Interceptors are part of the protocol
OkHttp calls interceptors in order. Square documents two kinds: application interceptors and network interceptors. Application interceptors run around the logical call. Network interceptors observe the network exchange and can run more than once when redirects occur.
An interceptor can replace the URL, add a bearer token, generate a signature, compress a body or retry with new state. It can also read a response and update stored credentials. The original request builder does not show those final values.
Trace the client that the app uses
Large APKs can create several OkHttpClient instances for different services. We find each builder, its interceptors, cookie jar, authenticator, connection rules and certificate settings. Then we map every service to its real client.
For signed calls, we record the exact input bytes before the signature function runs. Method, encoded path, query order, selected headers, body hash, timestamp, nonce and device fields can all enter the canonical string. The port must create the same bytes on every fresh request. For encrypted calls, we trace key creation, IV or nonce handling, padding, encoding and response decryption.
The full APK becomes a full callable API
We rebuild the application’s complete server-facing behavior. The delivery includes Python, JavaScript and TypeScript clients, an importable Postman collection, and working request examples. Authentication, cookies, refresh rules, request order and error handling are built in.
Signature generation runs with fresh timestamps and nonces. Encryption and decryption are implemented in code. Binary bodies are serialized correctly. Each client can start a new session and repeat the application workflows without reusing an old capture.
We test the clients against the same server flows used by the APK. Send the APK on WhatsApp or by email. We handle the technical questions in the conversation.
Sources
Reviewed 30 August 2026 · SReverse research desk