# Reverse API Engineer: turning a site's own network traffic into a typed API client

> Reverse API Engineer captures the requests a site already makes and has an AI model write a client for them. It is a code generator for people who would otherwise copy cURL commands out of DevTools by hand.

**nottelabs/reverse-api-engineer** — The agent that turns websites into APIs!

- Repository: https://github.com/nottelabs/reverse-api-engineer
- Website: https://reverseapi.dev
- Stars: 1,209 · Forks: 111
- Language: Python
- License: MIT
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/nottelabs-reverse-api-engineer

## The gap between a page and the endpoint behind it

Most modern sites render from JSON. The browser fetches a tidy endpoint, then paints it. What you get from the outside is HTML, which is a lossy view of the same data. Reverse API Engineer targets that gap: instead of parsing markup, you record the requests the page already makes.

The README frames the workflow around a goal rather than a URL. You give it a site and something like "fetch all Apple jobs from their careers page"; a browser visits, traffic is captured to a HAR file, and your configured model reads the capture and writes a client. The stated output languages are Python, JavaScript, TypeScript, Go, Java, C#, PHP, Ruby and C. The pitch is aimed at people who currently open DevTools, copy cURL, and glue a client together by hand. It is a code generator, not a crawler and not a proxy. The repository is MIT licensed and the package declares Development Status 4 - Beta.

## Capture, HAR, generation: the three stages

The pipeline is short and worth understanding before you trust it. Stage one is browsing. Stage two is capture: network traffic lands in a HAR file. Stage three is generation, where the model reads the capture and emits a client directory.

Modes decide who drives stage one. In manual mode you drive the browser yourself and the AI only generates from the captured traffic. In agent mode an AI agent drives capture on its own. There is also an engineer mode that re-runs generation against a previous capture, addressed by run id, and a collector mode where the agent gathers structured data as JSON or CSV using web search and fetch.

Agent mode is the default and it does not use a local Playwright install. It captures through npx-launched browser tooling: browser MCP servers (Playwright or Chrome DevTools) or the Vercel agent-browser CLI. The provider setting is auto by default, which the README describes as Playwright MCP with a single workflow for browsing and reverse engineering. chrome-mcp drives your real Chrome so existing sessions and cookies carry over, and the README states it requires Chrome 146+ and Node.js 20.19+. That session reuse is the difference between capturing a logged-in dashboard and capturing a login wall.

## Installing it and generating a first client

The base install is deliberately light. Since v0.12.0 Playwright became optional, so agent mode needs no extra Python packages. The README gives two equivalent install routes:

```bash
uv tool install reverse-api-engineer   # or: pip install reverse-api-engineer
```

Python 3.11 or newer is required. If you want manual mode, where you drive a local Playwright browser yourself, install the extra and its Chromium build:

```bash
uv tool install "reverse-api-engineer[manual]"   # or: pip install "reverse-api-engineer[manual]"
playwright install chromium
```

Then run the CLI with no arguments and type your goal. The README's quick start shows the browser opening, you navigating and interacting, and closing it when done:

```bash
reverse-api-engineer
> fetch all apple jobs from their careers page
```

According to the README, the result lands in ./scripts/apple_jobs_api/ containing api_client.py, README.md and example_usage.py. The generated README and example file are the part to read first: they tell you which endpoint the model settled on and how it authenticated. Shift+Tab cycles between the manual, agent, engineer and collector modes. Settings live in ~/.reverse-api/config.json and are editable from /settings inside the CLI. The keys you are most likely to touch are agent_provider, output_language, sdk and output_dir:

```json
{
  "agent_provider": "auto",
  "output_language": "python",
  "sdk": "claude",
  "output_dir": null
}
```

The sdk key accepts claude, opencode, cursor or copilot. Output language accepts python, javascript, typescript, go, java, csharp, php, ruby or c. The README notes that C needs a POSIX toolchain (cc and libcurl headers), so macOS, Linux, or WSL/MSYS2 on Windows.

## What it does not do for you

The generated client is a snapshot, not a contract. It reproduces the requests that happened during one capture session. If the site changes a query parameter, rotates a token, or moves to a different endpoint the next week, the client keeps calling the old shape until someone notices. Nothing in the described workflow watches for that drift.

Capture is also the failure point. Endpoints that only appear after a login, a scroll, or a specific interaction are missed unless you performed that interaction during capture. Agent mode mitigates this by letting the agent browse, but the agent still has to reach the state. chrome-mcp exists precisely because some sites need your real browser profile, which is an admission that a clean browser session is often not enough.

There is a cost dimension the README acknowledges rather than hides: /history lists past runs with timestamps, costs and status. Generation is a model call over a HAR file, and HAR files are large. A capture of a media-heavy page can be far bigger than the endpoint you wanted.

The bigger constraint is not technical. Reverse engineering a site's private endpoints sits in a legal and contractual grey zone. The README does not discuss terms of service, rate limits, or robots directives, and it does not document any consent or robots check before capture. That silence is not permission. If the endpoint is not public and documented, the tool being capable of reaching it says nothing about whether you may call it.

