Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
••
Linux Tipps & HardeningCPU Graph, a scrubbable adjustable CPU monitor(30.09.2026 um 21:25 Uhr)
••
Linux Tipps & HardeningLinux 7.2.2 on iPhone XS? First boot!(30.09.2026 um 22:12 Uhr)
••
Linux Tipps & HardeningMinecraft Dungeons 2 fix for linux(01.10.2026 um 00:49 Uhr)
••
Linux Tipps & HardeningEuropean Citizens' Initiative(01.10.2026 um 04:15 Uhr)
••••
Linux Tipps & HardeningCPU Graph, a scrubbable adjustable CPU monitor(30.09.2026 um 21:25 Uhr)
••
Linux Tipps & HardeningLinux 7.2.2 on iPhone XS? First boot!(30.09.2026 um 22:12 Uhr)
••
Linux Tipps & HardeningMinecraft Dungeons 2 fix for linux(01.10.2026 um 00:49 Uhr)
••
Linux Tipps & HardeningEuropean Citizens' Initiative(01.10.2026 um 04:15 Uhr)
••
Intelligence View
⚡ tsecurity.de Intelligence

Reverse-engineering undocumented APIs with Claude

🔗 Project: https://github.com/kalil0321/reverse-api-engineer Many websites expose public APIs, but they’re often undocumented, poorly documented, or inte…

Beitrag
0
Seite
0
↗ Quelle (dev.to)
Social ReaktionenReagiere als Erste:r — dein Feedback zählt!

reverse-api-engineer demo



🔗 Project: https://github.com/kalil0321/reverse-api-engineer



Many websites expose public APIs, but they’re often undocumented, poorly documented, or intentionally hard to find.



I’m currently building Stapply Map, a job aggregator that shows jobs on a map (https://map.stapply.ai), and I needed data. Most ATS platforms do have public APIs, but discovering how to use them usually means digging through network requests and reverse-engineering things manually.



So I started doing what many of us do:

open DevTools → inspect network → copy requests → paste them into Claude → manually turn them into a usable API client.



That worked, but it felt very repetitive.



What if I automated this?









The idea



I started building reverse-api-engineer: a tool that helps reverse-engineer APIs using Claude.



The initial flow was simple:




  1. You enter a query

  2. A browser opens with HAR recording enabled

  3. You navigate the website manually

  4. The HAR file is saved

  5. Claude Code analyzes it and generates an API client



This already worked well but I wanted to push the automation further.









Adding an agent mode



So I started experimenting with an agent mode, where an agent controls the browser directly and performs actions on your behalf.



I first tried:




  • browser-use

  • Stagehand



They worked, but weren’t ideal for this use case:




  • they rely on external libraries

  • native HAR recording support is missing for browser-use

  • integration was not clean for programmatic reverse-engineering, we had to do a 2 step pipeline (har recording with automation framework, then codegen with Claude)

  • the network requests could be unsufficient for the engineer to build the API client









Moving to Playwright MCP



At that point, I realized that Playwright MCP was actually a very good foundation and the only missing piece was HAR recording.



So I forked Playwright MCP and added it.



👉 I published this as v0.2.9, with built-in HAR support, and the results were already much better.



Now the flow looks like this:




  1. Claude (or another agent) controls the browser via MCP

  2. Actions are executed automatically (search, click, paginate, filter)

  3. Network traffic is recorded as HAR

  4. Claude analyzes the requests

  5. A structured API client is generated









What it can extract today




  • public but undocumented API endpoints

  • query parameters & payloads

  • pagination logic

  • filters and search behavior

  • required headers

  • request dependencies

  • session patterns



This works especially well for:




  • job boards

  • ATS platforms

  • dashboards

  • internal tools

  • search-heavy web apps









Roadmap



Here’s what I’m planning next:




  • collector mode (ie send a complex query and get the data directly + code)

  • a registry of apis to make it easier to discover already reverse-engineered APIs (users can opt-in)






🔗 Project: https://github.com/kalil0321/reverse-api-engineer



Feedback, ideas, and suggestions are very welcome!

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Reverse-engineering undocumented APIs with Claude

Thematisch verwandte Begriffe: Reverseengineering, undocumented, APIs, with · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag