{"repo":"mitmproxy/android-unpinner","free":true,"listed":false,"github":"https://github.com/mitmproxy/android-unpinner","clone":"git clone https://github.com/mitmproxy/android-unpinner.git","description":"Remove Certificate Pinning from APKs","language":"Python","stars":1029,"topics":["android","reverse-engineering","mitm","mitmproxy","apk","certificate-pinning","frida","jdwp"],"license":null,"category":"mobile-apps","readme_excerpt":"Android Unpinner This tool removes certificate pinning from APKs. - Does not require root. - Uses frida-apk to mark app as debuggable. This is much less invasive than other approaches, only AndroidManifest.xml is touched within the APK. - Includes a custom Java Debug Wire Protocol implementation to inject the Frida Gadget via ADB. - Uses HTTPToolkit's excellent unpinning script to defeat certificate pinning. - Already includes all native dependencies for Windows/Linux/macOS ( adb , apksigner , zipalign , aapt2 ). - Handles XAPKs by extracting the split APKs, unpinning them and installing them with adb install-multiple . The goal was not to build yet another unpinning tool, but to explore some newer avenues for non-rooted devices. Please shamelessly copy whatever idea you like into other tools. :-) Installation Using uv, you can install the tool with a single command: Alternatively, you can install it manually: Usage Connect your device via USB and run the following command. See android-unpinner --help for usage details. You can pull APKs from your device using android-unpinner list-packages and android-unpinner get-apks . Alternatively, you can download APKs from the internet, for example manually from apkpure.com or automatically using apkeep. Comparison Compared to using a rooted device, android-unpinner... 🟥 requires APK patching. 🟩 does not need to hide from root detection. Compared to apk-mitm , android-unpinner... 🟥 requires active instrumentation from a desktop mach","default_branch":null,"files":null,"tree":[],"storefront":"/r/mitmproxy","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/mitmproxy/android-unpinner/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}