{"slug": "show-hn-app2api-give-your-ai-the-api-behind-your-app", "title": "Show HN: App2Api – Give your AI the API behind your app", "summary": "App2Api launched in free beta, capturing the real HTTPS API calls behind a mobile app workflow and returning a runnable flow.sh, an OpenAPI 3.1 spec, and an owner report so AI agents can call the app's API directly. The tool takes a plain-English goal, drives a live emulator with a vision planner to capture every HTTPS request including session bootstrap, tokens and attestation, and types credentials locally so they are never sent to a model. App2Api says it only accepts apps the requester owns or is explicitly authorized to test, and that each beta run is processed by hand, so results arrive by email after a queue-dependent wait.", "body_md": "Describe what you want your app to do, in plain English. App2Api captures the real API call behind it — login, tokens and all — and gives your AI agent an OpenAPI spec it can call.\n\nFree during the beta. No card, no setup.\n\nHow it works\n\nYou don't get a dump of everything the app happened to touch. You describe one workflow, and App2Api walks it end to end — then hands you a call you can reproduce standalone.\n\nSend the app and a plain-English goal — \"trigger the loyalty lookup,\" \"add an item to my cart.\" Any credentials are typed locally, never sent to a model.\n\nA vision planner drives a live emulator toward that goal, capturing every HTTPS call the app makes along the way.\n\nWhen the action fires, we find the request behind it and walk backward for everything it needs — session bootstrap, tokens, attestation.\n\nA runnable flow.sh, an OpenAPI 3.1 spec, and an owner report. Monitoring is coming in beta, so you'll know the moment an update breaks the chain.\n\nWhat you get\n\nEvery run hands back the same set — a call to run, a spec to build on, a report to share.\n\nThe runnable call with its full auth chain. Paste it into a terminal and it works standalone.\n\nAn OpenAPI 3.1 spec for the endpoints the workflow touched — drop it straight into your tooling.\n\nA shareable report of the captured requests, ready to hand to a teammate or a client.\n\nWho it's for\n\nWhether you build the app, test it, or ship on top of it, App2Api turns its API into something you can depend on.\n\nDocument your own app's real API surface, catch undeclared endpoints, and get a contract you can test against every release.\n\nTurn a manual workflow into a scripted, replayable call — and know the instant an app update changes the contract underneath it.\n\nTrace auth chains and attestation flows on your engagements, with an owner report you can hand straight to the client.\n\nFAQ\n\nNo. App2Api is for apps you own or are explicitly authorized to test. Every request includes an authorization confirmation, and we decline anything we can't reasonably believe is authorized.\n\nA runnable flow.sh, an OpenAPI 3.1 spec, and an owner report — the endpoint you asked for plus the full auth chain needed to replay it standalone.\n\nWe email you the traced call once your run finishes. During the beta we run each request by hand, so depending on the queue it can take a little while — you don't need to resubmit.\n\nLogin flows are supported — credentials are typed locally at the keystroke and never sent to a model. Some hardened apps (for example ones shipping certain integrity protections) may not run in the emulator, and we'll tell you when that's the case.\n\nNothing during the beta. We run it on our own infrastructure and email you the result.\n\nFree beta\n\nSend us an app you're authorized to test and the goal you're after, and we'll email you the traced call once it's done. It's free during the beta — and depending on the queue, it can take a little while.\n\nWe'll run it and email you the traced call. Depending on the queue that can take a while, so no need to resubmit — just keep an eye on your inbox.", "url": "https://wpnews.pro/news/show-hn-app2api-give-your-ai-the-api-behind-your-app", "canonical_source": "https://app2api.com/", "published_at": "2026-09-26 09:27:27+00:00", "updated_at": "2026-09-26 10:01:12.988126+00:00", "lang": "en", "topics": ["ai-agents", "ai-tools", "developer-tools", "agent-protocols"], "entities": ["App2Api", "OpenAPI 3.1"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/show-hn-app2api-give-your-ai-the-api-behind-your-app", "markdown": "https://wpnews.pro/news/show-hn-app2api-give-your-ai-the-api-behind-your-app.md", "text": "https://wpnews.pro/news/show-hn-app2api-give-your-ai-the-api-behind-your-app.txt", "jsonld": "https://wpnews.pro/news/show-hn-app2api-give-your-ai-the-api-behind-your-app.jsonld"}}