Quickstart

From installer to exported schema.

Five steps. Everything runs on your machine, there is no account, and the only thing you need to decide up front is which host you are allowed to test.

Walkthrough
  1. Install

    Download the Windows .msi or the Linux .deb from the download page. The installers are not code-signed yet. SmartScreen will ask on first run: More info → Run anyway.

    Or install from the command line. On Windows, with Scoop:

    scoop
    $ scoop bucket add apiaxess https://github.com/KatrielMoses/scoop-apiaxess
    $ scoop install apiaxess/apiaxess

    On Debian or Ubuntu, from the downloaded package:

    apt
    $ sudo apt install ./apiaxess_0.1.0_amd64.deb

    Verify your download against its published SHA-256 checksum.

    Web capture needs nothing else: the capture Chromium is in the box. APK analysis and the Android target each use an add-on (about 1.2 GB and 1.3 GB), downloaded in the app when you click to get it.

  2. Start the workbench

    Run apiaxess with no arguments. It serves the interface on loopback and prints where everything landed, including the fingerprint of the certificate authority it generated for this session.

    startup
    APIaxess workbench is ready
    gui_address=127.0.0.1:7777  proxy_address=127.0.0.1:8080
    ca_fingerprint=<64-hex>
    store=…\apiaxess\workbench\session-<digest>\traffic.sqlite3
  3. Declare what you are allowed to test

    Set the engagement scope before you capture. Hosts can be exact, or a wildcard suffix such as *.northwind-retail.io. Scope labels every flow rather than blocking anything, so this is the record of your authorisation, not a safety net.

  4. Capture

    Start a web session and drive the site in the browser that opens. Flows appear in the workbench queue as the proxy finishes them.

    capture a site
    $ apiaxess web northwind-retail.io --authorize --output ./session.json

    --authorize is required. It is you stating that you have permission to test this target.

  5. Export the surface

    When the session has enough traffic, write it out. --format all produces every artefact at once.

    export
    $ apiaxess export ./session.json --format all --out ./out
    ./out/openapi.json
    ./out/postman.collection.json
    ./out/traffic.har.json
    ./out/python-sdk/
    ./out/apiaxess-evidence.json
Analysing an APK

The other way in.

If you have the application package rather than a live site, run the analysis pipeline instead. It is static by default; dynamic enrichment is requested explicitly and uses evidence from a session.

analyze an apk
$ apiaxess analyze ./northwind-4.2.1.apk \
    --allow-target api.northwind-retail.io \
    --output ./session.json \
    --json
Where sessions live
Session state is a SQLite file under your local application data directory. Scratch space from an analysis run is cleaned up when the run ends, with a second sweep for anything older than a day.