You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Android中Google API密钥防暴露:Manifest及Java文件安全使用咨询

How to Secure Your Google API Key in Android & Fix Exposure Warnings

Got it, let's tackle that Google API key exposure warning head-on. Here are practical, actionable steps to secure your key while keeping it usable in your XML and Java code:

This method keeps your key out of plain-text resource files and version control, while still making it accessible to your app:

  • Step 1: Store the key in gradle.properties
    In your project's root directory, open gradle.properties and add:

    GOOGLE_MAPS_API_KEY=AIza..................................03E
    GOOGLE_DIRECTIONS_API_KEY=AIza................................03E
    

    Pro tip: Add gradle.properties to your .gitignore file so you don't accidentally commit your key to version control.

  • Step 2: Inject the key into your app's build config
    Open your app module's build.gradle (the one inside /app) and add these lines inside the defaultConfig block:

    android {
        defaultConfig {
            // ... existing code
            // For Java/Kotlin code access
            buildConfigField("String", "GOOGLE_MAPS_API_KEY", "\"${GOOGLE_MAPS_API_KEY}\"")
            buildConfigField("String", "GOOGLE_DIRECTIONS_API_KEY", "\"${GOOGLE_DIRECTIONS_API_KEY}\"")
            
            // For XML resource access
            resValue("string", "google_maps_api_key", "${GOOGLE_MAPS_API_KEY}")
            resValue("string", "google_direction_api_key", "${GOOGLE_DIRECTIONS_API_KEY}")
        }
    }
    
  • Step 3: Update your Manifest and Java code

    • In AndroidManifest.xml, replace the hardcoded value with the generated string resource:
      <meta-data android:name="com.google.android.geo.API_KEY" android:value="@string/google_maps_api_key"/>
      
    • In your Java code, use the build config value instead of fetching from resources:
      +"&"+"key="+BuildConfig.GOOGLE_DIRECTIONS_API_KEY
      

2. Restrict Your API Key in Google Cloud Console (Critical for Security)

Even if your key somehow leaks, restricting it ensures only your app can use it:

  • Go to the Google Cloud Console, find your API key under APIs & Services > Credentials.
  • Set Application restrictions:
    • Choose Android apps, then add your app's package name (e.g., com.your.app.package) and the SHA-1 fingerprint of your signing certificate (add both debug and release fingerprints if needed).
  • Set API restrictions:
    • Choose Restrict key, then select only the APIs your app uses (e.g., Maps SDK for Android, Directions API). This prevents the key from being abused for other Google services.

3. Optional: Encrypt the Key for Extra Security

If you need an extra layer of protection (e.g., for highly sensitive apps), use Android Keystore to encrypt your key:

  • Generate an encryption key pair using Android Keystore (this is stored securely on the device, not in your app's code).
  • Encrypt your API key with this pair, then store the encrypted string in strings.xml or an assets file.
  • At runtime, decrypt the string using Keystore before using it in your API calls.

This is more complex, but worth it if you're handling sensitive data.


Content of the question comes from stack exchange, question author Noor Hossain

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 08:02:20