Android中Google API密钥防暴露:Manifest及Java文件安全使用咨询
Got it, let's tackle that Google API key exposure warning head-on. Here are practical, actionable steps to secure your key while keeping it usable in your XML and Java code:
1. Use Gradle Properties & Build Config (Official Recommended Approach)
This method keeps your key out of plain-text resource files and version control, while still making it accessible to your app:
Step 1: Store the key in
gradle.properties
In your project's root directory, opengradle.propertiesand add:GOOGLE_MAPS_API_KEY=AIza..................................03E GOOGLE_DIRECTIONS_API_KEY=AIza................................03EPro tip: Add
gradle.propertiesto your.gitignorefile so you don't accidentally commit your key to version control.Step 2: Inject the key into your app's build config
Open your app module'sbuild.gradle(the one inside/app) and add these lines inside thedefaultConfigblock:android { defaultConfig { // ... existing code // For Java/Kotlin code access buildConfigField("String", "GOOGLE_MAPS_API_KEY", "\"${GOOGLE_MAPS_API_KEY}\"") buildConfigField("String", "GOOGLE_DIRECTIONS_API_KEY", "\"${GOOGLE_DIRECTIONS_API_KEY}\"") // For XML resource access resValue("string", "google_maps_api_key", "${GOOGLE_MAPS_API_KEY}") resValue("string", "google_direction_api_key", "${GOOGLE_DIRECTIONS_API_KEY}") } }Step 3: Update your Manifest and Java code
- In
AndroidManifest.xml, replace the hardcoded value with the generated string resource:<meta-data android:name="com.google.android.geo.API_KEY" android:value="@string/google_maps_api_key"/> - In your Java code, use the build config value instead of fetching from resources:
+"&"+"key="+BuildConfig.GOOGLE_DIRECTIONS_API_KEY
- In
2. Restrict Your API Key in Google Cloud Console (Critical for Security)
Even if your key somehow leaks, restricting it ensures only your app can use it:
- Go to the Google Cloud Console, find your API key under APIs & Services > Credentials.
- Set Application restrictions:
- Choose Android apps, then add your app's package name (e.g.,
com.your.app.package) and the SHA-1 fingerprint of your signing certificate (add both debug and release fingerprints if needed).
- Choose Android apps, then add your app's package name (e.g.,
- Set API restrictions:
- Choose Restrict key, then select only the APIs your app uses (e.g., Maps SDK for Android, Directions API). This prevents the key from being abused for other Google services.
3. Optional: Encrypt the Key for Extra Security
If you need an extra layer of protection (e.g., for highly sensitive apps), use Android Keystore to encrypt your key:
- Generate an encryption key pair using Android Keystore (this is stored securely on the device, not in your app's code).
- Encrypt your API key with this pair, then store the encrypted string in
strings.xmlor an assets file. - At runtime, decrypt the string using Keystore before using it in your API calls.
This is more complex, but worth it if you're handling sensitive data.
Content of the question comes from stack exchange, question author Noor Hossain

