Model or dataset
littledivy/mimic avatar
littledivy/mimic

mimic: Turn Intercepted App Traffic into a Python API Client

Intercept any app, then call it from Python like a library

1,797 stars155 forksPythonMIT

At a glance

What is it?
littledivy/mimic is an MIT-licensed Python tool that captures HTTP traffic from a mobile or web app, extracts authentication credentials, and uses Claude to generate a typed Python client from the recorded endpoints. It is built for developers who want to script or automate personal app workflows without writing API wrappers by hand.
Who is it for?
mimic is a practical fit for a developer who wants to automate personal tasks on a mobile app that has no official API. The iOS capture path requires a Mac and a willingness to install a proxy certificate; the HAR and cURL paths work on any platform.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 68 days ago.
What is it written in?
Mainly Python, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 2, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What mimic Does and Who It Is For

Most apps authenticate requests with a stable bundle of values: a bearer token, some device IDs, a session ID, cookies. These values persist across API calls and can be captured once and reused to make new requests to the same API. mimic automates the entire pipeline from capture to usable Python code.

The README opens with a working example that shows the end result before explaining how to get there:

python
from hinge_client import Hinge

acc = Hinge()                 # reuses your captured session
recs = acc.get_recommendations()
acc.like(subject_id, comment="hi lol")

The file `hinge_client.py` is not written by the developer. mimic captures actual Hinge app traffic from an iPhone, extracts the authentication values, feeds the captured API calls to Claude, and Claude writes the client. The developer edits it like any other Python file and calls its methods.

The target user is a developer who wants to automate personal workflows on a mobile app that has no public API, without reverse-engineering binary protocols or writing HTTP wrappers from scratch.

The Three-Stage Pipeline: Capture, Extract, Generate

The README summarizes the pipeline in three steps:

code
capture traffic   ->   extract auth   ->   generate client
  (mitmproxy)         (mimic.Session)      (claude reads the
                                            captured endpoints)

The capture stage runs a local proxy (mitmproxy) that records every HTTP request the app makes. The extraction stage reads the captured auth values from the proxy's stored flows. The generation stage sends the captured endpoints and headers to Claude, which writes a Python class with named methods for each endpoint it saw.

The generated client is built on top of `mimic.App`, a base class in the mimic library. The client contains named methods, body templates, and multi-step call chains for APIs that require fetching a token in one request before spending it in another. Claude reads the captured traffic to infer these patterns.

Because the generated file is plain Python, the developer owns it. The README describes editing it like any other file; it can be committed to a repository, version-controlled, and reviewed like hand-written code.

Installing and Capturing iOS Traffic

Installation runs a shell script:

bash
sh install.sh

This installs `uv` if it is not already present, then installs mimic as an isolated tool. mitmproxy is not a separate install; mimic launches it via `uvx` on the first `mimic record` call. The alternative manual install is `uv tool install mimic-client`.

After install, verify the setup:

bash
mimic doctor                    # confirm proxy + claude are ready

For iOS app capture, start the proxy:

bash
mimic record                    # starts the proxy, prints the iPhone steps

The `record` command fills in the Mac's LAN IP and walks through four iPhone steps: configure a manual HTTP proxy to the Mac's IP on port 8080, install the mitmproxy CA certificate via Safari at `http://mitm.it`, then trust it in Settings under Certificate Trust Settings. The README notes that the trust step is easy to miss and nothing works without it.

Once the phone's traffic is flowing through the proxy, use the app normally, then run:

bash
mimic hosts                     # list captured hosts; pick your API host
mimic learn  prod-api.hingeaws.net    # see the endpoints mimic saw
mimic gen    prod-api.hingeaws.net    # generate hinge_client.py

The `mimic learn` step shows the endpoints captured for a given host. The `mimic gen` step calls Claude to generate the Python client.

Alternative Capture Backends: cURL and HAR

The mitmproxy path is the default for iOS apps. Two other capture backends handle different scenarios without requiring a proxy.

The cURL backend works for any app with a web version. In the browser developer tools, right-click a request in the Network tab and choose Copy as cURL, then paste the output into a Python string:

python
from mimic import Session

Session.from_mitm("prod-api.hingeaws.net")        # pull auth from mitmweb
Session.from_curl(open("copied.txt").read())      # paste "Copy as cURL" from devtools
Session(base_url="https://x.com", headers={...})  # explicit

No proxy, no certificate, no iPhone steps required for the cURL path.

The HAR file backend captures a full browser session. In Chrome or Firefox developer tools, open the Network tab, use the app, then right-click a request and choose Save all as HAR. Then:

bash
mimic hosts --har traffic.har
mimic gen api.example.com --har traffic.har

Or build a session directly in Python: `Session.from_har("traffic.har", "api.example.com")`. The HAR path works for any web app and requires no proxy infrastructure.

