Skip to content
AIwolfiePublic

About

No description, website, or topics provided.

Resources

Code of conduct

Contributing

Security policy

Stars

4 stars

Watchers

0 watching

Forks

Repository files navigation

 ⣎⣱ ⣀⡀ ⡇⡠ ⣏⡉ ⢀⡀ ⣰⡀ ⢀⣀ ⣇⡀
 ⠇⠸ ⡧⠜ ⠏⠢ ⠇  ⠣⠭ ⠘⠤ ⠣⠤ ⠇⠸

APKFetch

The High-Performance, Cross-Platform Google Play Downloader CLI

GitHub Release Build Status License Platform

Authentication • Installation • Quick Start • Commands • Single APK vs Splits • Security

APKFetch is a production-grade, zero-telemetry command-line application built to streamline downloading Android applications directly from the Google Play Store. It outputs single standalone .apk files by default, supports Android App Bundles (Split APKs / .apks archives), hardware device profile emulation, resumable chunked downloads, and cryptographic verification.


🔐 Authentication Modes

Google restricts standard web-browser OAuth clients from requesting Google Play Store scopes (Error 403: restricted_client). To provide a seamless, non-breaking experience, APKFetch supports two primary authentication modes:

1. ⚡ Anonymous Guest Mode (Recommended / Default)

No Google account or browser sign-in required. Generates an instant Google Services Framework (GSF) device checkin to download any public free application directly:

apkfetch login --anonymous

2. 🔑 Token / App Password Mode

Authenticate with a specific Google account using a Google Play auth token or Google App Password:

apkfetch login --token "<your-play-auth-token>" --email "user@gmail.com"

Note on Browser OAuth: Direct browser OAuth (apkfetch login without flags) is currently subject to Google's unverified client restrictions (Error 403: restricted_client). Use --anonymous for instant zero-setup downloads or --token for direct account access.


✨ Features

  • 🚀 Single Standalone APK Output: Downloads single, installable .apk files directly (downloads/app.apk) by default.
  • 📦 Split APK & .apks Support: Download split component folders with --split or pack them into standard .apks archives with --bundle.
  • 🛡️ AES-256-GCM Encrypted Keystore: Session tokens and device IDs are stored with local authenticated encryption using machine/user entropy.
  • ⚡ Resilient Downloader Engine: Multi-chunk download pipeline featuring automatic HTTP Range resume, exponential backoff retry loops, and temporary atomic .part commits.
  • 🔍 Checksum Validation: Automatically verifies SHA-256 / SHA-1 checksums and byte boundaries before completing downloads.
  • 📱 Device Profile Emulation: Emulate physical devices (Pixel 7 Pro, Galaxy S23, Generic x86_64) and specify target ABIs (arm64-v8a, armeabi-v7a, x86_64, x86).
  • 🚀 Concurrent Batch Queue: Process bulk package manifests with worker pools (apkfetch batch apps.txt --concurrency 4).
  • 🤖 Headless & CI/CD Native: Full --json output across all commands for automation.

💻 Supported Platforms

Operating System Architecture Binary Distribution
macOS Apple Silicon (arm64) apkfetch-macos-arm64
macOS Intel 64-bit (x64) apkfetch-macos-x64
Linux AMD64 / x86_64 (x64) apkfetch-linux-x64
Linux ARM64 / AArch64 (arm64) apkfetch-linux-arm64
Windows 64-bit (x64) apkfetch-windows-x64.exe

📦 Installation

Direct Binary Download

macOS / Linux

curl -fsSL https://github.com/AIwolfie/ApkFetch/releases/latest/download/apkfetch-linux-x64 -o apkfetch
chmod +x apkfetch
sudo mv apkfetch /usr/local/bin/

Windows (PowerShell)

Invoke-WebRequest -Uri "https://github.com/AIwolfie/ApkFetch/releases/latest/download/apkfetch-windows-x64.exe" -OutFile "apkfetch.exe"

Go Install

go install github.com/AIwolfie/ApkFetch@latest

Build from Source

git clone https://github.com/AIwolfie/ApkFetch.git
cd ApkFetch
go build -ldflags="-s -w" -o apkfetch main.go

🚀 Quick Start

1. Initialize Anonymous Session (Instant / Zero-Setup)

apkfetch login --anonymous

2. Inspect App Metadata

apkfetch info "https://play.google.com/store/apps/details?id=org.videolan.vlc"

3. Download Single APK (Default)

apkfetch download "https://play.google.com/store/apps/details?id=org.videolan.vlc"

Saves directly to ./downloads/org.videolan.vlc.apk.

4. Download Split APK Components (Optional)

# Save split components to ./downloads/org.videolan.vlc/
apkfetch download org.videolan.vlc --split

# Or pack splits into a single .apks archive
apkfetch download org.videolan.vlc --split --bundle

🕹️ Command Reference

Command Syntax Description
login apkfetch login --anonymous Establish anonymous guest session (zero-setup)
login apkfetch login --token <t> --email <e> Authenticate using direct token / app password
logout apkfetch logout Delete stored credentials and purge session
whoami apkfetch whoami View active account and device profile
download apkfetch download <url|pkg> Download standalone .apk package
info apkfetch info <url|pkg> Fetch store metadata without downloading
batch apkfetch batch <file> Download multiple packages concurrently
device list apkfetch device list List available Android hardware emulation profiles
device set apkfetch device set <name> Select active device profile (Pixel 7 Pro, Galaxy S23, etc.)
config list apkfetch config list Show all configuration keys and active settings
version apkfetch --version Print version and architecture details

Download Flags

  • -o, --output <dir>: Target download directory (default: ./downloads)
  • -f, --filename <name>: Custom file name for single APK downloads (e.g. vlc.apk)
  • --abi <arch>: Target Android device ABI (arm64-v8a, armeabi-v7a, x86_64, x86)
  • --split: Download all split APK components into a directory
  • --bundle: Pack split APKs into a .apks archive file (used with --split)
  • --force: Overwrite existing local files
  • -y, --yes: Auto-confirm interactive prompts
  • --json: Format output as JSON for scripting

🔒 Security & Privacy Architecture

  • No Plaintext Passwords: Password inputs are never stored in plaintext.
  • Hardware-Salted AES-256-GCM: Credentials and session keys are encrypted locally with keys derived from machine/user hardware entropy.
  • Strict File Permissions: Keyrings are stored with restricted permissions (0600).
  • Path Traversal Protection: All user input, URLs, package names, and output directories are sanitized against directory traversal exploits.
  • No Third-Party Telemetry: Zero analytics, telemetry, or third-party tracking.

📄 License

APKFetch is open-source software licensed under the Apache License, Version 2.0.

About

No description, website, or topics provided.

Resources

Code of conduct

Contributing

Security policy

Stars

4 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages