APK to hosted API

Upload an Android APK and call the API behind it

A person reverse engineers the private API the app talks to. The platform hosts it, issues your key and meters every call. One project costs $120, with a 14-day money-back guarantee.
Price per project$120
Money-back window14 days
Maximum upload512 MB
EngineeringDone by a person, not a batch job

How a project runs

Every project follows the same four stages. Upload takes minutes. The analysis between scope and delivery is the slow part, and it is done by hand.

  1. Upload your APK
  2. Scope confirmed
  3. Pay and open a queue slot
  4. Deliverables and hosted endpoint
  1. 01

    Send the signed build you want the API for. The manifest is read on upload.

  2. 02

    We report the framework, protections and signing scheme, then agree what will be recovered.

  3. 03

    One payment for one project, once you have seen the scope report and accepted it.

  4. 04

    You receive the SDK, documentation, keys and a live endpoint, and calls are metered from then on.

Deliverables

What you receive

Everything below is handed over at delivery. Nothing here is optional or billed as an add-on.

A typed SDK

Generated clients for Python and TypeScript, typed against the input fields each recovered endpoint declares.

OpenAPI description and Postman collection

A machine-readable description of every endpoint, so the API can be called from tools you already use.

Written documentation of the recovered workflows

What each workflow does, which fields it takes, what it returns, and what the upstream expects in return.

API keys

Keys are issued when the project is delivered and shown once. Any key can be revoked from the project page.

A live hosted endpoint

The platform runs the recovered connector, including request signing and payload encryption, so you never handle the crypto yourself.

What we need from you

Two things decide whether a project can start.

A valid signed APK

A build that installs and runs on a device or emulator. If your release pipeline produces an Android App Bundle, build a universal APK from it first, because the analysis works from the APK.

Authority to authorise the work

You need to own the app or hold permission from whoever does. Recovery of a backend you are not entitled to use is not something we take on.

At upload the platform reads the APK manifest and reports the framework, the protection products it recognises, and the signing scheme it finds. That report is available before you pay, and it is the basis of the scope you confirm.

Where this gets hard

Heavily protected apps take longer, and some are genuinely not viable. Packers, native code virtualisation and integrity checks all add work, and a request signing key that only exists inside a hardware-backed keystore may not be recoverable at all. Where we can tell before payment, you are told before you pay. If a project turns out to be undeliverable after payment, the 14-day guarantee covers it.

Next step

Start with your APK

Upload takes a few minutes and ends with a scope report. You pay only after you have read it.

Want the background first? The technical guides cover how Android request signing, pinning and payload encryption are actually handled.