Meta tags:
description= This document describes how to make standard API requests for integrity verdicts using the Play Integrity API, detailing the process of preparing the integrity token provider, requesting integrity tokens with a request hash for tamper protection, and server-side decryption and verification.;
keywords= Android, Google Play Integrity API, integrity verdicts, standard requests, integrity tokens, server verification, requestHash, Android 5.0;
Headings (most frequently used words):
and, integrity, verdict, request, with, on, the, java, unity, unreal, engine, native, android, make, standard, api, stay, organized, collections, save, categorize, content, based, your, preferences, overview, prepare, token, provider, one, off, protect, requests, against, tampering, recommended, an, demand, decrypt, verify, remediate, issues, google, play, prompt, optional, automatic, replay, protection, more, discover, devices, releases, documentation, downloads, support,
Text of the page (most frequently used words):
the (176), play (78), #integrity (70), android (64), and (56), token (55), #request (51), app (50), your (45), for (43), google (37), you (32), api (22), verdict (22), provider (22), user (19), standardintegritymanager (19), with (18), requesthash (18), get (17), can (17), error (17), prepare (17), all (15), more (15), server (15), from (14), that (14), build (14), libraries (14), how (13), make (12), delegate (12), device (11), use (11), studio (10), this (10), check (10), response (10), create (10), error_code (10), overview (10), tools (10), games (10), wear (9), code (9), learn (9), action (9), call (9), standard (9), integritytokenprovider (9), when (9), design (9), experiences (9), support (8), cars (8), thumb (8), are (8), users (8), standardintegritytokenrequest (8), hash (8), errorcode (8), backend (8), cloudprojectnumber (8), prepareintegritytokenrequest (8), latest (8), core (8), help (7), verdicts (7), console (7), will (7), tokenprovider (7), standardintegrityerrorcode (7), standardintegritytokenprovider (7), builder (7), field (7), services (7), updates (7), compose (7), apps (7), privacy (6), documentation (6), developer (6), samples (6), any (6), times (6), which (6), following (6), complete (6), standard_integrity_no_error (6), myclass (6), integritytokenoperation (6), integritytokenprovideroperation (6), index (6), news (5), releases (5), chromeos (5), devices (5), health (5), blog (5), need (5), down (5), java (5), value (5), resulting (5), com (5), long (5), tokenrequest (5), different (5), called (5), var (5), requests (5), not (5), data (5), tokenproviderrequest (5), prepareintegritytoken (5), programs (5), explore (5), phones (5), tablets (5), foldables (5), quality (5), standardintegritydialogrequest (5), integritydialogrequest (5), guidelines (4), cloud (4), platform (4), reference (4), guides (4), community (4), read (4), issue (4), content (4), protect (4), see (4), example (4), after (4), proceed (4), using (4), set (4), obtain (4), handle (4), new (4), remember (4), resources (4), polling (4), wait (4), return (4), standardintegritytoken (4), actions (4), several (4), opaque (4), bind (4), void (4), estandardintegrityerrorcode (4), yield (4), exception (4), supplying (4), want (4), start (4), against (4), game (4), warm (4), background (4), work (4), plan (4), level (4), sdk (4), delivery (4), monetization (4), jetpack (4), write (4), areas (4), excellent (4), experience (4), glasses (4), form (4), world (4), started (4), brand (3), studies (3), report (3), developers (3), camera (3), media (3), fitness (3), security (3), enterprise (3), information (3), too (3), many (3), steps (3), page (3), next (3), setup (3), time (3), these (3), dialogs (3), based (3), being (3), replay (3), attacks (3), decrypt (3), same (3), result (3), access (3), note (3), project (3), results (3), token_status (3), codes (3), operation (3), above (3), native (3), passing (3), onrequestintegritytokencompleted (3), providing (3), ustandardintegritytokenprovider (3), unity (3), integritytokenresponse (3), task (3), demand (3), digest (3), sha256 (3), token_provider_status (3), onprepareintegritytokencompleted (3), manager (3), plugin (3), before (3), one (3), off (3), verification (3), stay (3), case (3), apis (3), feature (3), together (3), projects (3), interfaces (3), gemini (3), technical (3), preview (3), optimize (3), powered (3), ide (3), adaptive (3), standardintegrityresponse (3), integrityresponse (3), develop (3), details (3), our (3), development (3), best (3), 한국어 (2), 日本語 (2), ภาษาไทย (2), বাংলা (2), हिंदी (2), فارسی (2), العربيّة (2), עברית (2), русский (2), türkçe (2), tiếng (2), việt (2), português (2), brasil (2), polski (2), italiano (2), indonesia (2), français (2), español (2), américa (2), latina (2), deutsch (2), english (2), tips (2), license (2), join (2), bug (2), downloads (2), discover (2), connect (2), business (2), other (2), date (2), last (2), updated (2), 2026 (2), utc (2), trademarks (2), classic (2), store (2), they (2), their (2), issues (2), tip (2), remediation (2), provides (2), option (2), receives (2), determine (2), such (2), tampered (2), give (2), optional (2), empty (2), unevaluated (2), recognition (2), mitigate (2), automatically (2), payload (2), plain (2), text (2), interface (2), playintegrity (2), integrity_token (2), service (2), account (2), encrypted (2), must (2), requesting (2), free (2), integritytoken (2), char (2), const (2), integrity_response_completed (2), integrityresponsestatus (2), async (2), _destroy (2), functions (2), iff (2), standardintegritytokenprovider_request (2), type (2), pointer (2), object (2), initiate (2), binddynamic (2), completion (2), handler (2), callback (2), function (2), fstring (2), cpp (2), standardintegrity_no_error (2), unreal (2), engine (2), getresult (2), break (2), standardintegrityasyncoperation (2), failed (2), appendstatuslog (2), noerror (2), null (2), playasyncoperation (2), 2cp24z (2), string (2), standardintegritymanagerv2 (2), ienumerator (2), handleerror (2), addonfailurelistener (2), addonsuccesslistener (2), setrequesthash (2), gms (2), tasks (2), import (2), construct (2), through (2), method (2), protected (2), side (2), compute (2), stable (2), serialization (2), relevant (2), has (2), checking (2), may (2), tampering (2), player (2), score (2), ensure (2), signed (2), only (2), recommended (2), standardintegritymanager_prepareintegritytoken (2), initialize (2), higher (2), setcloudprojectnumber (2), integritymanagerfactory (2), instance (2), latency (2), however (2), minute (2), number (2), launches (2), preparing (2), well (2), attestation (2), sends (2), calls (2), whenever (2), genuine (2), making (2), events (2), tos (2), product (2), categories (2), authors (2), marketing (2), bundles (2), install (2), referrer (2), reviews (2), asset (2), dev (2), center (2), policies (2), fundamentals (2), better (2), tech (2), bench (2), gradle (2), command (2), line (2), performance (2), test (2), debug (2), workflow (2), connectivity (2), files (2), multidevice (2), fraud (2), prevention (2), identity (2), permissions (2), accessibility (2), kotlin (2), multiplatform (2), testing (2), modularization (2), navigation (2), introduction (2), architecture (2), widgets (2), headsets (2), desktop (2), mobile (2), sandbox (2), experimental (2), productivity (2), social (2), messaging (2), category (2), googlebook (2), factor (2), training (2), hello (2), tokenresponse (2), exceptiondetails (2), integritytokenrequest (2), essentials (2), designed (2), grow (2), real (2), step (2), features (2), browse (2), secure (2), factors (2), subscribe, email, manage, cookies, products, firebase, chrome, research, ndk, download, guide, large, screens, machine, learning, gaming, podcasts, source, linkedin, articles, industry, thoughts, team, medium, follow, googleplaybiz, easy, understand, easytounderstand, solved, problem, solvedmyproblem, otherup, missing, missingtheinformationineed, complicated, toocomplicatedtoomanysteps, out, outofdate, samplescodeissue, otherdown, subject, licenses, described, openjdk, registered, oracle, its, affiliates, arrow_forward, arrow_back, previous, point, troubleshooting, certified, status, troubleshoot, trigger, show, dialog, prompts, take, official, version, indicates, there, unlicensed, compromised, chance, fix, themselves, remediate, prompt, enabled, multi, licensing, prevents, tokens, reused, attempting, repeatedly, cleared, follows, automatic, protection, contains, json, rest, available, programming, languages, including, client, library, googleapis, decodeintegritytoken, package_name, fetch, credentials, scope, within, linked, servers, verify, uses, expire, should, integrity_token_provider_invalid, standardintegritymanager_destroy, standardintegritytokenprovider_destroy, standardintegritytoken_destroy, standardintegritytokenrequest_destroy, standardintegritytoken_gettoken, standardintegritytoken_getstatus, standardintegritytokenrequest_setrequesthash, standardintegritytokenrequest_create, fstandardintegrityoperationcompleteddelegate, fstandardintegritytokenrequest, requestintegritytoken, ustandardintegritytoken, requestintegritytokencoroutine, sendtoserver, have, prepared, compare, digests, match, trustworthy, manner, decode, extract, receive, never, put, sensitive, into, argument, instead, input, default, caution, provide, parameters, happening, maximum, length, 500, bytes, include, crucial, protecting, included, verbatim, values, increase, size, leverage, wants, been, proxy, returns, inside, without, bound, but, specific, opens, possibility, attack, instructions, describe, effectively, prepareintegritytokenrequest_destroy, continue, standardintegritytokenprovider_getstatus, prepareintegritytokenrequest_setcloudprojectnumber, prepareintegritytokenrequest_create, int64_t, context, standardintegritymanager_init, getsubsystem, ustandardintegritymanager, getgameinstance, fprepareintegrityoperationcompleteddelegate, fprepareintegritytokenrequest, int64, requires, prepareintegritytokencoroutine, state, fresh, once, while, keep, internal, applicationcontext, createstandard, typical, few, seconds, majority, ups, under, 