The epsilon-integrity-check module requests a device attestation token so your backend can verify that the app is running on a legitimate device. Android uses the Play Integrity API. iOS uses App Attest.
The module returns the token. Your backend verifies it.
DeviceIntegrityCheck entry point on every target.IntegrityCheckResult.JVM and JavaScript call nonceProvider and then return an empty IntegrityCheckResult. Attestation runs on Android and iOS.
Requests an attestation token for a nonce supplied by your backend.
Holds either the attestation token or an error message.
Construct it with a CommonContext from epsilon-core. On Android that type is android.content.Context. On iOS, JVM, and JavaScript, pass the stub Context object from ag.sportradar.mobile.epsilon.context.
getIntegrityToken calls nonceProvider once and embeds that nonce in the attestation. Fetch the nonce from your backend inside the lambda. Coroutine cancellation is propagated to the caller. Any other failure from the nonce provider, or from the platform attestation call, is returned as IntegrityCheckResult.error.
Request example
val integrityCheck = DeviceIntegrityCheck(commonContext)
val result = integrityCheck.getIntegrityToken {
backend.fetchNonce()
}
val token = result.token
if (token != null) {
backend.verifyIntegrityToken(token)
} else {
val message = result.error
}On iOS the class is exported as EpsilonDeviceIntegrityCheck.
| Property | Meaning |
|---|---|
token | Attestation token to send to your backend. null when the check failed. |
error | Human-readable failure message. null when the check succeeded. |
On Android and iOS, a finished check sets one of these properties. On JVM and JavaScript, both stay null after a successful nonce fetch.
On iOS the type is exported as EpsilonIntegrityCheckResult.
The Android implementation calls the Play Integrity API with the nonce and returns the Play Integrity token.
The Play nonce must be a URL-safe, non-wrapping Base64 string between 16 and 500 characters. The same nonce is reused for retries, so it has to stay valid for the whole retry window.
Retried Play error codes are network failure, too many requests, Google server unavailable, client transient error, and internal error. Other Play errors are returned immediately in IntegrityCheckResult.error.
Link the app to Play Integrity in the Play Console. This module sends only the nonce. Play resolves the cloud project from that app linking.
The iOS implementation uses DCAppAttestService. The nonce string is SHA-256 hashed before it is passed to App Attest. The returned token is the Base64-encoded attestation object or assertion.
Enable the App Attest capability on the app. Devices where App Attest is unavailable return that failure in IntegrityCheckResult.error.
Lifecycle:
These targets call nonceProvider and then return IntegrityCheckResult() with token and error both null.
Add the dependency to your commonMain:
dependencies {
implementation("ag.sportradar.mobile.epsilon:epsilon-integrity-check:<version>")
}This module depends on epsilon-core and exports it, so CommonContext is available when you include integrity.
To use the types from Swift, export the module from your iOS framework. See the Integration Guide.