SReverseby Simpa Labs

React Native

Reverse engineering React Native API requests

The JavaScript is right there in the bundle. The endpoint is a string away, and the signing may be native.

Identify the JS runtime before hunting endpoints

A React Native APK ships a bundle under assets/. A debug build holds plain JavaScript; a release build usually holds Hermes bytecode. The magic bytes and the tooling differ, so identify the runtime first. A plain bundle preserves module structure and strings. Hermes stores strings in a table and code as bytecode, so strings still lead to endpoints but the logic needs a decompiler or a disassembler.

unzip -l app.apk | grep -iE '.(bundle|hbc|js)$'
# Hermes bytecode starts with a magic header; plain JS is readable text
head -c 4 assets/index.android.bundle | xxd

If the first bytes are the Hermes magic, treat it as bytecode. If they look like JavaScript, you can read it directly.

Pull endpoints out of either format

strings assets/index.android.bundle | grep -iE 'https?://' | sort -u
# for Hermes, decompile to JavaScript or disassemble to opcodes
npx react-native-decompiler assets/index.android.bundle -o out.js

Decompiled Hermes is not always readable; an obfuscated bundle can produce code that is hard to follow. When that happens, fall back to the string table and the disassembly, and use the request capture as the source of truth for what actually goes onto the wire.

Follow the request through its wrapper

Applications wrap fetch, Axios or a GraphQL client, and the wrapper adds the base URL, the bearer token, retry rules and telemetry headers. Search inbound from the business action, then move toward the shared client. Starting at every fetch string creates noise; starting at the action tells you which request actually matters.

grep -rnoE 'axios.(get|post|put|delete)|fetch(|[^.]*.(get|post)(' out.js | sort -u | head

Inspect the state around the call

The value you cannot find is usually not in the call at all. It is supplied by the state around it.

  • AsyncStorage or a secure-storage module may hold tokens and device registration data.
  • A state library may supply values that never appear as local constants.
  • GraphQL clients can load persisted-query hashes instead of the full query text.
  • Native modules can return signed headers or encrypted bodies.
  • Over-the-air update systems can replace the bundle after installation.

Trace a value into a native module

When the JavaScript appears to pass a value it did not create, the creator is a native module. Find the NativeModules call, then open the Java side and follow the method. This is common for signatures, secure storage and device identifiers, and it is the reason a bundle-only reconstruction fails.

Reconstruct the final wire call

After every interceptor, the final URL, method, headers and body are what the server checks. Capture that exact request, then identify how each changing value is made. Build those in Python or TypeScript, because the full server API is rebuilt, not the bundle itself.

ObservationLikely causeWhere to look
A header appears you did not setA shared client adds it.The Axios or fetch wrapper and its interceptors.
The token is not in the bundleSecure storage or a native module.The storage module and the native call.
The body looks encryptedProtobuf or a binary serializer.Field boundaries, not cipher.
The proxy sees nothingCertificate pinning.The pinned client and the CA required.

Rebuild it in your target language

Once you know the final wire call, rebuild it rather than replay the bundle. A signed request means carrying the same canonical string, the same encoding and the same session into your own language. Start from the value generator, not the captured value, because a nonce or a timestamp captured once will not be accepted a second time.

Keep the request order the app used and refresh the token through the same call the app uses. When you compare against a fresh capture, compare the final bytes and headers, not the parsed JSON. If the server still rejects a byte-identical request, read the response body and re-check the session before changing headers at random.

Two things catch people out more often than a hidden algorithm: a token that lives in secure storage and is read by a native module you never decompiled, and a value that a state library injects into the request body. Both look like they should be in the bundle, and neither is.

Reviewed 30 August 2026 · SReverse research desk

Related

Start a project

Send the full APK

Send the full APK. We review the application and quote its complete API reconstruction.

Projects start at $120. Most are delivered in 24 to 72 hours.

Start your full APK reconstruction

Send the full APK

Projects start at $120. Choose WhatsApp or email, then attach the APK in the app that opens. We reply within one hour with the next step and send the fixed quote after review.

Want us to contact you?