10s, warming, invokes, timeout, accommodates, tail, shown, examples, advance, opened, each, per, cold, asynchronous, impact, would, shortly, launched, signs, joins, might, allows, smartly, cache, partial, order, decrease, critical, path, again, way, repeat, less, resource, heavy, checks, decision, outcomes, determines, signals, contained, decrypts, verifies, returning, passes, needs, computes, suitable, algorithm, made, holds, memory, further, makes, send, decryption, then, act, needed, consists, two, parts, sequence, diagram, shows, high, figure, describes, supported, whether, interaction, save, categorize, preferences, organized, collections, standardintegritywebviewrequestmode, standardintegrityverdictoptout, integrityerrorcode, integritydialogtypecode, integritydialogresponsecode, annotations, model, standardintegrityexception, integrityserviceexception, exceptions, classes, integritymanager, package, class, release, notes, terms, safety, additional, recall, about, demo, sign, detailed, manuals, references, specifications, integrate, confidence, upcoming, webinars, workshops, meetups, special, initiatives, teams, achieve, goals, quick, deep, dive, tutorials, smarter, faster, stories, spotlight, collaborative, bring, loop, behind, scenes, looks, evolving, publishing, promoting, managing, deliver, engage, monitize, publish, share, own, pipeline, docs, companion, safeguard, threats, align, robust, testable, maintainable, logic, beautiful, practices, touch, throughout, year, feedback, prescriptive, opinionated, guidance, first, multiple, skip, main,
Text of the page (random words):
nuine overview figure 1 sequence diagram that shows the high level design of the play integrity api a standard request consists of two parts prepare the integrity token provider one off you need to call the integrity api to prepare the integrity token provider well before you need to obtain the integrity verdict for example you can do this when your app launches or in the background before the integrity verdict is needed request an integrity token on demand whenever your app makes a server request that you want to check is genuine you request an integrity token and send it to your app s backend server for decryption and verification then your backend server can determine how to act prepare the integrity token provider one off your app calls the integrity token provider with your google cloud project number your app holds the integrity token provider in memory for further attestation check calls request an integrity token on demand for the user action which needs to be protected your app computes the hash using any suitable hash algorithm such as sha256 of the request to be made your app requests an integrity token passing the request hash your app receives the signed and encrypted integrity token from the play integrity api your app passes the integrity token to your app s backend your app s backend sends the token to a google play server the google play server decrypts and verifies the verdict returning the results to your app s backend your app s backend determines how to proceed based on the signals contained in the token payload your app s backend sends the decision outcomes to your app prepare the integrity token provider one off before you make a standard request for an integrity verdict from google play you must prepare or warm up the integrity token provider this allows google play to smartly cache partial attestation information on the device in order to decrease the latency on the critical path when you make a request for an integrity verdict preparing the token provider again is a way to repeat less resource heavy integrity checks which will make the next integrity verdict that you request more up to date you might prepare the integrity token provider when your app launches i e on cold start up preparing the token provider is asynchronous and so will not impact the start up time this option would work well if you plan to make an integrity verdict request shortly after the app is launched for example when a user signs in or a player joins a game when your app is opened i e on warm start up however note that each app instance can only prepare the integrity token up to 5 times per minute at any time in the background when you want to prepare the token in advance of an integrity verdict request to prepare the integrity token provider do the following create a standardintegritymanager as shown in the following examples construct a prepareintegritytokenrequest supplying the google cloud project number through the setcloudprojectnumber method use the manager to call prepareintegritytoken supplying the prepareintegritytokenrequest tip typical warm up latency is a few seconds and the majority of all warm ups are under 10s however warming up invokes a server call so a timeout that accommodates a long tail of requests is recommended e g of 1 minute java import com google android gms tasks task create an instance of a manager standardintegritymanager standardintegritymanager integritymanagerfactory createstandard applicationcontext standardintegritytokenprovider integritytokenprovider long cloudprojectnumber prepare integrity token can be called once in a while to keep internal state fresh standardintegritymanager prepareintegritytoken prepareintegritytokenrequest builder setcloudprojectnumber cloudprojectnumber build addonsuccesslistener tokenprovider integritytokenprovider tokenprovider addonfailurelistener exception handleerror exception unity ienumerator prepareintegritytokencoroutine long cloudprojectnumber initialize the v2 manager requires play integrity unity plugin v2 0 0 or higher var standardintegritymanager new standardintegritymanagerv2 request the token provider var integritytokenprovideroperation standardintegritymanager prepareintegritytoken new prepareintegritytokenrequest