SReverseby Simpa Labs

Collection building

How to build a Postman collection from an APK

A Postman collection is only as good as its handling of the values the app computes. Deciding which requests can be saved as they are and which need a script is the first design choice, and it shapes everything after it.

What a collection can hold

A collection stores requests, variables and scripts. If a request depends on values computed at send time, the collection needs a script that computes them, or that request fails every time it is sent from a saved state. Sorting your endpoints into groups early saves rework later.

  • Static and parameterised requests translate directly into collection items.
  • Requests authenticated with a bearer token translate with a collection level auth setting and a variable.
  • Requests with signatures, encrypted bodies or device identifiers need a pre-request script that reproduces the derivation.

Build the endpoint inventory first

Collect endpoints from the app before opening Postman. Retrofit interfaces list paths and methods together. An OkHttp interceptor or a logging build reveals full URLs and headers. Where the app obfuscates both, the strings table and a traffic capture fill the gaps.

Record the method, path, required headers, content type and body shape for each endpoint. The body shape matters even where you hold a working sample, because fields that were absent in that sample may be required in other cases.

Move derived values into scripts

The Postman pre-request sandbox runs JavaScript, which covers hashing, HMAC, AES and base64 through its bundled crypto library. A signature computed with those primitives can be reproduced in a script, provided the key is available as a variable.

Some derivations do not survive the move. A value produced inside a native library, a key held in the Android keystore, or a signature over bytes the app assembles in C cannot be recreated in the sandbox. For those endpoints the honest options are a small local helper that signs and returns the value, or a note on the request explaining that the value comes from outside. A collection that pretends otherwise wastes the time of everyone who uses it.

Where the derivation involves a timestamp, keep the window short and read the server clock. A script that signs with the local machine time will work on your laptop and fail on a build machine in another region.

Chain requests with variables

Stateful flows become a folder of requests that pass values forward. The login or establishment request writes tokens and identifiers into variables, and the requests after it read them.

  • Set variables from the response in a test script, so later requests can use them.
  • Keep the session identifier separate from the access token, because the two expire independently.
  • Use an environment for values you change often and collection variables for values that belong to the flow.
  • Update the stored refresh token whenever a refresh call returns a new one.

Order inside a folder is a real dependency rather than a convenience. Someone who runs one request on its own should find that documented instead of discovering it through an opaque error. Name the folder after the workflow it represents, not after the screen that triggers it.

Cookies

Postman keeps a cookie jar per domain, which handles many session based APIs without any work on your part. Check whether the app also copies a cookie into a header or persists one to disk, because the jar will not cover either case. Where the API sets a cookie during login and expects it on every later call, verify the jar before you debug anything else. Confirm it with two calls in a row rather than one, because a jar that drops cookies while following a redirect fails in the middle of a flow rather than at the start.

Document what stays dynamic

A collection that hides its weak points is worse than one that names them. Describe each dynamic field, which script fills it, and what happens when it goes stale. Mark the endpoints that need an external signer, and note which requests depend on an earlier call in the folder.

That documentation is also the seed of an API description the team can maintain. The endpoint inventory you built at the start already holds the paths, methods and parameter shapes, so writing it down costs little and answers most of the questions a new client author would otherwise ask you directly.

Reviewed 28 September 2026 · SReverse research desk

Start your full APK reconstruction

Send the full APK

Projects start at $120. Choose WhatsApp or email, then attach the APK in the app that opens. We reply within one hour with the next step and send the fixed quote after review.

Want us to contact you?