{"repo":"b-erdem/rekit","free":true,"listed":false,"github":"https://github.com/b-erdem/rekit","clone":"git clone https://github.com/b-erdem/rekit.git","description":"Reverse Engineering Toolkit for Mobile APIs — 14 tools: traffic capture, client generation, TLS/HTTP2 fingerprinting, bot detection, token analysis, auth flow mapping, protobuf decoding, JS bundle scanning, cert pinning bypass, rate limit probing, mock servers, schema comparison","language":"Python","stars":11,"topics":["android","api","apk","bot-detection","curl-cffi","frida","har","mitm","mobile","python"],"license":"MIT","category":"mobile-apps","readme_excerpt":"rekit Reverse Engineering Toolkit for Mobile APIs. 14 focused tools for the mobile API reverse engineering pipeline: capture traffic, map endpoints, test fingerprints, detect bot protection, compare schemas, generate clients, mock servers, analyze tokens, map auth flows, decode protobuf, scan JS bundles, probe rate limits, bypass cert pinning, and fingerprint HTTP/2. Why rekit? Reverse engineering mobile APIs is a multi-step process with lots of manual work between each step. Existing tools (mitmproxy, jadx, frida) are great at individual steps but nothing connects the pipeline. rekit fills the gaps: - No more manual HAR-to-client translation — hargen generates typed Python clients automatically - No more proxy/cert pinning headaches — apktap hooks at the app layer, above TLS; certpatch generates targeted bypass scripts - No more grepping through 40K decompiled files — apkmap and jsbundle find the API surface for you - No more guessing why you're getting 403s — ja3probe , botwall , and headerprint tell you exactly what's blocking you - No more hand-mapping 25 different response schemas — schemadiff builds the unified model - No more copy-pasting JWTs into jwt.io — tokendump decodes every token in your traffic - No more manually figuring out auth flows — authmap maps OAuth2, session cookies, API keys, and generates auth modules - No more hitting live APIs during development — mockapi replays captured traffic as a local server - No more binary protobuf gibberish — protorev deco","default_branch":null,"files":null,"tree":[],"storefront":"/r/b-erdem","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/b-erdem/rekit/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}