I am building Android apps using Phonegap. The apps use rest APIs. But I have serious questions regarding the security of the API keys. I have been looking for answers everywhere, but the issue hasn't been answered well. As you know, an android apk can be extracted and the Phonegap folder can be reverse engineered. I have these questions/possible solutions regarding the problem :
I have used the Javascript obfuscation. But need a more robust option. Can anyone help out?
The best way to accomplish this is (if you don't have control over the API). To set up your own server side API That stores your credentials and then use that API to make a request to the other API, then your API can send back the response. Think off it like this.
APP > YOUR API > API > YOUR API > APP
I think
https://github.com/tkyaji/cordova-plugin-crypt-file
plugin might help you around. Still it will decrypt the stuff during run time.
This thread also have a similar topic.
How to encrypt the content assets folder in phonegap android application
Hope this helps. :)
If you love us? You can donate to us via Paypal or buy me a coffee so we can maintain and grow! Thank you!
Donate Us With