Pinned apps, captured. No favours from the dev team.

Read an APK before it runs, then capture it live on an emulator that already trusts you.

Run the Android target

An emulator you never had to prepare.

apiaxess
FileCaptureViewHelp
Go to surface, flow, endpoint or command⌘K
api.northwind-retail.ioLive control connected
Input · Android target

Android target

Launch the bundled Android target, install the app you want to explore, and drive it on the embedded screen. Its traffic flows into this workbench.

StatusRUNNING
ImageAndroid 13 · API 33 · AOSPSystem CA● TrustedPinningHandledAppio.northwind.retail 4.2.1
ScreenSTREAMING
14:41NORTHWIND
Checkout
Deliver toManchester M15
PaymentCard ···· 4417
Place order
Intercept queue 0Diagnostics 0Control · reliable
No paused requestsWith intercept on, matching requests pause here until you forward, modify or drop them.
ANDROID TARGETsession:2l1a434f3f6b1aControlTelemetry127.0.0.1
  1. A headless Android 13 emulator. No adb, no rooting. It's an add-on: download it in the app when you first need it.

Read an APK

Its endpoints, straight from the code.

apiaxess
FileCaptureViewHelp
Go to surface, flow, endpoint or command⌘K
api.northwind-retail.ioLive control connected
Input · Android APK

APK analysis

Point the engine at an APK on this machine and run the pipeline. Each stage contributes facts; the fused surface is assembled from all of them.

View surface
ArtifactREADY
APK path
C:\work\northwind-4.2.1.apk
Packageio.northwind.retailAcceptsAPK · split APKs · XAPK
Analysis pipelineIDLE
  1. 1Unpack
  2. 2Decompile · jadx
  3. 3Extract network facts
  4. 4Dynamic pass
  5. 5Fuse into the surface
Intercept queue 0Diagnostics 0Control · reliable
No paused requestsWith intercept on, matching requests pause here until you forward, modify or drop them.
APK ANALYSISsession:2l1a434f3f6b1aControlTelemetry127.0.0.1
  1. APK, split APKs or XAPK. The analysis runtime is an add-on you download once, in one click.

Or pair a real phone

A rooted device joins the same session.

apiaxess
FileCaptureViewHelp
Go to surface, flow, endpoint or command⌘K
api.northwind-retail.ioLive control connected
Input · Android device

Devices

Pair a rooted Android device with this workbench. Arm a device to show a QR the client scans, then accept its request to join the session.

Attached devices0 ATTACHED
No devices attachedArm pairing, then scan the code from the client app.
Pairing codeARMED
CA fingerprint · 4F:21:9C:0B:…:E7:3A
Intercept queue 0Diagnostics 0Control · reliable
No paused requestsWith intercept on, matching requests pause here until you forward, modify or drop them.
DEVICESsession:2l1a434f3f6b1aControlTelemetry127.0.0.1
  1. Show a pairing code for a rooted Android device, 7.0 or newer.

The details

Android
13 (API 33), AOSP image, no Google Play Services
Devices
Rooted, Android 7.0 (API 24) and newer, paired by QR code
Virtualization
KVM on Linux; Hyper-V, WHPX or AEHD on Windows. Slower software mode without it
Recommended
8 GB RAM, 4 vCPUs
Add-on
The Android target (about 1.3 GB) downloads from apiaxess.dev when you click to get it: resumable, checked against its SHA-256, and installed for your user only
or from the command line
$ apiaxess analyze ./northwind-4.2.1.apk --allow-target api.northwind-retail.io --json

--allow-target is the same authorisation affirmation capture uses.

Point it at an app. Read the API.