
The API security workbench for web & Android
apiaxess is a free, open-source API security workbench for analysing the API surface of web and Android applications. It bundles a browser and an Android emulator that are already routed through its proxy and trust its certificate, so captured traffic, static APK analysis and a replay/fuzz workbench all land in one session with no manual setup.
Uses its own Chromium on an isolated profile routed through the proxy, so your own browser is never touched and the certificate is already trusted.
A pre-prepared Android emulator that boots already trusting the certificate — install an APK, drive the app, and read its traffic, including certificate-pinned apps where possible.
Recovers endpoints directly from app code (tested against Retrofit, OkHttp, HttpURLConnection and GraphQL, including third-party hosts and calls behind taps).
Merges static and live capture so every recovered endpoint can be confirmed by both sources; in a reference test app with 17 documented endpoints it found 17/17 statically, 17/17 live, and 17/17 fused, with zero phantom endpoints.
Replay any captured request, run Intruder-class fuzzing with four attack types and no throttling, and intercept matching requests to forward, modify or drop them.
Generate OpenAPI 3.1, Postman, HAR and a Python client from one command.
Endpoints are labelled confirmed or inferred-from-code, first-party or third-party; your own Resend/Fuzz traffic doesn't leak into the recovered surface; sessions include live traffic stats, diagnostics and audit views.
Apache-2.0 licensed open source — the certificate generation can be reviewed, there is no telemetry, and you can build it yourself.
Choose a target: the built-in Chromium browser (web) or the bundled Android emulator with a pre-trusted certificate (mobile), or analyse an APK statically.
Traffic is decrypted live while the app runs; static analysis recovers endpoints from code; the two views are fused so each endpoint is confirmed by both.
Browse flows and merged endpoints, resend requests, queue intercepted traffic, and fuzz endpoints with four built-in attack types.
Leave with a spec rather than a screenshot: OpenAPI 3.1, Postman, HAR or a Python client from a single command.
Free and open source, Apache-2.0 licensed. Version 0.1.0 is downloadable for Windows, Linux and macOS.
It recovers the API surface of web and Android apps: a browser and Android emulator already routed through its proxy capture live traffic, APK analysis recovers endpoints from code, and the workbench lets you resend, intercept and fuzz requests before exporting a spec.
It is free and open source, licensed under Apache-2.0.
Desktop builds for Windows, Linux and macOS are available for download (v0.1.0).
Mobile capture targets an Android emulator that ships pre-trusting the certificate; iOS is not mentioned as supported.
Yes — pinned apps are explicitly supported ('Pinned apps included'), though for apps whose pinning can't be beaten, apiaxess tells you so rather than showing an empty list.
No — web capture uses apiaxess's own Chromium on an isolated profile routed through the proxy; your browser is never touched.
It's Apache-2.0 open source, the certificate generation is documented for review, there is no telemetry, and you can build it yourself.
OpenAPI 3.1, Postman, HAR and a Python client, from one command.