Submit any public APK URL. Get back, as JSON: package name, versionName / versionCode, min / target SDK, the full requested-permission list, uses-features, application label, and which signing schemes (v1) the APK carries — parsed from the binary manifest with no Android toolchain required.
GET /analyze?url=https://example.com/app.apk — $0.05 per call in USDC on Base, paid with the x402 protocol. An unpaid request returns HTTP 402 with payment details; any x402 client (or Coinbase's) completes it automatically.
Example response:
{
"url": ".../app.apk",
"analysis": {
"package": "com.tw.clipshare",
"versionName": "4.2.0",
"versionCode": 40200,
"minSdk": 28,
"targetSdk": 34,
"permissions": ["android.permission.INTERNET", ...],
"signing": { "v1Signed": true, "v1SchemeFiles": [...] },
"fileCount": 515
}
}
Typical uses: security scanners triaging samples, app-store catalogues, CI pipelines that need APK facts before download decisions.