Debug and bypass SSL pinning on an Android emulator
Inspect the API traffic of an Android app that uses SSL pinning with LDPlayer 9 and HTTP Toolkit: enable root, connect over ADB, auto-bypass SSL, and handle advanced protections.
On this page
This guide shows how to inspect the API request/response traffic of an Android app, including production apps that use SSL pinning, by combining the LDPlayer 9 emulator (runs Android 9, ships with root) and HTTP Toolkit (acts as an MITM proxy and auto-injects an SSL bypass).
Only do this to apps you own or are explicitly authorized to test. Intercepting other people's traffic, or other people's apps, without permission is illegal.
Requirements
- A Windows computer.
- The LDPlayer 9 emulator (running Android 9), because it ships with root and is easy to connect.
- HTTP Toolkit, acting as the MITM proxy that auto-injects the SSL bypass.
Quick reference
Once you have set this up once, later sessions only need this sequence:
- Open LDPlayer.
- Open a terminal (CMD/PowerShell) and run:
adb connect 127.0.0.1:5555 - Open HTTP Toolkit.
- Pick the Android 9 emulator connection.
- Grant root/VPN permission on LDPlayer (if prompted).
- Open the target app and start reading traffic.
Step by step
Step 1: Prepare the emulator (enable root)
- Download and install the LDPlayer 9 emulator.
- Enable "Root permission" and "ADB Debugging" in LDPlayer:
- Open LDPlayer, click the Settings icon (gear) on the right toolbar (or top right).
- Go to the Other Settings tab.
- Find Root permission and switch it from Disable to Enable.
- Under ADB Debugging (right below, or on the same panel), choose Open Local Connection (or Enable) to open the local ADB port.
- Click Save settings.
- You MUST choose Restart now for it to take effect.
- Sign in to Google Play, then download and install the app you want to debug into the emulator.
Step 2: Connect through HTTP Toolkit and fix errors
HTTP Toolkit usually picks "Android Device via ADB" on its own, but if it doesn't see the device (different ADB version or wrong port):
-
Open LDPlayer and wait for the home screen.
-
Open CMD/PowerShell on Windows.
-
Connect manually to the emulator's ADB port (the default for a single instance is
5555):adb connect 127.0.0.1:5555If you get
adb is not recognized, point directly at the LDPlayer folder. In PowerShell you must use.\adb.exe:cd C:\LDPlayer\LDPlayer9 .\adb.exe connect 127.0.0.1:5555 -
If you see
connected to 127.0.0.1:5555, it worked. If ADB hangs, runadb kill-serverthenadb start-serverand try the connect command again.
Step 3: Grant permission and intercept HTTPS with HTTP Toolkit
- Open HTTP Toolkit on the computer; by now it sees the device over ADB.
- In the device list, click the "Android 9 emulator" (blue) configuration button instead of the old device presets still in the cache (for example Samsung S10/S22...).
- IMPORTANT: the moment you click on the computer, look straight at the LDPlayer emulator screen.
- HTTP Toolkit gets pushed, auto-installs onto the emulator, and opens.
- The emulator shows a Superuser (root) permission prompt -> tap Allow or "Forever".
- Next, the app on the emulator warns about a VPN setup (to route all traffic through it) -> tap OK.
- When HTTP Toolkit on the computer switches to the green Connected icon, you're done.
Step 4: Auto-bypass SSL and observe
- Open the target app on the emulator.
- HTTP Toolkit's proxy (with its built-in Frida injection) automatically detects and hooks into the app to trick/bypass the system's SSL check.
- Back on the HTTP Toolkit main screen, you'll see the full traffic:
- Request headers (tokens, cookies, user-agent...).
- The JSON body being sent.
- The raw response from the server.
- Query parameters.
Handling advanced errors
A "proper production" app sometimes has extra protection layers. If you still hit errors, try these advanced fixes:
- Emulator detection or deep root checks: the app crashes on open because it detects root. Use a real spare device, or install Magisk on LDPlayer plus a Hide/Zygisk/Denylist module to bypass the detection.
- Application-layer encryption: the server accepts the request, but HTTP Toolkit only shows scrambled encrypted characters (the app encrypts with RSA/AES on top of HTTPS). The fix is to decompile the APK with JADX to find the key, or write your own Frida script to hook and read the raw data.
- Custom certificate pinning (OkHttp3/Retrofit): the proxy shows red and complains about a bad certificate. Use a Universal Pinning Bypass script via Frida-Tools instead of HTTP Toolkit's automatic mode.
Troubleshooting
| Symptom | Fix |
|---|---|
adb is not recognized | Point at the LDPlayer folder and use .\adb.exe connect ... in PowerShell |
| ADB hangs, can't connect | adb kill-server then adb start-server, then connect again |
| App crashes on open | App detects root/emulator - use a real device or Magisk + Hide/Zygisk/Denylist |
| Traffic shows scrambled encrypted characters | App encrypts at the application layer - decompile with JADX or hook with Frida |
| Proxy complains about a bad certificate | Custom certificate pinning - use a Universal Pinning Bypass script via Frida |