All three session types share the same `.get(path)`, `.post(path, json=...)`, and related HTTP verb helpers. Responses return parsed JSON and raise `requests.HTTPError` on failure. On a 401 response to an idempotent request, mimic automatically re-pulls the auth from mitmweb and retries once. Non-idempotent requests are not auto-retried unless you pass `refresh=True`.

Hard Limits: Certificate Pinning and DPoP Tokens

The README documents two auth schemes that block the approach, for different reasons.

Certificate pinning is a mitigation built into some apps: the app rejects any TLS certificate that does not match a hardcoded public key, including the mitmproxy certificate. Banking apps and Instagram use this. When an app pins its certificate, `mimic hosts` will show nothing because the proxy sees no traffic.

This blocks capture, not replay. If you can bypass the pin, the rest of the pipeline works normally. The `mimic unpin` command sets up a Frida-based bypass; the README references `docs/pinning.md` for details. Using a Frida-based certificate unpin requires more setup and may not work on all app versions.

DPoP (Demonstration of Proof-of-Possession) tokens are a fundamentally different problem. Each request carries a fresh cryptographic proof signed by a private key that never leaves the device. Captured requests using DPoP cannot be replayed on a new machine because the required private key is absent. The README states this defeats the core model, not just capture, and there is no clean workaround. See `docs/dpop.md`.

If `mimic hosts` shows the app's API hostname, certificate pinning is not in use and the pipeline will work.

Comparison with Using mitmproxy Directly

The obvious comparison is using mitmproxy directly, without mimic. mitmproxy is a mature interception proxy with a Python API, a terminal interface (mitmproxy), a web interface (mitmweb), and a scripting interface for inline request modification.

The difference is the code generation step. Using mitmproxy directly, you inspect captured requests and write Python code that recreates them manually: construct the correct headers, body format, and authentication parameters by hand. For an API with a dozen endpoints and a multi-step authentication flow, that is a few hours of work.

mimic replaces that writing step with a Claude call. The generated client may not be perfect, but it gives a typed starting point with named methods and extracted auth values. The developer edits the generated file rather than writing it from scratch.

For developers who want full control over every aspect of the client code, working with mitmproxy's Python scripting API directly is the more flexible path. mimic makes sense when the goal is a usable Python wrapper quickly rather than a polished library.

Ethics, Maintenance, and Licensing

The README includes an explicit ethics section: use mimic on your own accounts and data only. It replays your session; it is not a tool for accessing anyone else's. Respect each app's terms of service.

This is a meaningful constraint. Automating actions on a platform using mimic may violate the platform's terms of service even when the account is your own. The README flags this without resolving it; the legal risk varies by platform and jurisdiction.

The project has no GitHub releases. The version in `pyproject.toml` is `0.1.0`. The last push was on 2026-07-26, which is 63 days before this article was written, within the six-month window from today. The author is Divy Srivastava, and the package is published as `mimic-client` on PyPI. The dependency list is minimal: `requests>=2.28` is the only runtime dependency; `mitmproxy>=10` is optional, under the `capture` extra.

The license is MIT, with an explicit disclaimer that the software is provided as-is with no warranty, and that users are responsible for complying with each app's terms of service.

Editorial conclusion

mimic is a practical fit for a developer who wants to automate personal tasks on a mobile app that has no official API. The iOS capture path requires a Mac and a willingness to install a proxy certificate; the HAR and cURL paths work on any platform. Before capturing, run `mimic doctor` to confirm Claude and the proxy are configured. Apps that use certificate pinning, such as banking apps and Instagram, will not work at the capture stage without the `mimic unpin` Frida bypass, and apps that use DPoP sender-constrained tokens cannot be scripted at all with this approach. The project has no releases and was last pushed on 2026-07-26; treat the API as unstable.

Frequently asked questions

Does mimic work on Android apps?

The README documents the iOS capture path in detail, using mitmproxy and an iPhone proxy configuration. The README does not describe an Android-specific capture path; the HAR and cURL backends work independently of the mobile operating system for apps that have a web version.

Does mimic work with apps that use certificate pinning?

Certificate pinning blocks the mitmproxy capture step, because the app rejects the proxy certificate and no traffic appears in `mimic hosts`. The README documents `mimic unpin <ipa|bundle-id>` as a Frida-based bypass for pinning, with details in `docs/pinning.md`. Once the pin is bypassed, the rest of the pipeline works normally.

What Claude API key does mimic use for code generation?

The README mentions that `mimic doctor` confirms both the proxy and Claude are ready, indicating that Claude access is a setup prerequisite. The README does not document the specific environment variable or configuration file for the Claude API key; the `docs/` directory is referenced for detailed setup.

Official sources

  1. Issues
  2. License: MIT
  3. littledivy/mimic on GitHub
  4. README
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/littledivy-mimic.svg)](https://hysenlabs.com/projects/littledivy-mimic)