You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Flutter中集成Google Play Integrity API?关联控制台后卡API请求

Flutter 集成 Google Play Integrity 实操步骤

1. 添加 Flutter 依赖

  • 在项目根目录的 pubspec.yaml 中加入官方插件:
    dependencies:
      google_play_integrity: ^1.2.0  # 替换为最新版本
    
    执行 flutter pub get 完成依赖安装。

2. 配置 Google Cloud 关联项

  • 打开与你的 Play Console 项目绑定的 Google Cloud Console,找到 Play Integrity API 并启用它。
  • 创建 API 密钥:在 Cloud Console 的「API 和服务」>「凭据」页面新建 API 密钥,限制该密钥仅允许你的 Android 应用调用(绑定应用包名和 SHA-1 指纹),这个密钥将用于后端验证。

3. Flutter 端生成 Integrity Token

在需要触发验证的逻辑中(比如应用启动、付费前)加入以下代码:

import 'package:google_play_integrity/google_play_integrity.dart';

Future<String?> getPlayIntegrityToken() async {
  try {
    // 自定义唯一字符串作为请求哈希,防止重放攻击,建议由后端生成后传给客户端
    final String nonce = "your_unique_nonce_here";
    final IntegrityTokenResponse response = await GooglePlayIntegrity.generateIntegrityToken(
      requestHash: nonce,
    );
    return response.token; // 将这个 token 传给后端
  } catch (e) {
    print("生成 Token 失败: $e");
    return null;
  }
}

4. 后端验证 Token(核心环节)

必须通过后端调用 Google 的验证接口,不能在客户端直接处理:

  • 请求地址:https://playintegrity.googleapis.com/v1/[你的应用包名]:decodeIntegrityToken
  • 请求方式:POST,请求头携带 Authorization: Bearer [你的 API 密钥]
  • 请求体:
    {
      "integrity_token": "[客户端传来的 token]"
    }
    
  • 解析响应:重点查看 deviceIntegrity(设备是否合规)、appIntegrity(应用是否为官方版本)、accountIntegrity(账号是否为 Google 认证账号)三个字段,根据业务需求判断是否允许继续操作。

5. 常见问题解决

  • Token 生成失败:确保设备安装了最新版 Google Play 服务,且应用已上传至 Play Console(至少内部测试轨道)。
  • 验证接口返回权限错误:检查 API 密钥的限制规则,确认包名、SHA-1 与应用完全匹配。
  • API 未找到:确认已在 Cloud Console 中启用 Play Integrity API。

内容的提问来源于stack exchange,提问作者Gurjeet Singh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.24 05:37:42