Here's another idea but I don't remember the exact implementation.
I used my laptop as a proxy for my Android phone. On the laptop I run Wire Shark to monitor the network activity. This exposes the API endpoints and other nasty stuff.
At least that's why I remember it anyway.
is there a way to monitor what API a mobile app is, calling?