agentsclimarketplace

Cometchat android v5 production

Skill cometchat/cometchat-skills/skills/cometchat-android-v5-production

Production readiness for CometChat Android — server-side token auth, user management CRUD, ProGuard rules, and security checklist.From its SKILL.md

Install
npx -y skills add cometchat/cometchat-skills --skill cometchat-android-v5-production

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.

What its file declares

Copied from the file, not written here

The file declares its own license as MIT. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.

SKILL.md

3.2 KB, 719 tokens by cl100k_base, as published. Nobody here has run it

Ground truth: com.cometchat:chat-uikit-android:5.x (legacy/maintenance-only; +calls-sdk-android:5.x) — resolved AAR (javap) + ui-kit/android. Official docs: https://www.cometchat.com/docs/fundamentals/user-auth · Docs MCP: claude mcp add --transport http cometchat-docs https://www.cometchat.com/docs/mcp (or fetch the URL directly without MCP). Verify symbols against the installed package/source before relying on them.

Companion skills: cometchat-android-v5-core covers dev-mode login; cometchat-android-v5-push covers push notification setup for production.

Purpose

This skill covers hardening a CometChat Android integration for production: replacing client-side Auth Key with server-side token generation, user management CRUD, ProGuard/R8 rules, and security best practices.


Use this skill when

  • "Set up production auth"
  • "Replace Auth Key with tokens"
  • "ProGuard is breaking CometChat"
  • "How do I create CometChat users from my backend?"

Do not use this skill when

  • Setting up dev-mode login → use cometchat-android-v5-core
  • Adding features → use cometchat-android-v5-features

1. Why production auth matters

In dev mode, CometChatUIKit.login(uid) uses the Auth Key embedded in your app. Anyone can decompile the APK, extract the key, and login as ANY user. Production deployments MUST use server-side token generation.

2. Token auth flow

Client → Your Server → CometChat REST API → auth token → Client
Client calls CometChatUIKit.loginWithAuthToken(token)

Your server calls: POST https://{APP_ID}.api-{REGION}.cometchat.io/v3/users/{uid}/auth_tokens with headers: appId, apiKey (REST API Key, NOT Auth Key).

3. Client-side implementation

Java:

// Fetch token from YOUR backend
String token = fetchTokenFromYourServer(currentUserId);

CometChatUIKit.loginWithAuthToken(token, new CometChat.CallbackListener<User>() {
    @Override
    public void onSuccess(User user) {
        // Navigate to chat
    }
    @Override
    public void onError(CometChatException e) {
        // Handle error
    }
});

4. ProGuard/R8 rules

Add to proguard-rules.pro:

-keep class com.cometchat.** { *; }
-keep class com.cometchat.chatuikit.** { *; }
-dontwarn com.cometchat.**

5. Security checklist

  • Auth Key removed from client code
  • REST API Key stored server-side only
  • loginWithAuthToken() used instead of login(uid)
  • ProGuard rules added
  • Network security config allows CometChat domains
  • Push token unregistered on logout

Hard rules

  • Never ship Auth Key in production APKs. Use loginWithAuthToken().
  • REST API Key ≠ Auth Key. REST API Key is server-only. Auth Key is client-side dev-only.
  • Add ProGuard keep rules. R8 can strip CometChat classes needed at runtime.

What ships with it

Read from the repository

Just SKILL.md. No reference files, no scripts.

Keep looking

Skills are one crate of 325,949. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.