使用Scottyab SafetyNet库遇NETWORK_ERROR,示例包名应用正常
First, let's recap your issue clearly:
We're using the Scottyab SafetyNet Library, and our app with package name
com.safetynet.sampleis throwingStatus{statusCode=NETWORK_ERROR, resolution=null}even on a 4G connection. However, the official sample app with package namecom.scottyab.safetynet.sampleworks perfectly fine. We've tried relevant solutions without success, here's a snippet of the problematic code:private void runSafetyNetTest() { Log.v(TAG, "running SafetyNet.API Test"); requestNonce = gene...
Since the sample app works flawlessly, the issue is almost certainly tied to differences between your app's setup and the sample's. Let's break down the most likely fixes step by step:
1. Double-Check API Key Restrictions
SafetyNet relies heavily on API key restrictions tied to package names and SHA-1 fingerprints—this is the #1 culprit when a custom package fails but the sample works:
- Head to your Google Cloud Console, locate the API key you're using for SafetyNet.
- Under Application restrictions, confirm that your package name (
com.safetynet.sample) AND its corresponding SHA-1 fingerprint (for both debug and release builds, if applicable) are added. - It's easy to miss adding the debug SHA-1—if you're testing with a debug build, make sure that's included too.
2. Audit Network Security Config
Even with a working 4G connection, your app's network policies might be blocking the SafetyNet endpoint:
- If you have a
res/xml/network_security_config.xmlfile, verify it allows connections to*.googleapis.com(SafetyNet's API endpoint lives here). - For Android 9+, ensure you haven't restricted background network access if your SafetyNet call is triggered in a background context.
- Double-check that
cleartextTrafficPermittedisn't set incorrectly (though SafetyNet uses HTTPS, misconfigurations here can still cause unexpected network blocks).
3. Validate Nonce Generation & Library Setup
Your truncated code shows requestNonce = gene...—nonce issues are a common source of silent failures that manifest as network errors:
- Ensure your nonce is at least 16 bytes long, generated using a secure random source like
SecureRandom(avoid using weak or predictable nonces). - Compare your client initialization code directly to the sample app. Here's what the sample's typical call looks like:
Make sure you're passing the correct API key and nonce, with no accidental truncation or encoding mistakes.SafetyNet.getClient(this) .attest(requestNonce, YOUR_API_KEY) .addOnSuccessListener(this, successListener) .addOnFailureListener(this, failureListener);
4. Fix ProGuard/R8 Obfuscation
If you're using code obfuscation, it might be stripping critical parts of the SafetyNet library:
- Add these rules to your
proguard-rules.profile to protect the library classes:-keep class com.scottyab.safetynet.** { *; } -keep class com.google.android.gms.safetynet.** { *; } -keepattributes Signature - After adding these, clean your project and rebuild to eliminate obfuscation-related breakage.
5. Rule Out Carrier-Specific Blocks
Rarely, some mobile carriers restrict access to certain Google API endpoints on 4G:
- Test your app on a different carrier's 4G network to see if the error goes away.
- Try using a VPN—if the SafetyNet call works with a VPN, it's likely a carrier-level restriction you'll need to work around (or contact your carrier about).
Bonus Debug Tips
- Add verbose logging to get more context before the call:
Log.d(TAG, "Using API Key: " + YOUR_API_KEY); Log.d(TAG, "Generated nonce length: " + requestNonce.length); - Check logcat for more detailed network errors (like SSL handshake failures or connection timeouts) that might be hidden behind the generic
NETWORK_ERRORstatus.
内容的提问来源于stack exchange,提问作者Jigar Shekh

