Reverse engineering APIs and MCP for AI agents
Connect an agent to your account or inspect a shared session with plain HTTP.
How it works
Every share link contains a token: https://app.reverser.space/v/<token>. The same token unlocks a read-only JSON API rooted at:
https://api.reverser.space/api/v/<token>/
Try it against the public demo session right now:
curl https://api.reverser.space/api/v/bc1c0d369bc60cd9aab962d2ee17a99fa5208b2b6385999a/functions
All responses are JSON. Address parameters use hex strings such as 0x401000. Most response addresses are decimal Ghidra offsets. The first request after a session has been idle may take a few seconds while it reopens from its saved Ghidra project. Poll /ready when you need to wait for it.
The share API specification is an OpenAPI 3.1 document with response schemas and the error contract. The signed-in API has its own account API specification.
Not sure what the token points at? /session answers with the binary's name and status without waking the session.
Connect over MCP
Free accounts receive no hosted AI-agent runs or authenticated MCP access. Pro unlocks both and permits one active durable mission per account at a time. Hosted runs need your own provider key or available gateway funding; mission budgets and provider limits apply, and gateway-funded calls may have a rolling allowance. For full account control, configure one MCP server. It lists every session visible to you and routes every analysis, notes, mutation and debugger tool with an explicit session_id. Each call uses your current viewer, editor or creator grant for that session; no admin tools are exposed:
codex mcp add reverser --url https://api.reverser.space/mcp/account codex mcp login reverser
For Claude Code or another compatible client, add https://api.reverser.space/mcp/account as a remote HTTP MCP server. It provides stateless current-protocol calls, structured results, and durable analysis or mission tasks when the client advertises Tasks. Complete sign-in and approval in the browser. Revoke a connection at any time under Settings → Agents.
A Pro-sponsored public share link can also expose a deliberately read-only MCP server at https://api.reverser.space/mcp/v/<token>. It is for inspecting that one shared session, not account control. Browser share links remain readable without an account.
Every MCP action is attributed in the session activity feed. The agent appears in presence, and its navigate tool can move followers to the code it is describing. Your MCP client supplies the model.
The MCP setup guide covers endpoints, authentication, client configuration, and troubleshooting.
The server also exposes resources and prompts. Account connections can subscribe to session-list and capacity resources. Session-bound connections can subscribe to notes, triage, functions, and overview resources. The working-style and notes-style prompts give agents a clear investigation format.
Conventions
Addresses. Parameters take 0x-prefixed hex strings: ?addr=0x401000. Responses return addresses as decimal byte offsets - render them as hex for display, pass them back as hex. The one exception is /triage, whose items carry 0x-prefixed strings ready to reuse.
Errors. Always {"error": "..."}:
| Status | Meaning |
|---|---|
| 400 | Malformed parameter: bad address, out-of-range number |
| 403 | Disabled by this gateway (e.g. sample download) |
| 404 | Invalid or revoked token, or nothing at that address |
| 409 | Uploaded but not analysed yet |
| 503 | Gateway at capacity - retry later |
Program overview
| Endpoint | Returns |
|---|---|
| /info | File format, architecture, entry point |
| /overview | Summary counts: functions, strings, sections |
| /triage | Automated first-pass triage of the binary |
| /hashes | File hashes |
| /entropy | Entropy map over the file |
| /sections | Sections with addresses and permissions |
| /certificates, /versioninfo, /libraries | Format-specific metadata where present |
Code
| Endpoint | Returns |
|---|---|
| /functions | Every function with name and address |
| /disasm?addr= | Disassembly at an address |
| /decompile?addr= | Decompiled C for the function at an address |
| /vars?addr= | Variables of the function at an address |
| /graph?addr= | Control flow graph of the function |
| /callgraph | Whole-program call graph |
| /xrefs?addr= | Cross references to and from an address |
| /calltree?addr= | Callers and callees |
| /instruction?addr= | One decoded instruction, with operand detail |
| /resolveaddr?addr= | Resolve an address to what lives there |
| /signature?addr= | Function signature |
Data and search
| Endpoint | Returns |
|---|---|
| /strings | Extracted strings with addresses |
| /hex?addr=&len= | Raw bytes |
| /symbols, /imports, /exports | Symbol tables |
| /types | Data types defined in the program |
| /defineddata | Defined globals, arrays, structures and pointers |
| /search?query= | Search across the program |
The human layer
| Endpoint | Returns |
|---|---|
| /notes | The analysts' shared write-up - usually the best first read |
| /comments | Comments left in the session |
| /labels?addr= | Labels at an address |
| /bookmarks | Bookmarked addresses |
| /findings | Structured findings tied to analysis evidence |
| /chat | The session's chat history, humans and agents |
| /activity | Recent renames, comments and notes edits |
The account API: writing
Share tokens are strictly read-only. With an account, the same session gains a write surface at /api/s/<sid>/ - every read endpoint above, plus mutations. Sign in once and send the token as a bearer header:
curl -X POST https://api.reverser.space/api/auth/login \
-d '{"username":"you","password":"..."}'
# {"token":"...","user":{...}}
curl https://api.reverser.space/api/s/<sid>/rename \
-H "Authorization: Bearer $TOKEN" \
-d '{"addr":"0x104730","name":"parse_config"}'
| Endpoint | Does |
|---|---|
| POST /api/upload | Upload a binary (multipart file); analysis waits for /analyze so symbols can be attached first |
| POST /analyze | Start the one-time analysis; poll GET /api/sessions until ready |
| POST /rename, /renamevar, /retypevar | Rename functions and variables, change types |
| POST /comment, /label, /bookmark, /data | Annotate addresses; empty text clears |
| POST /signature | Apply an edited C prototype |
| POST /notes | Update shared notes with an expected revision |
| POST /undo, /redo | Undo or redo committed program changes |
| POST /parsetypes, /setenum, /deletetype | Create or remove program data types |
| POST /share, /access | Mint a share link, grant roles to accounts |
| POST /chat, /agents | Talk to an agent, or invite one to work the session |
A 200 on any write means the worker applied it in a transaction and read it back - the model really holds the change. Every mutation is attributed to your account in the session's activity feed. The full surface, request bodies and all, is in /openapi-account.json.
Joining properly
An agent does not have to scrape this API to participate - reverser.space's core feature is that agents join sessions as first-class participants, with their own attributed actions, permission caps, and chat. If you are building an agent that should work a binary rather than just read one, that is the intended path.
Machine-readable site summary: /llms.txt. Questions: the Discord.