Deliverable · Postman
Every request, importable.
SReverse returns the app's API as a Postman collection you import and use. Endpoints, environments, variables and pre-request scripts reproduce the headers, signing and tokens the app applies.
// Pre-request script · runs before every request in this folder // Environment: app-android. Rebuilds the app's signature and token. // 1. timestamp the app includes in each signed request const ts = String(Math.floor(Date.now() / 1000)); pm.environment.set("ts", ts); const method = pm.request.method; const path = pm.request.url.getPath(); const body = pm.request.body ? pm.request.body.raw : ""; // 2. refresh the access token before it expires const token = pm.environment.get("access_token"); const expiresAt = pm.environment.get("token_expires_at"); if (!token || Date.now() > Number(expiresAt)) { const res = pm.sendRequest({ url: pm.environment.get("base_url") + "/oauth/token", method: "POST", header: { "Content-Type": "application/json", "X-App-Key": pm.environment.get("app_key") }, body: { mode: "raw", raw: JSON.stringify({ grant_type: "password", username: pm.environment.get("user"), password: pm.environment.get("pass") }) }, }); const data = res.json(); pm.environment.set("access_token", data.access_token); pm.environment.set("token_expires_at", String(Date.now() + data.expires_in * 1000)); } // 3. sign the request and attach the headers the app sends const msg = `${method}\n${path}\n${body}\n${pm.environment.get("ts")}`; const sig = CryptoJS.HmacSHA256(msg, pm.environment.get("secret")).toString(); pm.request.headers.upsert({ key: "X-Timestamp", value: pm.environment.get("ts") }); pm.request.headers.upsert({ key: "X-Signature", value: sig }); pm.request.headers.upsert({ key: "Authorization", value: "Bearer " + pm.environment.get("access_token") });
Fig. 01 · the pre-request script regenerates the timestamp, token and signature on every call
This is the deliverable. A collection with the app's requests, an environment for the values you hold, and pre-request scripts that sign and authenticate the way the application does.
A collection is opened or imported. It is not a script you run from the command line. You load it into Postman, drop your credentials into the environment, and use each request directly.
What the collection covers
A collection you inspect, not a black box.
Each request is a plain folder and item you can open, edit and run. The moving parts the app handles are pushed into the pre-request scripts.
Every request in the full APK, with its method and path.
Variables for base URL, credentials and keys, so a team can share without hardcoding.
Tokens, timestamps and signatures set before the request leaves Postman.
Signing, header construction and token refresh, run automatically on each call.
Project
The deliverable covers the full APK.
Every project includes a Postman collection for every endpoint and backend workflow in the full APK.
Start a project
Get the app's requests in Postman.
Send the application and what the app does. We'll confirm the endpoints, the signing, and the project before we build.
One full APK. One complete delivery.
Projects start at $120. Most are delivered in 24 to 72 hours.
Every format included
Python, JavaScript/TypeScript, Postman and complete API documentation cover the same full endpoint set. Your team runs the clients in its own server or system.
Ready in 24–72 hours
The delivery window starts after we receive the APK and any account access needed to run it. The fixed quote states the deadline. Most projects finish sooner.
Deployment checked before the quote
The package includes signing, encryption, decryption and session handling. We verify device-bound keys and server integrity checks during review and document runtime requirements before you commit.
30 days of fixes
Report a defect within 30 days of delivery. We fix any delivered call that does not match the tested APK at no extra cost.