Files
OpenFUT-Bridge/docs/reverse-engineering.md
funman300 a826e5f7d3 Initial commit: OpenFUT Bridge
FIFA 23 reverse-engineering proxy and integration scaffold.

- Catch-all HTTP proxy that captures all incoming FIFA 23 traffic
- Known-route mapper (speculative FUT paths → Core API calls)
- Placeholder JSON responses for unmapped endpoints
- Admin endpoints: GET /_bridge/captures, GET /_bridge/unknown
- Capture persistence to captures/*.json for RE analysis
- 4 unit tests passing

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-25 15:09:47 -07:00

2.3 KiB

Reverse Engineering Notes — FIFA 23 FUT API

This document tracks what is known and unknown about EA's FUT API as used by FIFA 23.


Status

🔴 Very early — almost nothing confirmed. All mappings in src/mapper.rs are speculative.


Known / Suspected Endpoints

These are guesses based on:

  • Common FUT API patterns from public research
  • Observations from older FIFA titles
  • Community reverse-engineering work
Method Path Purpose Status
POST /ut/auth Authentication / session Suspected
GET /ut/game/fut/user/settings User settings Suspected
GET /ut/game/fut/usermassinfo Club + profile bulk Suspected
GET /ut/game/fut/squad/active Active squad Suspected
GET /ut/game/fut/store/packdetails Pack store Suspected
GET /ut/game/fut/transfermarket Transfer market Suspected

Unknown Endpoints

Run GET /_bridge/unknown after a game session to see what new routes appeared. Each entry represents a real FIFA 23 request that hasn't been mapped yet.


Request Format Notes

Auth

EA FUT auth appears to use a multi-step token flow:

  1. EA account auth (OAuth2-style)
  2. FUT-specific auth with a "nucleus ID"
  3. Session token issued

For offline purposes, OpenFUT Bridge returns a static token that satisfies the client.

Headers

Common headers seen in FUT traffic:

  • X-UT-SID — session token
  • X-UT-PHISHING-TOKEN — anti-CSRF token
  • Content-Type: application/json
  • X-HTTP-Method-Override — EA sometimes uses POST + this header instead of DELETE/PUT

Tools

  • mitmproxy — HTTPS interception
  • Fiddler — Windows-friendly proxy
  • Wireshark — low-level packet capture
  • OpenFUT Bridge captures/ folder — automatic request logging

Resources

  • Previous FIFA FUT API research: search GitHub for "fifa-ut-api", "easfc", "futapi"
  • ea.com documentation: none public
  • Community wikis: FUT Trading community resources

TODO

  • Capture a real FIFA 23 session via mitmproxy
  • Document the auth flow completely
  • Map the squad endpoints
  • Map the pack opening endpoints
  • Map the objectives endpoints
  • Map the SBC endpoints
  • Map the transfer market endpoints
  • Identify which endpoints are critical vs optional