v1

latestOpenAPI 3.0.0Creative Commons Attribution 3.02026-07-13274687.3 KB
projects

Accepts an App Attest CBOR attestation and verifies it with Apple using your preconfigured team and bundle IDs. If valid, returns an attestation artifact that can later be exchanged for an AppCheckToken using ExchangeAppAttestAssertion. For convenience and performance, this method's response object will also contain an AppCheckToken (if the verification is successful).

post/v1/{+app}:exchangeAppAttestAttestation

Path parameters

appstring required

Required. The relative resource name of the iOS app, in the format: projects/{project_number}/apps/{app_id} If necessary, the project_number element can be replaced with the project ID of the Firebase project. Learn more about using project identifiers in Google's AIP 2510 standard.

Request body

keyIdstring byte

Required. The key ID generated by App Attest for the client app.

attestationStatementstring byte

Required. The App Attest statement returned by the client-side App Attest API. This is a base64url encoded CBOR object in the JSON response.

challengestring byte

Required. A one-time challenge returned by an immediately prior call to GenerateAppAttestChallenge.

limitedUseboolean

Specifies whether this attestation is for use in a limited use (true) or session based (false) context. To enable this attestation to be used with the replay protection feature, set this to true. The default value is false.

Response

Successful response