We built a reference Android app with 17 documented endpoints (Retrofit, OkHttp, HttpURLConnection and GraphQL, plus a third-party host and calls behind taps and a second screen) and scored apiaxess against it.
Static17/17
Found from the code, zero phantom endpoints.
Live capture17/17
Decrypted while the app ran.
Fused17/17
Each one confirmed by both.
Capture both clients. Keep the evidence.
01Mobile
A phone you never had to prepare.
Boots already trusting the certificate. Install an APK, drive it, read the traffic. Pinned apps included.
02Web
A browser that already trusts you.
Its own Chromium on an isolated profile, routed through the proxy. Your browser is never touched.
03Workbench
See it live. Resend it. Fuzz it.
Replay any request, or run a full Intruder-class attack. Four attack types, no throttling.
04Export
Leave with a spec, not a screenshot.
OpenAPI 3.1, Postman, HAR and a Python client, from one command.
It won’t make things up.
Every endpoint is labelled confirmed or inferred-from-code, first-party or third.
Your own Resend and Fuzz traffic never leaks into the recovered surface.
And when something can’t be done, like an app whose pinning can’t be beaten, apiaxess tells you so instead of showing you an empty list.
Nine endpoints a browser-only session never sees.
Open source. Read every line.
Apache-2.0 licensed. Check how the certificate is made, confirm there’s no telemetry, build it yourself.