That signature issue you ran into probably boils down to figuring out whether those parameters are cryptographically tied to your session or just derived from something predictable like a timestamp. That one detail makes a huge difference - it tells you whether cracking the signature is actually feasible or whether you're better off just spinning up browser automation and calling it a day. If you want to level up your architecture discovery game, start by explicitly mapping out where each parameter actually comes from like hardcoded stuff, session-derived, generated on the fly, whatever, right at the jump - that's honestly the difference between wrapping this up in a few hours versus drowning in it for weeks. This whole pattern is basically the industry standard now, especially in healthcare, fintech, and government systems where they're paranoid, rightfully so, about security