A typed SDK
Generated clients for Python and TypeScript, typed against the input fields each recovered endpoint declares.
APK to hosted API
Every project follows the same four stages. Upload takes minutes. The analysis between scope and delivery is the slow part, and it is done by hand.
Send the signed build you want the API for. The manifest is read on upload.
We report the framework, protections and signing scheme, then agree what will be recovered.
One payment for one project, once you have seen the scope report and accepted it.
You receive the SDK, documentation, keys and a live endpoint, and calls are metered from then on.
Deliverables
Everything below is handed over at delivery. Nothing here is optional or billed as an add-on.
Generated clients for Python and TypeScript, typed against the input fields each recovered endpoint declares.
A machine-readable description of every endpoint, so the API can be called from tools you already use.
What each workflow does, which fields it takes, what it returns, and what the upstream expects in return.
Keys are issued when the project is delivered and shown once. Any key can be revoked from the project page.
The platform runs the recovered connector, including request signing and payload encryption, so you never handle the crypto yourself.
Two things decide whether a project can start.
A build that installs and runs on a device or emulator. If your release pipeline produces an Android App Bundle, build a universal APK from it first, because the analysis works from the APK.
You need to own the app or hold permission from whoever does. Recovery of a backend you are not entitled to use is not something we take on.
At upload the platform reads the APK manifest and reports the framework, the protection products it recognises, and the signing scheme it finds. That report is available before you pay, and it is the basis of the scope you confirm.
Heavily protected apps take longer, and some are genuinely not viable. Packers, native code virtualisation and integrity checks all add work, and a request signing key that only exists inside a hardware-backed keystore may not be recoverable at all. Where we can tell before payment, you are told before you pay. If a project turns out to be undeliverable after payment, the 14-day guarantee covers it.
Next step
Upload takes a few minutes and ends with a scope report. You pay only after you have read it.
Want the background first? The technical guides cover how Android request signing, pinning and payload encryption are actually handled.