The published numbers
Projects start at $120 and most are delivered in 24 to 72 hours. Those are the only prices stated here. Any other figure for a specific app would be a guess, because the work depends on what the package contains, and that is visible only after someone opens it.
The starting price covers a project of the size the service normally sees: a target with no unusual protection and a client that reproduces a bounded set of endpoints. Android reverse engineering cost sets out the same numbers on the service side and explains what the base engagement includes.
What raises the work
Price follows effort, and effort follows the number of independent mechanisms the client has to reproduce. Each of these adds a distinct piece of work, and they combine.
- Request signing adds a tracing step. The work is finding the function that computes the value, recovering any key it uses, and confirming that a script produces the same output for the same input.
- Encrypted payloads add a second mechanism. A body cipher sits beside the signature, and it has to be located and reproduced before any parameter can be read or written.
- Device binding removes the option of copying a value. When the server checks something the device produces, the client needs a way to obtain an equivalent value rather than a stored string.
- Certificate pinning changes how traffic is observed. The capture step costs more time when the app refuses to talk to a proxy, and that time comes before any endpoint is understood.
- Commercial protectors raise the cost of reading code. Packing, string encryption and virtualisation each add work before the endpoint code becomes readable at all.
- Protocol choice changes the tooling. gRPC, GraphQL, WebSocket and a custom binary framing each need their own parsing path and their own way of describing a call.
A pinned app with a signed request and an encrypted body takes longer than an app with either one alone. None of those conditions make a project impossible, and each has a known method. APK API extraction lists the cases the service takes on.
What the quote depends on
A quote follows from a look at the APK, because the mechanisms above are visible in the package before any code is written. The reviewer checks which networking library is present, whether the request path contains signing or encryption, whether a packer or protector is applied, and how many endpoints the client has to cover. Those four answers decide the estimate.
Scope matters as much as difficulty. A single read-only endpoint costs less than a full flow with login, token refresh, upload and pagination, because the later stages bring session state and ordering with them. What $120 buys describes the smaller end of that range in detail.
Where the time goes
Delivery inside 24 to 72 hours covers a normal project. The clock starts when the APK arrives and the scope is complete, and most of the elapsed time goes to the one mechanism that is specific to the app: the signing routine, the cipher, the protector or the session flow. The rest is assembly around it.
- Static reading identifies the shape of the work. Decompiling, following client construction and listing endpoints takes the first pass and produces the plan.
- Dynamic observation confirms the derived values. Running the app and watching its traffic turns a guess about a value into a measurement.
- Reproduction moves the logic into a client. The recovered routine becomes code in the requested language, with the transport around it.
- Verification compares the two implementations. The new client and the app send requests that the server accepts, including after a token refresh.
Send the APK with a note about the endpoints you care about. That note is the difference between a quote for one call and a quote for a workflow, because scope is priced per mechanism and per flow rather than per endpoint alone.
The reviewer also asks what the client has to do with the data, since a one-way export is less work than a flow that writes back to the server. Write access brings validation rules, ordering and error handling with it, and those are estimated in the same pass as the read path.
Reviewed 28 September 2026 · SReverse research desk