SReverseby Simpa Labs

Deliverable · Postman

Every request, importable.

SReverse returns the app's API as a Postman collection you import and use. Endpoints, environments, variables and pre-request scripts reproduce the headers, signing and tokens the app applies.

pre-request script · collection "app-android"
// Pre-request script · runs before every request in this folder
// Environment: app-android. Rebuilds the app's signature and token.

// 1. timestamp the app includes in each signed request
const ts = String(Math.floor(Date.now() / 1000));
pm.environment.set("ts", ts);

const method = pm.request.method;
const path   = pm.request.url.getPath();
const body   = pm.request.body ? pm.request.body.raw : "";

// 2. refresh the access token before it expires
const token = pm.environment.get("access_token");
const expiresAt = pm.environment.get("token_expires_at");
if (!token || Date.now() > Number(expiresAt)) {
  const res = pm.sendRequest({
    url: pm.environment.get("base_url") + "/oauth/token",
    method: "POST",
    header: { "Content-Type": "application/json",
              "X-App-Key": pm.environment.get("app_key") },
    body: { mode: "raw", raw: JSON.stringify({
      grant_type: "password",
      username: pm.environment.get("user"),
      password: pm.environment.get("pass") }) },
  });
  const data = res.json();
  pm.environment.set("access_token", data.access_token);
  pm.environment.set("token_expires_at", String(Date.now() + data.expires_in * 1000));
}

// 3. sign the request and attach the headers the app sends
const msg = `${method}\n${path}\n${body}\n${pm.environment.get("ts")}`;
const sig = CryptoJS.HmacSHA256(msg, pm.environment.get("secret")).toString();

pm.request.headers.upsert({ key: "X-Timestamp", value: pm.environment.get("ts") });
pm.request.headers.upsert({ key: "X-Signature", value: sig });
pm.request.headers.upsert({ key: "Authorization", value: "Bearer " + pm.environment.get("access_token") });

Fig. 01 · the pre-request script regenerates the timestamp, token and signature on every call

This is the deliverable. A collection with the app's requests, an environment for the values you hold, and pre-request scripts that sign and authenticate the way the application does.

A collection is opened or imported. It is not a script you run from the command line. You load it into Postman, drop your credentials into the environment, and use each request directly.

What the collection covers

A collection you inspect, not a black box.

Each request is a plain folder and item you can open, edit and run. The moving parts the app handles are pushed into the pre-request scripts.

Endpoints

Every request in the full APK, with its method and path.

Environments

Variables for base URL, credentials and keys, so a team can share without hardcoding.

Variables

Tokens, timestamps and signatures set before the request leaves Postman.

Pre-request scripts

Signing, header construction and token refresh, run automatically on each call.

Project

The deliverable covers the full APK.

Every project includes a Postman collection for every endpoint and backend workflow in the full APK.

The collection contains every endpoint, authentication flow, variable and signing rule found across the full APK.

Start a project

Get the app's requests in Postman.

Send the application and what the app does. We'll confirm the endpoints, the signing, and the project before we build.

Projects start at $120. Most are delivered in 24 to 72 hours.

One full APK. One complete delivery.

Projects start at $120. Most are delivered in 24 to 72 hours.

Every format included

Python, JavaScript/TypeScript, Postman and complete API documentation cover the same full endpoint set. Your team runs the clients in its own server or system.

Ready in 24–72 hours

The delivery window starts after we receive the APK and any account access needed to run it. The fixed quote states the deadline. Most projects finish sooner.

Deployment checked before the quote

The package includes signing, encryption, decryption and session handling. We verify device-bound keys and server integrity checks during review and document runtime requirements before you commit.

30 days of fixes

Report a defect within 30 days of delivery. We fix any delivered call that does not match the tested APK at no extra cost.

Start your full APK reconstruction

Send the full APK

Projects start at $120. Choose WhatsApp or email, then attach the APK in the app that opens. We reply within one hour with the next step and send the fixed quote after review.

Want us to contact you?