Skip to main content

Export Google Play Integrity Key (Beta/Production)

This option requires your app to already be uploaded to the Google Play Store (Beta or Production track). It exports the Google Play Integrity private key for local token processing, which reduces network round-trip time compared to the service-account approach above.

  1. Create a new RSA key pair (2048-bit):

    openssl genrsa -aes128 -out private.pem 2048

    Terminal output of openssl genrsa generating private.pem

  2. Derive the public key from the private key:

    openssl rsa -in private.pem -pubout > public.pem

    Terminal output of openssl rsa deriving public.pem

  3. In the Google Play Console, go to your app's App Integrity section.

    Google Play Console — App Integrity section

  4. Under Integrity API > Response Encryption, select Change.

    Response Encryption "Change" option

  5. Select Manage and download my response encryption key, then upload the public.pem generated in step 2.

    Public key upload dialog

  6. Select Save Changes. Play Console generates the app's response encryption key and prompts you to download the encrypted keys (.enc) file.

    Screenshot: Encrypted key download prompt. The source document did not include a screenshot for this step.

  7. Decrypt the .enc file into api_keys.txt using the private key from step 1:

    openssl rsautl -decrypt -oaep -inkey private.pem -in keys.enc > api_keys.txt
  8. Encrypt api_keys.txt and share it with Fiuu.