v1

latestOpenAPI 3.0.0Creative Commons Attribution 3.02026-07-13274687.3 KB
projects

Accepts an App Attest assertion and an artifact previously obtained from ExchangeAppAttestAttestation and verifies those with Apple. If valid, returns an AppCheckToken.

post/v1/{+app}:exchangeAppAttestAssertion

Path parameters

appstring required

Required. The relative resource name of the iOS app, in the format: projects/{project_number}/apps/{app_id} If necessary, the project_number element can be replaced with the project ID of the Firebase project. Learn more about using project identifiers in Google's AIP 2510 standard.

Request body

artifactstring byte

Required. The artifact returned by a previous call to ExchangeAppAttestAttestation.

assertionstring byte

Required. The CBOR-encoded assertion returned by the client-side App Attest API.

challengestring byte

Required. A one-time challenge returned by an immediately prior call to GenerateAppAttestChallenge.

limitedUseboolean

Specifies whether this attestation is for use in a limited use (true) or session based (false) context. To enable this attestation to be used with the replay protection feature, set this to true. The default value is false.

Response

Successful response