Feed aggregator

Show HN: Harpist – convert any website into a refined and documented API

Hacker News - Mon, 07/13/2026 - 10:50am

Hello HN!

As part of our work at Kenobi[0], I used Codex to analyse an HTTP archive (HAR) for a website I was trying to see if I could use programatically, i.e. by exposing its underlying / undocumented API. That approach worked much better than I expected, so I started looking for a way to do this easily for other websites.

I couldn't find exactly what I wanted, so we decided to build Harpist -- a product in two parts: i. A Chrome extension, that allows you to record HAR files and view generated documentation; and ii. A CLI that can be used by agents to refine these HAR files and create oRPC contracts, documentation, and allow you to replay HTTP requests.

There's an agent skill that lets you use Claude or Codex to manage all of the refinement and CLI usage, so right now the workflow is as follows:

1. Open the Chrome extension and record yourself using a website (the parts you'd want to automate).

2. Tell your agent to "use Harpist to refine my latest recording".

3. When it's done, the extension lets you view documentation for the discovered endpoints.

4. Replay the endpoints and view captured auth data in the CLI yourself, or just...

5. Ask your agent to do something for you on one of the website's you've captured and processed using Harpist.

It's all open source (MIT licensed)[1], and under the hood it uses oRPC to create TypeScript-compatible API contracts, but I've mostly been focussing on the documentation for now which just uses the oRPC Scalar integration[2] to generate OpenAPI-looking docs.

I'm keen to learn what other people are doing to discover and automate web workflows at the moment, and what kind of things people _wish_ existed too.

[0] - https://kenobi.ai

[1] - https://github.com/kenobi-ai/harpist

[2] - http://orpc.dev/docs/openapi/scalar

Comments URL: https://news.ycombinator.com/item?id=48893610

Points: 1

# Comments: 0

Categories: Hacker News

Omarchy 4 concerns, am I the only one?

Hacker News - Mon, 07/13/2026 - 10:50am

well from thousands of ai written lines of code to some system specific moves that might break tons of installs where people have customized things quite a bit might break, or am i over thinking this?

Comments URL: https://news.ycombinator.com/item?id=48893609

Points: 1

# Comments: 0

Categories: Hacker News

Show HN: Hackney – Compare Uber, Lyft, Waymo, and Robotaxi Prices

Hacker News - Mon, 07/13/2026 - 10:47am

I created an app that compares real-time prices and wait times across Uber, Lyft, Waymo, Tesla Robotaxi, Curb, and Empower. It shows you all ride options in one list, then once you’re ready to book, it deeplinks you to the provider’s app with the route pre-filled.

I reverse-engineered ride-hailing mobile apps to understand how they fetch prices from their servers. You sign in to my app with your ride-hailing accounts, and then my app requests live prices from the same APIs that ride-hailing apps use. Importantly, my app is built using an on-device approach: the app on your phone stores authentication tokens locally and sends network requests directly to each ride-hailing company’s servers. This keeps your accounts private. I wrote a blog post showing network requests sent by my app, which you can verify yourself: https://blog.hackney.app/p/how-hackney-works

This seems like an obvious app. Why doesn’t it already exist? That’s because most ride-hailing companies don’t offer public APIs for prices and wait times. Uber does offer one, but they prohibit using it for price comparison. When someone built a comparison app using the official API, Uber terminated their API access (https://www.benedelman.org/news-053116). There are apps today that don’t use official APIs, but they run your account tokens through their servers and send price requests server-side.

To integrate a ride-hailing provider, my app sends network requests for sign-in, token refresh, ride prices, and ride history (to power a feature that shows you unified ride history across apps and how much you’ve saved on each ride). Some ride-hailing apps implement certificate pinning to prevent you from viewing their network requests, and some communicate with their server using Protobuf, a data format that doesn’t include the original field names. Building an app using this approach is technically complex, but it makes possible all sorts of useful products that couldn’t otherwise exist.

The app is completely free. In the future, I may monetize through a subscription or partnerships with ride-hailing companies. I’d love to hear your feedback. You can download it today.

iOS: https://apps.apple.com/us/app/hackney-compare-rideshares/id6...

Android: https://play.google.com/store/apps/details?id=app.hackney

Comments URL: https://news.ycombinator.com/item?id=48893550

Points: 1

# Comments: 0

Categories: Hacker News

The Death of Open Channels

Hacker News - Mon, 07/13/2026 - 10:40am
Categories: Hacker News

Precursor

Hacker News - Mon, 07/13/2026 - 10:39am
Categories: Hacker News

Trusting your kids online isn’t enough (Lock and Code S07E14)

Malware Bytes Security - Mon, 07/13/2026 - 10:33am

This week on the Lock and Code podcast…

There is a lot going on right now regarding the safety of kids online.

In the United States, the majority of state legislatures have passed age verification laws requiring a variety of websites to more rigorously verify the age of their visitors. In the United Kingdom, Canada, Norway, Spain, and Germany, lawmakers are considering bans on social media access for anyone under the age of 16—Australia passed its ban in 2025. In schools across the world, smartphones have been removed from classrooms, hallways, and cafeterias. And online, some of the most popular apps and video games with children, such as Discord and Roblox, have implemented default restrictions on what young users can find and who they reach.

But all this activity comes after rising crises at home, as an increasing number of behavioral researchers connect increased social media use with increased rates of depression, isolation, and suicidal thoughts. So, until real, societal change takes place, what is a concerned parent to do?

That’s what we’re trying to answer today.

Today, on the Lock and Code podcast with host David Ruiz, we bring back Anna Brading, editor-in-chief of Malwarebytes Labs and director of content and, perhaps most importantly, mother of three. With a long career in cybersecurity—and an equally long time spent reading, writing, and assigning some of the cybersecurity world’s most pressing headlines—Brading has a unique perspective on what is most dangerous to her children online.

Brading’s list of priorities is long, and includes improper image use, “online nastiness,” and Roblox, but she has a few rules and guidelines to help. She sets a one-hour-a-day video game limit on the weekends, restricts YouTube to a communal and monitored activity, and requests that no one share photos of her children online without her express permission. Importantly, she also reminds parents to trust their guts.

“If the norm now is mental health issues or online grooming or non-consensual porn or constant comparison, then I’m okay without my kids fitting in. I would say be radical, buck the trend, don’t do what everybody else is doing. Say no to things you don’t feel comfortable with.”

Tune in today to listen to the full conversation.

Show notes and credits:

Intro Music: “Spellbound” by Kevin MacLeod (incompetech.com)
Licensed under Creative Commons: By Attribution 4.0 License
http://creativecommons.org/licenses/by/4.0/
Outro Music: “Good God” by Wowa (unminus.com)

Listen up—Malwarebytes doesn’t just talk cybersecurity, we provide it.

Protect yourself from online attacks that threaten your identity, your files, your system, and your financial well-being with our exclusive offer for Malwarebytes Premium for Lock and Code listeners.

Categories: Malware Bytes

Hacker Conversations: Jesse McGraw (GhostExodus), From Blackhat Hacker to Redemption

Security Week - Mon, 07/13/2026 - 10:30am

Once a notorious blackhat hacker, McGraw shares his journey from high school hacking and prison to redemption as a cybersecurity advocate.

The post Hacker Conversations: Jesse McGraw (GhostExodus), From Blackhat Hacker to Redemption appeared first on SecurityWeek.

Categories: SecurityWeek

Pages