p202 app integrity credential set

Set or rotate the service account (the key is stored encrypted and never shown)

Writessupports --staged
All commands

01Run it

Replace the <placeholders> with your own values, or use the builder below.

p202 app integrity credential set <registration-id> --file <file>

02What you get

Pick the shape you need. People get a table. Add --json, --csv or --ndjson for scripts, or -q for ids only. An AI agent gets compact JSON without asking. All output formats

03Build your command

Pick values and the command line writes itself, quoted and ready to paste.

p202 app integrity credential set

Set flags below; the command updates as you type.

04Flags

1 flag, plus the global flags every command takes.

FlagWhat it does
--file, -fstringrequiredThe service-account key file (JSON); "-" or omitted reads piped stdin

05How it works

Uploads a Google service-account key file for the app. The account must be able to call the Play Integrity API for the app: the Google Cloud project it belongs to is linked to the app in Play Console. Setting it again replaces it (rotation). The server stores the key encrypted and answers with the account's email and key id only.

06For agents

Running this from an agent

  • Read the same facts as JSON: p202 commands app integrity credential set --json.
  • With AI_AGENT, CLAUDECODE or another agent variable set, output is compact JSON and errors arrive on stderr as a JSON envelope with a hint.
  • Exit codes: 0 ok, 1 bad input, 2 auth, 3 network, 4 server error, 5 partial failure.
  • This command writes. Add --staged to record it as a proposal a person applies with p202 change apply.
p202 commands app integrity credential set --json
{
  "path": "p202 app integrity credential set",
  "use": "set <registration-id> --file <service-account.json>",
  "short": "Set or rotate the service account (the key is stored encrypted and never shown)",
  "long": "Uploads a Google service-account key file for the app. The account must be able to call\nthe Play Integrity API for the app: the Google Cloud project it belongs to is linked to the\napp in Play Console. Setting it again replaces it (rotation). The server stores the key\nencrypted and answers with the account's email and key id only.",
  "runnable": true,
  "flags": [
    {
      "name": "file",
      "shorthand": "f",
      "type": "string",
      "default": "",
      "usage": "The service-account key file (JSON); \"-\" or omitted reads piped stdin",
      "required": false
    }
  ]
}