# Hidden API Finder

> Hidden API Finder is an AI agent skill for Claude Code, Codex CLI, Gemini CLI, and other agents that read SKILL.md. Finds the real endpoint behind a web app button by reading its JavaScript, read-only. Best for: reverse engineer website API.

- URL: https://atharvashah.com/ai-skills/hidden-api-finder
- Price: $19, one payment
- Works with: Claude Code, Codex CLI, Gemini CLI, Cursor, GitHub Copilot
- Category: Agents and engineering
- Built by: Atharva Shah (https://atharvashah.com)
- Requirements: Needs a paid Claude plan with Claude Code and Python. You need your own login to the app. It finds client-side calls only and never bypasses access controls. Check the app terms before you automate it.
- Buy: https://buy.polar.sh/polar_cl_UrbGOx20Q8jkmsQZp6DiawITRxXonNK11YhGk4UcDzG?custom_field_data.skill-standard=hidden-api-finder (the skill folder and setup guide arrive by email)

## Find the API call behind the button, without pressing it.

It reads the web app code your browser already downloads and finds the exact request a button sends. You learn the path, the payload flags, and what cannot be undone before you fire anything.

## What it produces

- **The verified finding.** You get the exact request, what each flag does, and proof it sent no email, before anything fires in production. ![A finding note for editing a published Substack post: the publish call from the app bundle, its send flags, and a verified result.](https://atharvashah.com/ai-skills/hidden-api-finder/scene-1.webp)
- **The API, documented.** Undocumented paths come back as a note with the base URL and the cookie each call needs. ![A draft article, Your Substack Has a Secret API, showing three raw Substack API paths and the session cookie names.](https://atharvashah.com/ai-skills/hidden-api-finder/scene-2.webp)
- **From finding to tool.** A verified call becomes a command you can script, as it did for the public substack-cli. ![The substack-cli README on GitHub comparing the Substack web editor with the command line tool, row by row.](https://atharvashah.com/ai-skills/hidden-api-finder/scene-3.webp)

## Read the code first. Touch production last.

Every web app ships its request paths in public script files. It reads those instead of clicking.

1. **Name the button.** Tell it which app and which action. It loads the page you already have access to and lists every script file it pulls in.
2. **It reads the request.** It searches for stable strings that survive each deploy, then reads the path, the payload flags, and the confirm text next to the call. It also checks whether an undo exists.
3. **Test with a restore path.** Only after your yes, it saves the record, makes the smallest change, checks the result from two sides, and restores the original.

## The usual way to find a hidden endpoint fires it.

Watching the network tab means clicking the real button. On an action that sends email or publishes, the click is the damage.

### Hidden API Finder

- **Nothing fires.** It reads public script files and sends no writes.
- **Every call the app can make.** It sees paths no button in view exposes.
- **Undo checked first.** It searches for the reverse action before any test.
- **Snapshot and restore.** The first write happens only after your yes.

### Click and watch the network tab

- **The click is live.** You learn the request by sending it to production.
- **One path at a time.** You only see the calls the buttons you clicked make.
- **No undo check.** You find out an action is permanent after you run it.
- **Hidden flags.** The default payload hides the options the app supports.

### Waiting on the vendor

- **Support tickets.** The answer is often that no public API exists.
- **Roadmap promises.** The endpoint ships next quarter, maybe.
- **Paid integration tools.** They cover the popular actions and skip yours.
- **Your project waits.** The automation you planned sits in a backlog.

## Frequently asked questions

### How do I find the API endpoints of a website?

Open the JavaScript bundles the page already loads and search for the request the button sends. This skill does that search and writes up the endpoint, the method, and the payload.

### Is this hacking?

No. It reads the script files your browser already downloads when you open the app. It sends no requests you could not send yourself, and it never gets past a login or a permission check.

### Does it work on every app?

It works on web apps that build requests in the browser, which covers most modern software. Actions handled only on the server leave no trace in the scripts.

### Will it trigger the action by accident?

No. Discovery is read-only. The first write happens only after you approve it, and it saves the record first so it can restore it.

### Can my session call every endpoint it finds?

Not always. Some admin routes need a different token and answer 403. It tells you when a route exists but your access cannot reach it.

### Which Claude plan do I need?

A paid plan with Claude Code. Pro is enough, since one search reads a few dozen files.

### What else do I pay for?

Nothing. Python and the fetch tools are free.

### Why did my change not show on the public page?

Often a CDN serves an old copy. It checks the public page with a cache-busting fetch before it calls a write a failure.

### Is it allowed under the app terms?

That depends on the app. Read its terms before you automate anything, and keep to your own account and data.

### What if the first search finds nothing?

It changes the search to other stable strings, such as payload keys or the confirm text shown to users. If the call lives only on the server, it tells you so.

### Does this skill work with Gemini CLI, Codex, Cursor, or GitHub Copilot?

Yes, with one caveat. The skill is a SKILL.md folder in the Agent Skills open standard, which Claude Code, Codex CLI, Gemini CLI, Cursor, and GitHub Copilot all load. It is built and tested on Claude Code. Steps that lean on Claude-only features, such as parallel subagents, run one after another or need a manual step in other agents.

### How do I install an agent skill?

Copy the skill folder into your agent's skills directory: ~/.claude/skills for Claude Code, or the skills folder your agent documents for Codex CLI, Gemini CLI, Cursor, or Copilot. The agent reads the description and loads the skill when your request matches it. Each skill ships with a setup guide for any tool it needs.

[All AI skills](https://atharvashah.com/skill-pack) · [Library index](https://atharvashah.com/ai-skills.md)
