To warm up an old finding of mine. The Kagi apps are using PairIP (Play Integrity Check). This "service" can be bypassed with Magisk and LSPosed; without it you are pretty much out of luck I think. As to why Kagi is using this "service" I can only speculate, but since some requests for direct APK distribution or custom F-Droid repo got ignored I don't think they are interested in removing this malware.
EDIT: I use Kagi services in the web browser on my phone. I'm not interested in apps that don't respect device ownership and user autonomy.