## Where it sits next to Postman and OpenAPI tooling

People searching for API reverse engineering usually arrive from two directions: Postman's interceptor-style capture, or OpenAPI spec generation from an existing service.

The difference in approach is the input. Postman captures requests you make and stores them as a collection you then hand-maintain; the collection is a record, and any client code is something you write or generate separately. Reverse API Engineer starts from a goal and a browser session, and its output is source code in one of nine languages, not a collection. The model reads the traffic and decides what the client should look like, including which request in the HAR actually carries the data.

Against OpenAPI generators, the direction is reversed. Those tools take a spec and produce a client, and they are only as good as the spec. Reverse API Engineer produces a client when no spec exists, which is the common case for a site you do not control. The trade-off is that a spec is a promise and a capture is an observation.

## Model backends, local models and the OpenCode path

The default sdk is claude, with claude-sonnet-4-6 as the default model for both the main flow and the collector. The README lists Opus 4.6 as the most capable and Haiku 4.5 as the fastest. That is a straightforward quality-versus-latency dial on the generation step.

The OpenCode path is more interesting. With sdk set to opencode, the tool reuses an existing OpenCode server or downloads and starts opencode-ai@latest through npx, so a global OpenCode installation is not required. Fresh configurations default to the free opencode/big-pickle model. Before creating a session it validates the saved provider and model pair and suggests currently available free models when the configuration is invalid. Node.js 20+ is required for automatic startup, and password-protected servers use OPENCODE_SERVER_PASSWORD with an optional OPENCODE_SERVER_USERNAME.

Ollama is reached through OpenCode rather than directly. Choosing provider ollama in /settings makes the tool start an installed daemon if needed, list only installed models that support tool calling and 64k+ context, and supply OpenCode's provider config inline. The README is explicit that models are never downloaded silently. That constraint is sensible, and it also means a local setup is limited to models you have already pulled that clear the tool-calling and context bar.

## Maintenance, licence and what upgrading costs

The last push to the default branch was on 2026-08-30, and v0.13.1 shipped the same day with a fix for a missing httpx dependency on fresh installs. That release note is worth reading as a warning about the base install: dependency gaps have reached users before. If you pin the package, pin it deliberately and test the install in a clean environment rather than trusting an existing virtualenv.

The version history shows the maintainers willing to move weight around. v0.12.0 made Playwright optional and moved to a lightweight base install; v0.13.0 added a client_executed json-stream event. Both are structural changes to how the tool runs, so a minor version bump is not automatically a drop-in. Read CHANGELOG.md before upgrading, and note that pyproject.toml still declares version 0.13.0 while the latest release is v0.13.1.

The MIT licence covers the tool itself. It does not cover the sites you point it at, the data you capture into HAR files, or the terms you agreed to when you signed up for those sites. HAR files routinely contain cookies, authorization headers and personal data, and the README does not describe a redaction step. Treat a capture directory the way you would treat a credential file. None of this is legal advice; if the target site's terms matter to your organisation, that question is separate from the licence question.

## Conclusion

Adopt Reverse API Engineer if you need repeatable clients for sites whose private endpoints you are allowed to call, and you already have a model SDK configured. Do not adopt it if you need a stable, documented contract: the generated client tracks whatever the site did during capture, and the next redesign can break it. Before writing code, confirm which agent provider your sessions and cookies require, and check whether the target site's terms permit automated access.

## FAQ

### What is Reverse API Engineer?

It is a Python CLI that turns a website into an API client. A browser visits the site, network traffic is captured to a HAR file, and a configured model reads that traffic and writes a working client in one of nine languages.

### How do I install Reverse API Engineer?

The README gives two routes: uv tool install reverse-api-engineer or pip install reverse-api-engineer. Manual mode, which drives a local Playwright browser, needs the [manual] extra plus playwright install chromium. Python 3.11 or newer is required.

### Which programming languages can Reverse API Engineer generate clients in?

The README lists Python, JavaScript, TypeScript, Go, Java, C#, PHP, Ruby and C. The output_language setting selects one of these. The README notes that C needs a POSIX toolchain with cc and libcurl headers.

### Does Reverse API Engineer need Playwright installed?

Not for agent mode, which is the default. Since v0.12.0 Playwright is an optional extra, and agent mode captures through npx-launched browser tooling instead. Manual mode is the path that requires the [manual] extra and a Chromium install.

### Which AI models can Reverse API Engineer use?

The default SDK is claude, with Sonnet 4.6 as the default model and Opus 4.6 and Haiku 4.5 listed as alternatives. The sdk setting also accepts opencode, cursor or copilot, and OpenCode can be pointed at locally installed Ollama models that support tool calling and 64k+ context.

## Sources

- [License: MIT](https://github.com/nottelabs/reverse-api-engineer/blob/main/LICENSE)
- [nottelabs/reverse-api-engineer on GitHub](https://github.com/nottelabs/reverse-api-engineer)
- [Project website](https://reverseapi.dev)
- [README](https://github.com/nottelabs/reverse-api-engineer/blob/main/README.md)
- [Releases](https://github.com/nottelabs/reverse-api-engineer/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/nottelabs-reverse-api-engineer
