SReverseby Simpa Labs

Endpoint discovery

Finding the REST API URLs in a decompiled APK

A decompiled APK usually contains the API host and most of its paths as text, because building every URL from encrypted fragments is more work than most applications do. The task is to search in the right order.

Search order that finds most URLs

Work through the package in this order and stop when the strings stop appearing.

  • Search the dex string tables for a scheme. A search for a URL scheme returns every literal that looks like an address, grouped by class. Filter out the hosts for analytics, crash reporting and advertising, and the API host usually stands out as the one with a path.
  • Search for path fragments rather than full addresses. Base hosts and path prefixes are often stored as separate constants, so a literal such as a version segment or a resource name finds a route that no full-address search reveals.
  • Read the resources and assets. Environment names, feature flags and endpoint tables ship in configuration files, and a bundled JSON file can carry the whole route list for a schema-driven client.
  • Find the class that builds the client. A Retrofit builder, an OkHttp client, a Ktor client or a Volley queue is constructed once, and the base URL is set there. That class is the single place where the host is decided, which makes it the most direct source for the environment.
  • Read the interfaces and call sites. Declarative clients declare paths in annotations or interface methods. Hand-written calls build a path next to the verb.
  • Check the native libraries. A client written in C or C++ keeps its strings in the shared object, so run the same search over the library files when the dex search comes up short.

When the strings are encrypted

A protected app can replace literals with ciphertext and decrypt them at run time. The evidence is a search that returns no host while the app clearly makes requests, together with a routine that turns an array of bytes into a string. Find that routine and the table it reads, then hook its return value at run time to collect the strings as the app uses them. Static recovery is possible when the routine is simple, and observation is faster when it is not. String encryption in an APK covers the distinction.

When an address is assembled from parts

Some clients build the address per request: a host from a configuration value, a version prefix from a constant, a path from a template, and query parameters from a map. A full-address search finds nothing in that design, while a fragment search finds every piece. Read the method that assembles them to learn the order, then confirm the result against a capture, because that method is the only place that states which part wins when two are set.

Use the running app for what static search misses

Static reading answers which endpoints exist. Observation answers which values the app actually sends. Instrument the client builder, the address builder or the transport method, and log the final address just before the request leaves. That trace also shows the headers and the order of calls, which a string search cannot. Finding the backend base URL in an APK describes where the host is decided, and tracing a request signature covers the values added at request time.

Confirm the inventory against a capture

A static list holds more addresses than the app uses in one session, and some of them serve endpoints that are disabled for your account or your region. Run one flow at a time, capture the traffic, and mark which addresses the app actually called. That comparison removes retired routes from the deliverable and shows which endpoints share a host, which matters when the base address changes between environments.

The comparison also exposes protocol variants. A client that speaks GraphQL posts to one address and carries the operation in the body, a gRPC client uses one address and a service name, and a protobuf client sends a binary payload along the paths a JSON client would use. The host search finds the address in all three cases, and the payload decides how much more work the client needs.

Turn the inventory into a client

A list of addresses is the start of an API client rather than the end of one. The client also needs authentication, the headers every request carries, the payload shapes and the state between calls. APK API extraction service produces that client, and Android API reverse engineering covers the wider discipline.

Reviewed 28 September 2026 · SReverse research desk

Start your full APK reconstruction

Send the full APK

Projects start at $120. Choose WhatsApp or email, then attach the APK in the app that opens. We reply within one hour with the next step and send the fixed quote after review.

Want us to contact you?