Headless

The same binary, on a machine you do not sit at.

apiaxess serve runs the workbench without the desktop shell and holds it open until you stop it. Useful when the host with the virtualisation, the disk, or the network position is not the host in front of you.

serve
$ apiaxess serve --port 7777
Ports

Two listeners, both loopback by default.

7777
The workbench interface, its HTTP API and the live sockets
8080
The MITM proxy — capture traffic, and the transport for resend and fuzzing
8000
Only with the Android add-on: the screen stream, on loopback behind the engine’s own proxy
Override
APIAXESS_GUI_ADDRESS and APIAXESS_PROXY_ADDRESS, both of which refuse a non-loopback address
Exposure

One flag can put the workbench on the network. Think before using it.

The environment overrides reject anything that is not loopback. serve --host is the deliberate exception — the one way to bind the interface to an address other people can reach. It exists because remote hosts are real, and it is the operator’s call, not the product’s.

Make that call carefully. Most of the control plane relies on the loopback boundary for its protection rather than checking a token on every request; the pairing and Android-target routes are the ones that gate individually. Bound to an interface, the workbench is as reachable as the network makes it.

Put something in front of it
The safer shape is to leave apiaxess on loopback and reach it through an SSH tunnel, or place an authenticating reverse proxy in front of it. Do not expose port 7777 or 8080 to an untrusted network and rely on the application to sort out who is calling.
Host

What the machine needs.

OS
Windows x64 or Linux amd64. There is no arm64 build
Web capture
No special hardware — it is a bundled Chromium and a proxy
Android target
Virtualisation for acceleration: KVM on Linux, WHPX, Hyper-V or AEHD on Windows. Without it, the emulator runs in software: correct, much slower
Memory
At least 2 GB free for the emulator itself, on top of whatever the host needs
Disk
Emulator boot checks free space first; the floor is configurable with APIAXESS_EMULATOR_MIN_FREE_MB
Environment

Overrides that matter on a server.

The bundled tools are used unless you point at your own. Paths given here are used as-is, which is how you swap in a host Java or a specific jadx build.

selected environment variables
APIAXESS_GUI_ADDRESS        workbench bind address (loopback only)
APIAXESS_PROXY_ADDRESS      proxy bind address (loopback only)
APIAXESS_ALLOWED_TARGETS    scope for the running session
APIAXESS_WORKBENCH_STORE_DIR  where the session SQLite store is kept
APIAXESS_CHROMIUM           use this Chromium instead of the bundled one
APIAXESS_JAVA               use this Java runtime
APIAXESS_APKTOOL            use this apktool
APIAXESS_JADX               use this jadx
APIAXESS_ANDROID_TARGET     path to the Android add-on payload
APIAXESS_EMULATOR_MIN_FREE_MB  disk floor before the emulator boots
Before you script it

Automate the CLI, not the HTTP API.

analyze, web, inspect and export all take --json, which is the supported way to drive apiaxess from a pipeline. The workbench’s own HTTP API is internal and free to change — more on that here.