Skip to main content

Generate Service Account for Google Play Integrity (Development)

Play Integrity tokens are encrypted and need Google Cloud API access to decrypt and verify. This Service Account credential is used by Fiuu's Attestation Service to call the Google Cloud API, decrypt the token, and process its payload. Because this is a network call, it takes up to ~1 second solely for waiting on the response — see Encrypt Service Account Credential file for why production apps may prefer the exported-key option instead.

  1. Enable the Google Play Integrity API in Google Cloud Console.

    APIs & Services dashboard — Enable APIs and Services API Library search for "Google Play Integrity" Google Play Integrity API product page — Enable button

  2. Create a Service Account in Google Cloud Console.

    Google Cloud Console — Service Accounts page, "Create Service Account" button

  3. Enter the service account details, then click CREATE AND CONTINUE.

    Service account creation form

  4. Grant the Service Account User and Service Usage Consumer roles.

    IAM role grant screen

  5. Click DONE — you'll return to the service account listing. Open the service account you just created (named play-integrity-demo in the source document).

    Service account listing

  6. Create a key for that service account.

    "Keys" tab — "Add Key" button

  7. Select JSON format.

    Key type selection dialog

  8. A JSON key file is generated and downloaded to your machine.

    Download confirmation

Next, encrypt this JSON file before sharing it with Fiuu.