Private API Identification Needed

Job ID: 40547468

Budget: ₹100 – ₹400 INR

I’m looking for someone who can track down and document the specific private APIs behind the Starmaker platform. My sole objective is to locate those exact endpoints—no comparisons or public catalogues, just the real calls the app already makes under the hood.

You’ll need to observe the traffic (Charles Proxy, Wireshark, or a similar sniffer), identify every relevant request, work out the auth flow, then hand back clean, repeatable examples I can drop straight into Postman or a custom script.

Deliverables
• A list of discovered endpoints with full URLs, required headers, and query/body parameters
• Step-by-step authentication sequence (tokens, refresh logic, cookies—whatever Starmaker relies on)
• Sample JSON/XML responses for each call, captured live and redacted only where sensitive
• A short test collection or cURL bundle proving each endpoint works outside the original app

Acceptance criteria: each endpoint must be callable from an independent environment and return data consistent with the live service. If a particular call can’t be triggered without device-side encryption or obfuscation, note the limitation and any workaround.

Let me know your expected timeline and any similar reverse-engineering work you’ve done so I can gauge fit quickly.