SReverseby Simpa Labs

Android protocol reconstruction · GraphQL

GraphQL Android API reverse engineering

We extract the APK’s complete GraphQL API specification: endpoint, operations, fragments, variables, headers, persisted-query hashes, uploads and session flow.

One endpoint can hide the whole application

GraphQL lets a client describe the fields it needs. Many app screens can call one URL while sending different operations in the request body. Searching the APK for REST paths will miss that structure. The useful evidence is the query document, operation name, variables and code that handles the returned fields.

Android apps can keep query documents as strings, generated classes, bundled files or hashes used for persisted queries. Apollo-generated models can expose operation names and response shapes even when the source query file is gone. A release build may also split fragments across generated code or build the variables at runtime.

Recover every operation and its real inputs

We inventory queries, mutations and subscriptions across the APK. For each operation, we trace variable creation, optional values, custom scalar formats, headers and the response model. Aliases and fragments are kept because they change the shape the app expects. We also map pagination cursors, cache keys and follow-up calls that join several operations into one workflow.

  • Find the GraphQL URL and any separate subscription endpoint.
  • Restore operation names, query text, fragments and variables.
  • Map persisted-query hashes to their full operations.
  • Recover custom scalar values such as dates, IDs and encoded payloads.
  • Handle GraphQL responses that contain both data and errors.

Authentication and signing sit around GraphQL

The GraphQL specification defines operations and results. The app still decides how it authenticates the HTTP or WebSocket call. We trace bearer tokens, cookies, device headers, signatures and request encryption around each operation. When the app signs the raw JSON body, key order and exact encoded bytes become part of every valid request.

Subscriptions need their own connection flow. We recover the negotiated WebSocket subprotocol, connection payload, subscribe messages, keepalive behavior and reconnect rules used by the APK. Uploads are mapped with the same care when the app sends multipart GraphQL requests.

The full delivery

You receive a callable API for the full APK in Python and JavaScript/TypeScript, plus a Postman collection. The clients cover every recovered endpoint and workflow. They create fresh signatures, encrypt requests, decrypt responses, keep authentication and session state, and follow the same request order as the app.

Each client includes clear input models, parsed outputs, refresh behavior, uploads, downloads, streaming events and useful errors where the app uses them. We test the delivery against the live service so it runs without copied requests or old tokens.

Reviewed 30 August 2026 · SReverse research desk

One full APK. One complete delivery.

Projects start at $120. Most are delivered in 24 to 72 hours.

Every format included

Python, JavaScript/TypeScript, Postman and complete API documentation cover the same full endpoint set. Your team runs the clients in its own server or system.

Ready in 24–72 hours

The delivery window starts after we receive the APK and any account access needed to run it. The fixed quote states the deadline. Most projects finish sooner.

Deployment checked before the quote

The package includes signing, encryption, decryption and session handling. We verify device-bound keys and server integrity checks during review and document runtime requirements before you commit.

30 days of fixes

Report a defect within 30 days of delivery. We fix any delivered call that does not match the tested APK at no extra cost.

Start your full APK reconstruction

Send the full APK

Projects start at $120. Choose WhatsApp or email, then attach the APK in the app that opens. We reply within one hour with the next step and send the fixed quote after review.

Want us to contact you?