Blog | G5 Cyber Security

App Store Authorisation: No Backend

TL;DR

You want to let users install apps from a public store (like Google Play or the Apple App Store) without your app needing to talk to your own servers. This guide explains how to do that securely, focusing on verifying the user’s choice and preventing tampering.

Solution Guide

  1. Understand the Limitations
  • App Signing and Package Verification
  • Deep Linking with App Store URLs
  • Intent Filters (Android Only)
  • URL Scheme Handling (iOS Only)
  • User Confirmation and Transparency
  • Regularly Update Signing Keys
  • Consider App Attestation (Advanced)
  • Exit mobile version