The entry price and what it covers
SReverse projects start at $120, and most are delivered in 24 to 72 hours. The base price covers the full APK: every callable backend workflow recovered from the app and delivered as something a team can run. Concretely that means unpacking and decompiling the APK, locating every endpoint the app uses, recovering the request and response shapes, identifying the headers and the authentication each call carries, and building a working client in Python or TypeScript with a Postman collection and a written description of every call.
Most projects that arrive are small by this measure. A login, a lookup and a submit that share one token, a single signed call used by an internal tool, or one feature extracted from an app that has no public API all fit inside the entry price and the 24 to 72 hour window.
Two things are outside that scope and are not offered at any price. Key extraction and DRM circumvention are not part of the work, and neither is a promise that a server will accept a request when the requirement depends on hardware-held credentials. A short feasibility pass states where that boundary falls before money is committed.
What raises the price
- Scope size raises the estimate. A flow with four endpoints is a different job from an app with several dozen spread across two API generations and three body formats, because each endpoint has to be traced and tested.
- A second protection layer under PairIP raises the work. An app that went through a commercial protector at build time and then got wrapped by Play for distribution carries string encryption and control flow work that has to be undone before the request logic becomes readable.
- Native signing raises the work. When the signature is computed in a shared library rather than in Java, the routine has to be read out of compiled code for the relevant ABIs and reimplemented byte for byte.
- Account-gated flows raise the work. A call that only answers for a signed-in user requires the account path first, including any registration, device binding or verification step the service enforces.
- Long request chains raise the work. When each response feeds the next request and the values expire, the client needs the full sequence and the renewal behaviour, not a set of independent calls.
- Obfuscation depth raises the work. Renamed classes, encrypted strings and reflection-based dispatch cost reading time even when the underlying logic is ordinary.
How the quote is worked out
The estimate follows the flow rather than the app. Five things are checked first: how many endpoints are in scope, what the request and response formats are, whether signing lives in Java or in a native library, which protection wrapped the build, and whether the calls require a signed-in account.
A short test on one endpoint usually settles the rest. If the captured request replays with no edits, the remaining work is client construction. If it fails, the failure pattern shows whether the effort sits in signing, freshness or session state, and that pattern is what the quote is built on.
A fixed price is possible for this kind of work because the deliverable is enumerable. The endpoint list, the client, the collection and the documentation are all countable, and the uncertain part is how much protection sits between the APK and the request logic. That is why a project with a packed build and native signing is quoted higher up front rather than billed by the hour.
What arrives at the end
The usual delivery is a module in Python or TypeScript that performs the recovered flow with the token handling, signing and session state it needs, a Postman collection that runs the same calls manually, and documentation describing each endpoint, its parameters and the values that have to come from a previous call. Teams that need one language only receive that one.
The client is checked against the app on the same account and the same inputs, so the comparison is behavioural rather than a code review. Where a service changes after delivery, the documentation is what makes the difference visible, because the failing call is named along with the value it expected.
For a larger target, the same structure holds and the price and the delivery window are set in writing before work starts. The entry price is a real entry price: a team can send one APK, get a working client for one flow, and decide from there whether the rest of the app is worth the additional scope.
Related work
Reviewed 28 September 2026 · SReverse research desk