owner or license service.

PlayReady

Used where the service requires it

The request and response flow sits behind the same MediaDrm interface.

Trace it

Follow the license request

MediaDrm · session
// the app asks MediaDrm for the bytes to send
drm = MediaDrm(UUID.fromString(scheme))
session = drm.openSession()

request = drm.getKeyRequest(
    session, init_data, media_type, KEY_TYPE_STREAMING)

// the request body goes to the license endpoint
response = client.post(LICENSE_URL, request.data, auth)
drm.provideKeyResponse(session, response)

Fig. 01 · the request the app sends, kept inside the platform call

The entitlement that precedes the license is often the harder part. We map the account state, playback token and request headers so the call reaches the server in the same shape as the app.

Project

What we take on

We reconstruct the request

Manifest, license, entitlement, playback-token and request-header flows.

We do not extract keys

MediaDrm keeps the device-side key session. We reconstruct the server-facing request chain around it.

Send us the app

Need the media request rebuilt?

Send the app, the title you tested and the playback error. We trace the request chain and quote the exact reconstruction.

Projects start at $120. Most are delivered in 24 to 72 hours.

One full APK. One complete delivery.

Projects start at $120. Most are delivered in 24 to 72 hours.

Every format included

Python, JavaScript/TypeScript, Postman and complete API documentation cover the same full endpoint set. Your team runs the clients in its own server or system.

Ready in 24–72 hours

The delivery window starts after we receive the APK and any account access needed to run it. The fixed quote states the deadline. Most projects finish sooner.

Deployment checked before the quote

The package includes signing, encryption, decryption and session handling. We verify device-bound keys and server integrity checks during review and document runtime requirements before you commit.

30 days of fixes

Report a defect within 30 days of delivery. We fix any delivered call that does not match the tested APK at no extra cost.

Start your full APK reconstruction

Send the full APK

Projects start at $120. Choose WhatsApp or email, then attach the APK in the app that opens. We reply within one hour with the next step and send the fixed quote after review.

Want us to contact you?