openrtc-trust-play-integrity
v2.8.8
Published
Optional Google Play Integrity host adapter for OpenRTC 2.0 device enrollment.
Readme
openrtc-trust-play-integrity
This package adapts an application-owned native Play Integrity implementation
to OpenRTC's provider-neutral enrollment interface. The native host must bind
the returned standard token to base64url(SHA-256(challenge)) as the Play
Integrity requestHash. Package/signing identity, freshness, request hash,
app recognition, licensing policy, and device-integrity verdicts are validated
by the managed server adapter. Request tokens only for enrollment, key
rotation, recovery, or an explicit risk escalation—not as a connection timer.
The adapter declares request-challenge binding. OpenRTC still verifies the
install-key signature and nonce independently, and the server derives the
authoritative trust policy from the registered provider rather than trusting a
client-declared strength.
