Find the last code that changes the request
Android apps often add headers after the screen code has created the request. OkHttp application interceptors can add, remove or replace headers before a call runs. Network interceptors can see redirects and the final request sent over the connection. An authenticator can create another request after the server returns an authentication challenge.
We trace the request through each layer. This catches headers added by Retrofit adapters, OkHttp interceptors, token stores, native libraries and protection SDKs. It also shows which values belong to every call and which belong to one endpoint.
Rebuild the signature base exactly
Names such as X-Signature, X-Token and X-Auth do not explain how a value is made. We follow each input into the final algorithm. Common inputs include the HTTP method, path, sorted query, body digest, timestamp, nonce, account token and device value.
The order and encoding are part of the algorithm. We record newline rules, case changes, URL encoding, JSON serialization, binary packing and hash output format. If the signer crosses JNI, we map the Java-to-native arguments and the bytes returned to the request builder.
Fresh values prove the reconstruction
A copied header expires. A working client creates a new timestamp and nonce, reads current session state, serializes the body and signs the final request. We test repeated calls, changed inputs, token refresh and server clock errors so the implementation handles normal use.
What you receive
The full APK becomes a callable API in Python and JavaScript/TypeScript, plus Postman requests with pre-request scripts where they are useful. Signature generation, encryption, decryption, authentication, sessions and every linked workflow ship together.
Reviewed 30 August 2026 · SReverse research desk