requestToken
Requests a Play Integrity token from the Google Play Integrity API.
The token is a signed JWT that encodes device integrity, app integrity, and account details. It should be forwarded to your backend server for verification via the Play Integrity API.
This function is coroutine-safe: it suspends the calling coroutine until the token is available or an error occurs, and supports cooperative cancellation via suspendCancellableCoroutine.
A fresh nonce is generated automatically for each call to prevent replay attacks.
Example flow:
// Android side
val token = playIntegrityHelper.requestToken()
api.verifyIntegrity(token)
// Backend side (ASP.NET Core / any server)
// POST https://playintegrity.googleapis.com/v1/{packageName}:decodeIntegrityToken
// { "integrity_token": "<token>" }Return
A signed Play Integrity token string to be sent to your backend.
Throws
If the Play Integrity service is unavailable, the app is not recognised by Google Play, or the device fails integrity checks.
If the calling coroutine is cancelled before the token is delivered.