Everything Has an API If You're Willing to Prompt

· Bagas Wastu ·

4 min read Original article ↗

I've been using an app called Boostcamp for at least 3 years to track my workouts. It does a great job at logging sets. But, the problem is that the deep analytics are locked behind a subscription paywall.

All analytics locked behind a paywall

All analytics locked behind a paywall

This happens with almost every service. They hold your data hostage inside the app, and you're stuck with whatever they decide to show you. Even if I paid them $50/year for subscription, they still wouldn't let me export my training logs.

I was inspired recently seeing people use AI agents to get their own stuff back, like having Codex reverse-engineer studio lights or taking a Samsung TV from a browser sandbox all the way to root.

Before AI, my instinct was always to reverse-engineer the app myself whenever I wanted my data back. But let's be honest, who wants to spend hours after work digging through network requests and databases just to get a CSV?

The setup

I already have an old Xiaomi Poco F4 that's rooted with KernelSU dedicated to things like this.

My rooted Xiaomi Poco F4

My rooted Xiaomi Poco F4

The phone is connected to my private network through meshflare (my project that brings a Tailscale-like mesh network to Cloudflare Zero Trust), running my fork of wadbd so wireless ADB stays active across reboots and is bound strictly to the VPN interface.

I used DeepSeek V4 Flash and attached my grill-me skill so the agent interviews me about what data I actually want before touching anything.

Then I pointed it at the phone over wireless ADB.

Pulling 3 years of data

Because the phone is rooted, there was no need to decompile the app. The agent went in over ADB, inspected the app's local storage, and grabbed my active Firebase auth credentials and refresh token.

It wrote a standalone Python script to query Boostcamp's private API directly. In less than 10 minutes, it dumped and normalized all 339 of my lifetime workouts (5,069 sets) into JSON and CSV files, matching my exact app stats.

Then it built a single-file dashboard canvas of the full lifting history:

My full lifting history

The agent looked at the logs and noticed I only lift around 1.6 times a week, so some muscle groups stall. I asked it to design two new full-body routines around the equipment I actually have. A gym routine grouped into 3 physical stations, so I don't have to walk around hogging machines. A home routine that's dumbbell-only, with minimal plate changes and no bench needed.

I didn't configure those exercises back into the app myself. The agent used Boostcamp's own internal API to archive my old stalled program and push both routines in as native workout templates.

Custom templates that Agent created on Boostcamp

Custom templates that Agent created on Boostcamp

Now I have a personal dashboard, three years of clean workout history in my own database, and an agent that updates my routine whenever I need it, all without paying for a subscription :)

If you try this

GPT, Claude, and Gemini refuse the moment you ask them to inspect or reverse-engineer an APK. GLM or DeepSeek tend to have far fewer false-positive refusals when inspecting your own hardware. I used DeepSeek V4 Flash because it's fast and cheap.

Also, I would skip the emulator. Play Integrity and missing hardware sensors is really pain in the ass. A cheap secondary Android phone rooted with KernelSU is a good option in my case. For Play Integrity bypasses, root hiding, and the rest of that cat-and-mouse game, r/androidroot is where people share what still works on current firmware.

If the app uses certificate pinning or heavy obfuscation, use DragonJAR's Android-Pentesting-Skill to equip the agent with Frida hooks and decompilation workflows so it doesn't get stuck.

If you don't want a USB cable tethered to your machine 24/7, the original wadbd module keeps ADB alive over Wi-Fi across reboots. The catch is that stock wadbd listens on all network interfaces (0.0.0.0), exposing root ADB to your entire local network. My fork patches it to bind strictly to the VPN interface instead.