One endpoint can hide the whole application
GraphQL lets a client describe the fields it needs. Many app screens can call one URL while sending different operations in the request body. Searching the APK for REST paths will miss that structure. The useful evidence is the query document, operation name, variables and code that handles the returned fields.
Android apps can keep query documents as strings, generated classes, bundled files or hashes used for persisted queries. Apollo-generated models can expose operation names and response shapes even when the source query file is gone. A release build may also split fragments across generated code or build the variables at runtime.
Recover every operation and its real inputs
We inventory queries, mutations and subscriptions across the APK. For each operation, we trace variable creation, optional values, custom scalar formats, headers and the response model. Aliases and fragments are kept because they change the shape the app expects. We also map pagination cursors, cache keys and follow-up calls that join several operations into one workflow.
- Find the GraphQL URL and any separate subscription endpoint.
- Restore operation names, query text, fragments and variables.
- Map persisted-query hashes to their full operations.
- Recover custom scalar values such as dates, IDs and encoded payloads.
- Handle GraphQL responses that contain both
dataanderrors.
Authentication and signing sit around GraphQL
The GraphQL specification defines operations and results. The app still decides how it authenticates the HTTP or WebSocket call. We trace bearer tokens, cookies, device headers, signatures and request encryption around each operation. When the app signs the raw JSON body, key order and exact encoded bytes become part of every valid request.
Subscriptions need their own connection flow. We recover the negotiated WebSocket subprotocol, connection payload, subscribe messages, keepalive behavior and reconnect rules used by the APK. Uploads are mapped with the same care when the app sends multipart GraphQL requests.
The full delivery
You receive a callable API for the full APK in Python and JavaScript/TypeScript, plus a Postman collection. The clients cover every recovered endpoint and workflow. They create fresh signatures, encrypt requests, decrypt responses, keep authentication and session state, and follow the same request order as the app.
Each client includes clear input models, parsed outputs, refresh behavior, uploads, downloads, streaming events and useful errors where the app uses them. We test the delivery against the live service so it runs without copied requests or old tokens.
Reviewed 30 August 2026 · SReverse research desk