From installer to exported schema.
Five steps. Everything runs on your machine, there is no account, and the only thing you need to decide up front is which host you are allowed to test.
Install
Download the Windows
.msior the Linux.debfrom the download page. The installers are not code-signed yet. SmartScreen will ask on first run: More info → Run anyway.Or install from the command line. On Windows, with Scoop:
$ scoop bucket add apiaxess https://github.com/KatrielMoses/scoop-apiaxess $ scoop install apiaxess/apiaxess
On Debian or Ubuntu, from the downloaded package:
$ sudo apt install ./apiaxess_0.1.0_amd64.deb
Verify your download against its published SHA-256 checksum.
Web capture needs nothing else: the capture Chromium is in the box. APK analysis and the Android target each use an add-on (about 1.2 GB and 1.3 GB), downloaded in the app when you click to get it.
Start the workbench
Run
apiaxesswith no arguments. It serves the interface on loopback and prints where everything landed, including the fingerprint of the certificate authority it generated for this session.APIaxess workbench is ready gui_address=127.0.0.1:7777 proxy_address=127.0.0.1:8080 ca_fingerprint=<64-hex> store=…\apiaxess\workbench\session-<digest>\traffic.sqlite3
Declare what you are allowed to test
Set the engagement scope before you capture. Hosts can be exact, or a wildcard suffix such as
*.northwind-retail.io. Scope labels every flow rather than blocking anything, so this is the record of your authorisation, not a safety net.Capture
Start a web session and drive the site in the browser that opens. Flows appear in the workbench queue as the proxy finishes them.
$ apiaxess web northwind-retail.io --authorize --output ./session.json
--authorizeis required. It is you stating that you have permission to test this target.Export the surface
When the session has enough traffic, write it out.
--format allproduces every artefact at once.$ apiaxess export ./session.json --format all --out ./out ./out/openapi.json ./out/postman.collection.json ./out/traffic.har.json ./out/python-sdk/ ./out/apiaxess-evidence.json
The other way in.
If you have the application package rather than a live site, run the analysis pipeline instead. It is static by default; dynamic enrichment is requested explicitly and uses evidence from a session.
$ apiaxess analyze ./northwind-4.2.1.apk \
--allow-target api.northwind-retail.io \
--output ./session.json \
--json