1. 迁移不是可选项——SafetyNet 已全面停用。Google 在弃用时间线中写明:"The SafetyNet Attestation API was deprecated in 2022 and fully turned down in January 2025. Developers should migrate to the Play Integrity API that consolidates multiple integrity offerings (including the SafetyNet Attestation integrity verdict) under a single API." 现存的调用会直接失败:"If you try to call the SafetyNet Attestation API, you will receive an error. The attest API returns a task that always invokes the onFailure listener with an ApiException and a status code of 7 (NETWORK_ERROR)." 若你仍在分发调用 SafetyNet 的版本,请引导用户更新。(https://developer.android.com/privacy-and-security/safetynet/deprecation-timeline)
2. 这个 API 到底核验什么。"The Play Integrity API helps you check that user actions and server requests are coming from your genuine app, installed by Google Play, running on a genuine and certified Android device." 它返回三类核心 verdict:accountDetails(未授权访问——用户是否在 Google Play 上安装或购买过该应用)、appIntegrity(代码被篡改——二进制是否为 Google Play 认可的未修改版本)、deviceIntegrity(风险设备与被模拟环境——是否为经过认证的正版 Android 设备或正版 Google Play Games for PC)。可选 verdict 还包括 MEETS_STRONG_INTEGRITY(已安装近期安全更新,Android 13+)、appAccessRiskVerdict(其他应用截屏、覆盖层、滥用无障碍权限)、playProtectVerdict(Play Protect 已开启且无危险应用)、recentDeviceActivity(请求量异常偏高)与 deviceRecall(beta)。(https://developer.android.com/google/play/integrity/overview)
3. 创建并关联 Google Cloud 项目。"To integrate the API, you must have a Google Cloud project... You can then link your Google Cloud project in the Google Play Console (for apps) or the Google Play SDK Console (for SDKs). Linking your project is required",关联后才能解锁高级功能与配额提升。你可以直接在 Google Cloud Console 中启用 Play Integrity API,也可以先关联、关联时会自动启用。注意这个坑:"Projects that are enabled in the Google Cloud Console but not linked in the Play Console or Play SDK Console are not eligible for additional features."(https://developer.android.com/google/play/integrity/setup)
4. 在 Standard 与 Classic 之间做选择——两者在时延与缓存上不同。Standard 请求时延最低("a few hundred milliseconds on average")、拿到可用 verdict 的可靠性高、使用设备端智能缓存,并把某些攻击的防护交给 Google Play;你只需一次性准备("warm up")token provider——单个实例"can only prepare the integrity token up to 5 times per minute"——之后按需请求 token。Classic 请求(最早的方式)时延更高("a few seconds on average"),会发起一次全新评估、更耗用户数据与电量,并把某些攻击的缓解留给开发者,因此只应"infrequently as a one-off"用于高敏感或高价值的操作。两者都要求 Android 6.0(API level 23)及以上。明确规则:"If you are considering making a classic request and caching it to use later, then you should make a standard request instead to reduce the risk of attacks."(https://developer.android.com/google/play/integrity/overview, https://developer.android.com/google/play/integrity/standard)
5. 在服务端核验,绝不在客户端判断。流程是:应用用你的 Google Cloud 项目号准备 token provider;应用请求 integrity token 并传入一个 request hash;应用收到已签名、已加密的 token 后交给自己的后端;随后"your app's backend sends the token to a Google Play server. The Google Play server decrypts and verifies the verdict, returning the results to your app's backend." 只在后端依据 verdict 做处置——客户端判断可以被逆向绕过。(https://developer.android.com/google/play/integrity/standard)
6. 把 token 绑定到具体那次请求。Standard 请求绑定你在请求 token 时提供的 request hash;Classic 请求使用 nonce 字段,基于请求数据做内容绑定或配合服务端逻辑。不要缓存复用 verdict:"Caching a verdict increases the risk of attacks such as exfiltration and replay." 如果你本打算缓存 Classic 的 verdict 供以后使用,应改用 Standard 请求。(https://developer.android.com/google/play/integrity/classic)
7. 遵守配额。"By default, your app can make up to 10,000 total requests per day across all installs"——可以申请提高每日上限,但要在配额内规划,并且不要频繁准备 token provider(单个实例每分钟最多 5 次)。(https://developer.android.com/google/play/integrity/overview)
8. 不误伤正常用户地逐步放开判定。Google 的明确建议:先"implement the API without enforcement","gather telemetry and understand your audience before taking action",再估算任何启用判定的影响并调整你的反滥用策略。把该 API 当作一个信号而非整套策略:"The Play Integrity API works best when used alongside other signals as part of your overall anti-abuse strategy and not as your sole anti-abuse mechanism." 该 API 覆盖手机、平板、折叠屏、Android Auto、Android TV、Android XR、ChromeOS、Wear OS 以及 Google Play Games on PC。(https://developer.android.com/google/play/integrity/overview)