SReverseby Simpa Labs

Full APK to JavaScript and TypeScript

Clients for the full Android API, including generated headers, signatures, encryption, sessions and backend workflows.

What your team receives

The package includes typed methods, runtime response checks, configuration, errors and tests. JavaScript and TypeScript call the same reconstructed API. The Postman collection and documentation cover the same endpoint set.

Types and runtime checks do different jobs

TypeScript checks your code against declared types. A backend response arrives at runtime and needs validation. A type assertion does not check JSON or detect a remote API change. The parser below rejects a response with the wrong field type. TypeScript type assertions.

Run this offline example: download signing.ts. It uses a public test key and does not contact an app or backend.

// Offline example. Public test key; no APK or backend is contacted.
const encoder = new TextEncoder();

export async function sign(key: Uint8Array, message: Uint8Array): Promise<string> {
  const imported = await crypto.subtle.importKey(
    "raw", new Uint8Array(key), { name: "HMAC", hash: "SHA-256" }, false, ["sign"],
  );
  const bytes = new Uint8Array(await crypto.subtle.sign("HMAC", imported, new Uint8Array(message)));
  return Array.from(bytes, byte => byte.toString(16).padStart(2, "0")).join("");
}

export function parseLookup(value: unknown): { reference: string } {
  if (typeof value !== "object" || value === null ||
      !("reference" in value) || typeof value.reference !== "string") {
    throw new Error("Response is missing a string reference");
  }
  return { reference: value.reference };
}

const vector = await sign(new Uint8Array(20).fill(0x0b), encoder.encode("Hi There"));
if (vector !== "b0344c61d8db38535ca8afceaf0bf12b881dc200c9833da726e9376c2e32cff7") {
  throw new Error("RFC 4231 test failed");
}
parseLookup({ reference: "ABC123" });
let rejected = false;
try { parseLookup({ reference: 123 }); } catch { rejected = true; }
if (!rejected) throw new Error("Invalid response was accepted");
const body = JSON.stringify({ reference: "ABC123" });
console.log(body);
console.log(await sign(encoder.encode("public-demo-key"),
  encoder.encode("1700000000\nPOST\n/v1/lookup\n" + body)));

Run signing code on the server

Keep private credentials and signing secrets out of browser bundles. Browser requests also depend on the remote server’s CORS policy. A client that runs in Node does not gain browser access by using fetch. Browser integrations should call your server-side client. CORS documentation.

The sample uses Web Crypto and a public RFC 4231 test vector. Python and TypeScript produce the same signature for the same demo bytes. Project tests use the recovered app formats and validate both success and failure responses.

Android Keystore keys can be non-exportable and bound to secure hardware. A server that requires proof from that hardware has a runtime dependency that copied code cannot remove. We check this during the APK review and state the deployment requirements before the quote. Android Keystore documentation.

The full APK is the project

You receive Python, JavaScript/TypeScript, Postman and API documentation for the full application. The work covers endpoints, authentication, request signatures, encryption, decryption, sessions and backend workflows.

Run the complete public demonstration to inspect one matching workflow in every format.

Send the APK on WhatsApp or email. The 24–72 hour delivery window starts after we receive the APK and any account access needed to run it. The fixed quote states the deadline. Most projects finish sooner.

One full APK. One complete delivery.

Projects start at $120. Most are delivered in 24 to 72 hours.

Every format included

Python, JavaScript/TypeScript, Postman and complete API documentation cover the same full endpoint set. Your team runs the clients in its own server or system.

Ready in 24–72 hours

The delivery window starts after we receive the APK and any account access needed to run it. The fixed quote states the deadline. Most projects finish sooner.

Deployment checked before the quote

The package includes signing, encryption, decryption and session handling. We verify device-bound keys and server integrity checks during review and document runtime requirements before you commit.

30 days of fixes

Report a defect within 30 days of delivery. We fix any delivered call that does not match the tested APK at no extra cost.

Start your full APK reconstruction

Send the full APK

Projects start at $120. Choose WhatsApp or email, then attach the APK in the app that opens. We reply within one hour with the next step and send the fixed quote after review.

Want us to contact you?