android / android/nowinandroid
[FR]: Securing Unsplash API Key in APK – Best Practices?
- Dominant language
- Kotlin
- Stars
- 21.8k
- Forks
- 4.6k
- Avg merge
- 19h 20m
- Merged PRs (30d)
- 2
Description
### Is there an existing issue for this?
- [x] I have searched the existing issues
### Describe the problem
I’m currently integrating the Unsplash API into an Android app and I’m concerned about securing the API key inside the APK.
Right now, storing the key in the client feels unsafe. It’s quite easy to intercept traffic using tools like firda extract the API key from network requests.
I’d like to understand how you approach API key security in production apps:
### Describe the solution
I did not find any safe way
### Additional context
_No response_
### Code of Conduct
- [x] I agree to follow this project's Code of Conduct
Contributor guide
Research direction
The issue identifies an Android/Kotlin integration with the Unsplash API but names no repository file, test, or entry point. First clarify whether the project should provide documentation or implement a change; done criteria are not defined in the issue.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- android, kotlin
- Domain
- mobile, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100