apiaxess is a zero-setup API inspection tool that ships with a preconfigured Chromium browser and an Android environment that already trust its proxy certificate, so you install an APK or use the built-in browser and immediately capture decrypted traffic. It captures both mobile and web clients, merges endpoints, shows live flows (example session: 2,481 flows, 128 endpoints merged, nine endpoints seen only from the app), and offers an interactive workbench to replay, resend or fuzz requests with four attack types and no throttling. Sessions can be exported to OpenAPI 3.1, Postman, HAR and a Python client with one command. The UI labels requests by host, method, status and authorization, and prevents test traffic from contaminating the recovered API surface.
Claims are measured: a reference Android app with 17 documented endpoints was used to score apiaxess, which found 17/17 statically, decrypted 17/17 live, and fused 17/17 confirmed endpoints. Endpoints are marked confirmed or inferred and first- or third-party; the tool reports when pinning cannot be bypassed instead of producing false positives. It is open source under Apache-2.0, cross-platform (Windows, Linux, macOS), invites code inspection (no telemetry), and targets integration into API security and reverse-engineering workflows.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.