Skillquality 0.46

cometchat-android-v5-production

Production readiness for CometChat Android — server-side token auth, user management CRUD, ProGuard rules, and security checklist.

Price
free
Protocol
skill
Verified
no

What it does

Companion skills: cometchat-android-v5-core covers dev-mode login; cometchat-android-v5-push covers push notification setup for production.

Purpose

This skill covers hardening a CometChat Android integration for production: replacing client-side Auth Key with server-side token generation, user management CRUD, ProGuard/R8 rules, and security best practices.


Use this skill when

  • "Set up production auth"
  • "Replace Auth Key with tokens"
  • "ProGuard is breaking CometChat"
  • "How do I create CometChat users from my backend?"

Do not use this skill when

  • Setting up dev-mode login → use cometchat-android-v5-core
  • Adding features → use cometchat-android-v5-features

1. Why production auth matters

In dev mode, CometChatUIKit.login(uid) uses the Auth Key embedded in your app. Anyone can decompile the APK, extract the key, and login as ANY user. Production deployments MUST use server-side token generation.

2. Token auth flow

Client → Your Server → CometChat REST API → auth token → Client
Client calls CometChatUIKit.loginWithAuthToken(token)

Your server calls: POST https://{APP_ID}.api-{REGION}.cometchat.io/v3/users/{uid}/auth_tokens with headers: appId, apiKey (REST API Key, NOT Auth Key).

3. Client-side implementation

Java:

// Fetch token from YOUR backend
String token = fetchTokenFromYourServer(currentUserId);

CometChatUIKit.loginWithAuthToken(token, new CometChat.CallbackListener<User>() {
    @Override
    public void onSuccess(User user) {
        // Navigate to chat
    }
    @Override
    public void onError(CometChatException e) {
        // Handle error
    }
});

4. ProGuard/R8 rules

Add to proguard-rules.pro:

-keep class com.cometchat.** { *; }
-keep class com.cometchat.chatuikit.** { *; }
-dontwarn com.cometchat.**

5. Security checklist

  • Auth Key removed from client code
  • REST API Key stored server-side only
  • loginWithAuthToken() used instead of login(uid)
  • ProGuard rules added
  • Network security config allows CometChat domains
  • Push token unregistered on logout

Hard rules

  • Never ship Auth Key in production APKs. Use loginWithAuthToken().
  • REST API Key ≠ Auth Key. REST API Key is server-only. Auth Key is client-side dev-only.
  • Add ProGuard keep rules. R8 can strip CometChat classes needed at runtime.

Capabilities

skillsource-cometchatskill-cometchat-android-v5-productiontopic-agent-skillstopic-ai-agenttopic-chattopic-claude-codetopic-cometchattopic-cursortopic-messagingtopic-nextjstopic-reacttopic-react-nativetopic-ui-kit

Install

Quality

0.46/ 1.00

deterministic score 0.46 from registry signals: · indexed on github topic:agent-skills · 27 github stars · SKILL.md body (2,412 chars)

Provenance

Indexed fromgithub
Enriched2026-05-18 19:04:45Z · deterministic:skill-github:v1 · v1
First seen2026-05-07
Last seen2026-05-18

Agent access