APKScan: static Android APK analysis as a JSON API

Send a URL to any .apk file. Get back a machine-readable security and structure report: package identity, version, min/target SDK, all requested permissions with risk flags (SMS, contacts, camera, location, overlay, debuggable, allowBackup), every exported component (activities, services, receivers, providers), deep links, and the launcher activity.

Endpoint: GET /analyze?url=<apk-url> - $0.02 per call in USDC on Base via the x402 payment protocol. An unpaid request returns HTTP 402 with payment details; any x402 client can pay and retry.

Example report shape

{
  "package": "com.example.app",
  "versionName": "1.2.3",
  "minSdk": 24, "targetSdk": 34,
  "permissions": [{"name": "android.permission.CAMERA", "risk": "use camera"}],
  "riskFlags": ["2 exported component(s) reachable by any other app..."],
  "exported": {"activities": [...], "services": [...], "receivers": [...], "providers": [...]},
  "deepLinks": [{"component": "...", "scheme": "https", "host": "example.com"}],
  "mainActivity": "com.example.app.MainActivity"
}

No app upload needed - just a publicly reachable APK URL. Useful for security researchers, app-buyer due diligence, SDK audits, and malware triage pipelines.