For developers · Checked 30 September 2026

The Play Integrity API: what it checks and how to use it

Short answer: the Play Integrity API lets your backend check that a request comes from your unmodified app, installed from Google Play, on a genuine certified Android device. Your app asks for an integrity token, your server decodes it and reads the verdicts, and you decide what to allow. By default an app can make 10,000 requests a day across all installs; linking your Google Cloud project in Play Console lets you ask for more.

Device integrity labels

From Android Developers «Integrity verdicts», read 30 September 2026. The basic and strong labels are optional and must be opted in; a device returns every label it meets.

LabelWhat it means
MEETS_STRONG_INTEGRITY (opt-in)Genuine certified device; on Android 13+ also security updates in the last year for all partitions
MEETS_DEVICE_INTEGRITYGenuine certified Android device; on Android 13+ hardware-backed proof of a locked bootloader and certified OS image
MEETS_BASIC_INTEGRITY (opt-in)Passes basic system integrity checks; bootloader may be unlocked, device may not be certified
MEETS_VIRTUAL_INTEGRITYAndroid emulator with Google Play services, for apps released to Google Play Games for PC
EmptySigns of attack or compromise, such as hooking or rooting, or an emulator that fails the checks

What the verdicts cover

Three verdicts come by default. appRecognitionVerdict is PLAY_RECOGNIZED when the binary is the one Google Play knows. appLicensingVerdict is LICENSED when the user got the app from Google Play, and you can show the GET_LICENSED dialog to users who did not. deviceIntegrity carries the device labels in the table. Opt-in verdicts add more: appAccessRiskVerdict for apps that could capture the screen, draw overlays or control the device, playProtectVerdict for Play Protect status and known malware, recentDeviceActivity for unusually many requests, and device recall, in beta, to recognise a device you flagged before even after a reinstall or reset.

Standard or classic requests

Standard requests suit any app: after a warm-up of a few seconds they return in a few hundred milliseconds on average, can be made on demand for any action, and Google Play handles protection against replay attacks. Bind them to the action with the requestHash field, a digest of the relevant request values. Classic requests are the original method: a few seconds per call, more data and battery, and you protect them yourself with a nonce checked on your server, so keep them for rare, high-value actions. Google advises against caching a classic verdict for later; make a standard request instead. Both return the same verdict format.

Setting it up

Every app calling the API needs a Google Cloud project. In Play Console, open your app, go to Protected with Play, choose Get started next to Play Integrity API and click Link Cloud project; the API is enabled on the project automatically. Linking is what makes you eligible for optional verdicts and a higher daily quota. Test devices that fail device integrity usually need the factory ROM and a locked bootloader, and Play Console lets you create Play Integrity API tests.

Roll it out without locking out real users

Google’s advice is to use the verdicts as one signal in an anti-abuse strategy, not as the only one, and to start without enforcement: collect the verdicts your current users return, estimate who a rule would block, then enforce. Ask for a verdict as close as possible to the action you are protecting, and consider a tiered response, for example allowing reading on a basic device but requiring device integrity for payments or rewards. The API works on phones, tablets, foldables, Android Auto, Android TV, Android XR, ChromeOS, Wear OS and Google Play Games for PC.

Where Censuus fits

Protecting the app keeps the numbers honest; being found is the rest. Censuus ranks apps by the visits they draw, and adding your app is free on the List my app form. Placement comes from traffic and sponsorship: apps climb on the visits they draw, and a sponsor can pay to rise higher.

Frequently asked questions

How many Play Integrity API requests can I make per day?

By default up to 10,000 requests a day across all installs. You can request a higher daily maximum after linking your Google Cloud project in Play Console.

What is the difference between MEETS_DEVICE_INTEGRITY and MEETS_STRONG_INTEGRITY?

Device integrity means a genuine certified Android device. Strong integrity, an opt-in label, also requires security updates in the last year for all partitions on Android 13 and later.

Should I use standard or classic requests?

Standard requests for most checks: lower latency and replay protection handled by Google Play. Classic requests only for rare, high-value actions, protected with a nonce on your server.

Do I need a Google Cloud project for Play Integrity?

Yes. Every app or SDK calling the API needs one, and linking it in Play Console under Protected with Play unlocks optional verdicts and quota increases.

Should I block users who fail the integrity check right away?

Google recommends collecting verdicts without enforcement first to see the impact on your real users, and using the API alongside other anti-abuse signals.

Guides for app developers

Put your app in the ranking

Censuus ranks apps by the visits they draw and by sponsorship, no bots. Listing is free; sponsorship raises placement.