SReverseby Simpa Labs

Undocumented API reverse engineering

The API exists. It just isn't public.

The app reaches a service the vendor never documented. We find that service, reconstruct how the app calls it, and hand you a client that does the same without the app.

Private endpoints Request shape Auth Serialization
U
Fig. 01 · a private service, surfaced from the app's own code

Find the private endpoints

Where an undocumented API hides

In the code

Endpoints that the app calls but the developer never printed in docs. Retrofit interfaces, URL constants and string tables name them.

In the traffic

Calls the app makes that no user action obviously triggers, like background refresh, analytics or device registration.

In the native layer

Paths assembled at runtime in a .so file do not show up in a plain dex string search.

To find an undocumented API we look at what the app can do, then trace how each feature reaches the server. The private endpoint is the path behind the feature that has no public equivalent.

Request shape & serialization

Rebuild the bytes the server expects.

A private endpoint accepts a specific shape. We reconstruct how the body is serialized, whether it is JSON, Protobuf, gRPC or a custom format, and how fields are encoded, ordered and sometimes encrypted. Reverse engineering an undocumented API means matching that shape exactly.

Shape details we reproduce

  • Field names and order
  • Encoding
  • Protobuf field numbers
  • gRPC method
  • Compression
  • Base64 wrapping
  • Encrypted payload
  • Message framing
messages.proto (reconstructed)
syntax = "proto3";

message LookupRequest {
  string id = 1;
  string locale = 2;
  bytes device_token = 3;
  int64 nonce = 4;
}

Fig. 02 · the field numbers and types the server actually reads

Auth

Private endpoints still check who is calling.

A private endpoint is usually reachable once the app can prove a session. We reconstruct the auth flow: how the app gets a token, where it stores it, what it sends back, and whether each request is signed or derived from a device value.

Login endpointToken grantRefreshToken storage Header placementCookie bindingRequest signingNonce TimestampDevice idIntegrity checkReplay guard

Rebuild the client

Use the app's API without the app.

This is the last step of reverse engineering an undocumented API: take the endpoint, the shape and the auth, and return a client that reproduces them so you can use the Android app API without the app itself.

private_client.py
import grpc, time, secrets
import messages_pb2 # our reconstructed module

def lookup(identifier, token):
    req = messages_pb2.LookupRequest(
        id=identifier, locale="en",
        device_token=derive_device_token(token),
        nonce=int(time.time() * 1000))
    return stub.Lookup(req, metadata=(
        ("authorization", bearer(token)),
        ("x-nonce", req.nonce),))

Fig. 03 · endpoint, shape and auth reproduced as a working call

Start a project

We find the API behind the feature.

Tell us what the app does. We'll locate the private endpoint and confirm the project before we quote.

Projects start at $120. Most are delivered in 24 to 72 hours.

One full APK. One complete delivery.

Projects start at $120. Most are delivered in 24 to 72 hours.

Every format included

Python, JavaScript/TypeScript, Postman and complete API documentation cover the same full endpoint set. Your team runs the clients in its own server or system.

Ready in 24–72 hours

The delivery window starts after we receive the APK and any account access needed to run it. The fixed quote states the deadline. Most projects finish sooner.

Deployment checked before the quote

The package includes signing, encryption, decryption and session handling. We verify device-bound keys and server integrity checks during review and document runtime requirements before you commit.

30 days of fixes

Report a defect within 30 days of delivery. We fix any delivered call that does not match the tested APK at no extra cost.

Start your full APK reconstruction

Send the full APK

Projects start at $120. Choose WhatsApp or email, then attach the APK in the app that opens. We reply within one hour with the next step and send the fixed quote after review.

Want us to contact you?