Vũ Văn HảiFull-stack · AI-native
GuidesBlog
Discuss a project

© 2026 Vu Van Hai · Written from real deployment experience.

HomeGuidesBlogRSS
  1. Guides
  2. /Dev tools
  3. /Debug and bypass SSL pinning on an Android emulator

Debug and bypass SSL pinning on an Android emulator

Inspect the API traffic of an Android app that uses SSL pinning with LDPlayer 9 and HTTP Toolkit: enable root, connect over ADB, auto-bypass SSL, and handle advanced protections.

Updated: Sep 21, 20264 min read
AndroidNetworkingSecurity
On this page
  • Requirements
  • Quick reference
  • Step by step
  • Step 1: Prepare the emulator (enable root)
  • Step 2: Connect through HTTP Toolkit and fix errors
  • Step 3: Grant permission and intercept HTTPS with HTTP Toolkit
  • Step 4: Auto-bypass SSL and observe
  • Handling advanced errors
  • Troubleshooting

This guide shows how to inspect the API request/response traffic of an Android app, including production apps that use SSL pinning, by combining the LDPlayer 9 emulator (runs Android 9, ships with root) and HTTP Toolkit (acts as an MITM proxy and auto-injects an SSL bypass).

Only do this to apps you own or are explicitly authorized to test. Intercepting other people's traffic, or other people's apps, without permission is illegal.

Requirements

  • A Windows computer.
  • The LDPlayer 9 emulator (running Android 9), because it ships with root and is easy to connect.
  • HTTP Toolkit, acting as the MITM proxy that auto-injects the SSL bypass.

Quick reference

Once you have set this up once, later sessions only need this sequence:

  1. Open LDPlayer.
  2. Open a terminal (CMD/PowerShell) and run: adb connect 127.0.0.1:5555
  3. Open HTTP Toolkit.
  4. Pick the Android 9 emulator connection.
  5. Grant root/VPN permission on LDPlayer (if prompted).
  6. Open the target app and start reading traffic.

Step by step

Step 1: Prepare the emulator (enable root)

  1. Download and install the LDPlayer 9 emulator.
  2. Enable "Root permission" and "ADB Debugging" in LDPlayer:
    • Open LDPlayer, click the Settings icon (gear) on the right toolbar (or top right).
    • Go to the Other Settings tab.
    • Find Root permission and switch it from Disable to Enable.
    • Under ADB Debugging (right below, or on the same panel), choose Open Local Connection (or Enable) to open the local ADB port.
    • Click Save settings.
    • You MUST choose Restart now for it to take effect.
  3. Sign in to Google Play, then download and install the app you want to debug into the emulator.

Step 2: Connect through HTTP Toolkit and fix errors

HTTP Toolkit usually picks "Android Device via ADB" on its own, but if it doesn't see the device (different ADB version or wrong port):

  1. Open LDPlayer and wait for the home screen.

  2. Open CMD/PowerShell on Windows.

  3. Connect manually to the emulator's ADB port (the default for a single instance is 5555):

    adb connect 127.0.0.1:5555

    If you get adb is not recognized, point directly at the LDPlayer folder. In PowerShell you must use .\adb.exe:

    cd C:\LDPlayer\LDPlayer9
    .\adb.exe connect 127.0.0.1:5555
  4. If you see connected to 127.0.0.1:5555, it worked. If ADB hangs, run adb kill-server then adb start-server and try the connect command again.

Step 3: Grant permission and intercept HTTPS with HTTP Toolkit

  1. Open HTTP Toolkit on the computer; by now it sees the device over ADB.
  2. In the device list, click the "Android 9 emulator" (blue) configuration button instead of the old device presets still in the cache (for example Samsung S10/S22...).
  3. IMPORTANT: the moment you click on the computer, look straight at the LDPlayer emulator screen.
    • HTTP Toolkit gets pushed, auto-installs onto the emulator, and opens.
    • The emulator shows a Superuser (root) permission prompt -> tap Allow or "Forever".
    • Next, the app on the emulator warns about a VPN setup (to route all traffic through it) -> tap OK.
  4. When HTTP Toolkit on the computer switches to the green Connected icon, you're done.

Step 4: Auto-bypass SSL and observe

  1. Open the target app on the emulator.
  2. HTTP Toolkit's proxy (with its built-in Frida injection) automatically detects and hooks into the app to trick/bypass the system's SSL check.
  3. Back on the HTTP Toolkit main screen, you'll see the full traffic:
    • Request headers (tokens, cookies, user-agent...).
    • The JSON body being sent.
    • The raw response from the server.
    • Query parameters.

Handling advanced errors

A "proper production" app sometimes has extra protection layers. If you still hit errors, try these advanced fixes:

  • Emulator detection or deep root checks: the app crashes on open because it detects root. Use a real spare device, or install Magisk on LDPlayer plus a Hide/Zygisk/Denylist module to bypass the detection.
  • Application-layer encryption: the server accepts the request, but HTTP Toolkit only shows scrambled encrypted characters (the app encrypts with RSA/AES on top of HTTPS). The fix is to decompile the APK with JADX to find the key, or write your own Frida script to hook and read the raw data.
  • Custom certificate pinning (OkHttp3/Retrofit): the proxy shows red and complains about a bad certificate. Use a Universal Pinning Bypass script via Frida-Tools instead of HTTP Toolkit's automatic mode.

Troubleshooting

SymptomFix
adb is not recognizedPoint at the LDPlayer folder and use .\adb.exe connect ... in PowerShell
ADB hangs, can't connectadb kill-server then adb start-server, then connect again
App crashes on openApp detects root/emulator - use a real device or Magisk + Hide/Zygisk/Denylist
Traffic shows scrambled encrypted charactersApp encrypts at the application layer - decompile with JADX or hook with Frida
Proxy complains about a bad certificateCustom certificate pinning - use a Universal Pinning Bypass script via Frida
PreviousRoll back a Git commit and update safely on a VPSNextFix Claude Code connection errors on Windows (ECONNREFUSED, Bun crash)

Related articles

  • Set up Vertex AI for the Gemini API (keyless and service account)

    Set up Google Cloud Vertex AI (now Gemini Enterprise Agent Platform) to call Gemini models: enable the API, create a service account, authenticate keyless with ADC or with a JSON key, install the google-genai SDK, and fix org policy, 429 and 404 errors.

    Integrations

    Integrations
  • Connect to PostgreSQL on a VPS through an SSH tunnel

    Use an SSH tunnel so your dev machine can reach PostgreSQL on a VPS without exposing port 5432 to the internet, plus the DATABASE_URL setup for local and production.

    Database

    Database
  • Quick-check a VPS's specs with a single command

    A one-line bash script that checks a VPS's OS, CPU, RAM, disk and network in about 15 seconds, plus reference tables that tell you whether each number is weak, fine or strong.

    VPS

    VPS

Written by Vu Van Hai

I'm Hai, a full-stack developer based in Ho Chi Minh City. These guides come from systems I built and run myself. Need to build or untangle something similar? Get in touch.

Discuss a projectMore guides

Spot a mistake or a command that no longer works? Let me know

On this page

  • Requirements
  • Quick reference
  • Step by step
  • Step 1: Prepare the emulator (enable root)
  • Step 2: Connect through HTTP Toolkit and fix errors
  • Step 3: Grant permission and intercept HTTPS with HTTP Toolkit
  • Step 4: Auto-bypass SSL and observe
  • Handling advanced errors
  • Troubleshooting