JADX shows broken or empty code
Check the APK before changing tools. Small DEX files, a replacement application class and large native libraries point to runtime loading or a protection shell. Normal-sized DEX files with short class names point to R8, ProGuard or a stronger obfuscator. Follow call references from Android components, URLs, serializers and native methods instead of waiting for readable names.
If the app is Flutter, important Dart logic may be compiled into libapp.so. React Native can keep it in a JavaScript or Hermes bytecode bundle. JNI methods move the path into an ABI-specific .so file.
The app works but the proxy sees no request
Confirm whether the app uses the proxy at all. Then check Android network security settings, certificate pinning, native TLS and protocols the proxy does not decode. Cronet, custom sockets, QUIC and native clients can bypass the path used by a normal Java HTTP stack.
A domain found in code is useful, but it does not prove the final request. Trace the call that turns the app action into bytes and capture the data at that boundary.
The captured request fails in Python or cURL
Compare the canonical request, not the visible header list. Signatures can include the method, path, query order, selected headers, exact body bytes, timestamp and nonce. JSON spacing, Unicode encoding, gzip, protobuf serialization and URL escaping can change the signed bytes.
Check session creation and request order next. A valid token can still depend on cookies, device registration, a challenge, a prior lookup or a refreshed key. A 401, 403 or signature error often comes from stale state rather than a missing endpoint.
Frida or the debugger changes app behavior
Look for the reaction as well as the check. The app may exit, delay, skip a branch or corrupt one request value. Checks can run in Java, native code or a protection runtime. Trace the full application flow and the values it produces before and after instrumentation.
When to stop debugging and send the app
Send the APK when you need a working client rather than another list of tools. Include the APK and any account needed to reach the app. We reconstruct the full application flow and deliver the complete API package.
Read the focused guides on request replay, endpoint discovery, JNI code and protected APKs.
Reviewed 30 August 2026 · SReverse