cloudprojectnumber wait for playasyncoperation to complete yield return integritytokenprovideroperation check the resulting error code if integritytokenprovideroperation error null integritytokenprovideroperation error errorcode standardintegrityerrorcode noerror appendstatuslog standardintegrityasyncoperation failed with error integritytokenprovideroperation error errorcode yield break get the response var integritytokenprovider integritytokenprovideroperation getresult unreal engine h void myclass onprepareintegritytokencompleted estandardintegrityerrorcode errorcode ustandardintegritytokenprovider provider check the resulting error code if errorcode estandardintegrityerrorcode standardintegrity_no_error cpp void myclass prepareintegritytoken int64 cloudprojectnumber create the integrity token request fprepareintegritytokenrequest request cloudprojectnumber create a delegate to bind the callback function fprepareintegrityoperationcompleteddelegate delegate bind the completion handler onprepareintegritytokencompleted to the delegate delegate binddynamic this myclass onprepareintegritytokencompleted initiate the prepare integrity token operation passing the delegate to handle the result getgameinstance getsubsystem ustandardintegritymanager prepareintegritytoken request delegate native initialize standardintegritymanager standardintegritymanager_init app s java vm an android context create a prepareintegritytokenrequest opaque object int64_t cloudprojectnumber prepareintegritytokenrequest tokenproviderrequest prepareintegritytokenrequest_create tokenproviderrequest prepareintegritytokenrequest_setcloudprojectnumber tokenproviderrequest cloudprojectnumber prepare a standardintegritytokenprovider opaque type pointer and call standardintegritymanager_prepareintegritytoken standardintegritytokenprovider tokenprovider standardintegrityerrorcode error_code standardintegritymanager_prepareintegritytoken tokenproviderrequest tokenprovider proceed to polling iff error_code standard_integrity_no_error if error_code standard_integrity_no_error remember to call the _destroy functions return use polling to wait for the async operation to complete integrityresponsestatus token_provider_status check for error codes standardintegrityerrorcode error_code standardintegritytokenprovider_getstatus tokenprovider token_provider_status if error_code standard_integrity_no_error token_provider_status integrity_response_completed continue to request token from the token provider remember to free up resources prepareintegritytokenrequest_destroy tokenproviderrequest protect requests against tampering recommended when you re checking a user action in your app with the play integrity api you can leverage the requesthash field to mitigate against tampering attacks for example a game may want to report the player s score to the game s backend server and your server wants to ensure this score has not been tampered with by a proxy server the play integrity api returns the value you set in the requesthash field inside the signed integrity response without the requesthash the integrity token will be bound only to the device but not to the specific request which opens up the possibility of attack the following instructions describe how to make use of the requesthash field effectively when you request an integrity verdict compute a digest of all relevant request parameters e g sha256 of a stable request serialization from the user action or server request that is happening the value set in the requesthash field has a maximum length of 500 bytes include any app request data in the requesthash that is crucial or relevant to the action that you are checking or protecting the requesthash field is included in the integrity token verbatim so long values may increase the request size provide the digest as the requesthash field to the play integrity api and obtain the integrity token caution never put any sensitive information as plain text into the requesthash argument instead hash all the input by default when you receive an integrity verdict decode the integrity token and extract the requesthash field compute a digest of the request in the same manner as in the app e g sha256 of a stable request serialization compare the app side and server side digests if they do not match the request is not trustworthy note standard requests are automatically protected against replay attacks request an integrity verdict on demand after you have prepared the integrity token provider you can start requesting integrity verdicts from google play to do so complete the following steps obtain a standardintegritytokenprovider construct an standardintegritytokenrequest supplying the request hash of the user action you want to protect through the setrequesthash method use the integrity token provider to call request supplying the standardintegritytokenrequest java import com google android gms tasks task standardintegritytokenprovider integritytokenprovider see above how to prepare integritytokenprovider request integrity token by providing a user action request hash can be called several times for different user actions string requesthash 2cp24z task standardintegritytoken integritytokenresponse integritytokenprovider request standardintegritytokenrequest builder setrequesthash requesthash build integritytokenresponse addonsuccesslistener