Documentation
README
CLIENT-SIDE REQUEST-SIGNING / ANTI-BOT TOKEN REVERSAL
You hit a request you cannot replay. Burp Repeater returns 401 invalid signature or 403 bot detected even though the browser/app does it fine. There is a sign, sig, X-Signature, _token, nonce, X-Acf-Sensor-Data, or encrypted body the client computes. This skill recovers just enough of that signer to reproduce the request outside the client.
This is the opening of the README. Read the full README on GitHub.