response sendtoserver response token addonfailurelistener exception handleerror exception unity ienumerator requestintegritytokencoroutine standardintegritymanagerv2 standardintegritytokenprovider integritytokenprovider see above how to prepare integritytokenprovider request integrity token by providing a user action request hash can be called several times for different user actions string requesthash 2cp24z var integritytokenoperation integritytokenprovider request new standardintegritytokenrequest requesthash wait for playasyncoperation to complete yield return integritytokenoperation check the resulting error code if integritytokenoperation error null integritytokenoperation error errorcode standardintegrityerrorcode noerror appendstatuslog standardintegrityasyncoperation failed with error integritytokenoperation error errorcode yield break get the response var integritytoken integritytokenoperation getresult unreal engine h void myclass onrequestintegritytokencompleted estandardintegrityerrorcode errorcode ustandardintegritytoken response check the resulting error code if errorcode estandardintegrityerrorcode standardintegrity_no_error get the token fstring token response token cpp void myclass requestintegritytoken ustandardintegritytokenprovider provider prepare the ustandardintegritytokenprovider request integrity token by providing a user action request hash can be called several times for different user actions fstring requesthash fstandardintegritytokenrequest request requesthash create a delegate to bind the callback function fstandardintegrityoperationcompleteddelegate delegate bind the completion handler onrequestintegritytokencompleted to the delegate delegate binddynamic this myclass onrequestintegritytokencompleted initiate the standard integrity token request passing the delegate to handle the result provider request request delegate native create a standardintegritytokenrequest opaque object const char requesthash standardintegritytokenrequest tokenrequest standardintegritytokenrequest_create tokenrequest standardintegritytokenrequest_setrequesthash tokenrequest requesthash prepare a standardintegritytoken opaque type pointer and call standardintegritytokenprovider_request can be called several times for different user actions see above how to prepare token provider standardintegritytoken token standardintegrityerrorcode error_code standardintegritytokenprovider_request tokenprovider tokenrequest token proceed to polling iff error_code standard_integrity_no_error if error_code standard_integrity_no_error remember to call the _destroy functions return use polling to wait for the async operation to complete integrityresponsestatus token_status check for error codes standardintegrityerrorcode error_code standardintegritytoken_getstatus token token_status if error_code standard_integrity_no_error token_status integrity_response_completed const char integritytoken standardintegritytoken_gettoken token remember to free up resources standardintegritytokenrequest_destroy tokenrequest standardintegritytoken_destroy token standardintegritytokenprovider_destroy tokenprovider standardintegritymanager_destroy if your app uses the same token provider for too long the token provider can expire which results in the integrity_token_provider_invalid error on the next token request you should handle this error by requesting a new provider decrypt and verify the integrity verdict after you request an integrity verdict the play integrity api provides an encrypted response token to obtain the device integrity verdicts you must decrypt the integrity token on google s servers to do so complete these steps create a service account within the google cloud project that s linked to your app on your app s server fetch the access token from your service account credentials using the playintegrity scope and make the following request playintegrity googleapis com v1 package_name decodeintegritytoken d integrity_token integrity_token note to access the api s rest interface you can use the google api client library which is available in many programming languages including java read the json response the resulting payload is a plain text token that contains integrity verdicts automatic replay protection to mitigate replay attacks google play automatically prevents integrity tokens from being reused many times attempting to repeatedly decrypt the same token will result in cleared verdicts as follows the device recognition verdict will be empty the app recognition verdict and app licensing verdict will be set to unevaluated any of the optional verdicts that are enabled using the play console will be set to unevaluated or to an empty verdict if it is a multi value verdict remediate verdict issues with a google play prompt optional after your server receives an integrity verdict it can determine how to proceed if the verdict indicates there s an issue such as the app being unlicensed tampered with or the device being compromised you can give users a chance to fix the issue themselves the play integrity api provides an option to show a google play dialog that prompts the user to take action for example to get the official version of your app from google play to learn how to trigger these dialogs from your app based on the server s response see remediation dialogs tip at any ti...
|