Cometchat android v5 production
Skill cometchat/cometchat-skills/skills/cometchat-android-v5-production
Production readiness for CometChat Android — server-side token auth, user management CRUD, ProGuard rules, and security checklist.From its SKILL.md
npx -y skills add cometchat/cometchat-skills --skill cometchat-android-v5-productionAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
What its file declares
Copied from the file, not written here
The file declares its own license as MIT. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.
SKILL.md
3.2 KB, 719 tokens by cl100k_base, as published. Nobody here has run it
Ground truth:
com.cometchat:chat-uikit-android:5.x(legacy/maintenance-only; +calls-sdk-android:5.x) — resolved AAR (javap) +ui-kit/android. Official docs: https://www.cometchat.com/docs/fundamentals/user-auth · Docs MCP:claude mcp add --transport http cometchat-docs https://www.cometchat.com/docs/mcp(or fetch the URL directly without MCP). Verify symbols against the installed package/source before relying on them.
Companion skills:
cometchat-android-v5-corecovers dev-mode login;cometchat-android-v5-pushcovers push notification setup for production.
Purpose
This skill covers hardening a CometChat Android integration for production: replacing client-side Auth Key with server-side token generation, user management CRUD, ProGuard/R8 rules, and security best practices.
Use this skill when
- "Set up production auth"
- "Replace Auth Key with tokens"
- "ProGuard is breaking CometChat"
- "How do I create CometChat users from my backend?"
Do not use this skill when
- Setting up dev-mode login → use
cometchat-android-v5-core - Adding features → use
cometchat-android-v5-features
1. Why production auth matters
In dev mode, CometChatUIKit.login(uid) uses the Auth Key embedded in your app. Anyone can decompile the APK, extract the key, and login as ANY user. Production deployments MUST use server-side token generation.
2. Token auth flow
Client → Your Server → CometChat REST API → auth token → Client
Client calls CometChatUIKit.loginWithAuthToken(token)
Your server calls: POST https://{APP_ID}.api-{REGION}.cometchat.io/v3/users/{uid}/auth_tokens
with headers: appId, apiKey (REST API Key, NOT Auth Key).
3. Client-side implementation
Java:
// Fetch token from YOUR backend
String token = fetchTokenFromYourServer(currentUserId);
CometChatUIKit.loginWithAuthToken(token, new CometChat.CallbackListener<User>() {
@Override
public void onSuccess(User user) {
// Navigate to chat
}
@Override
public void onError(CometChatException e) {
// Handle error
}
});
4. ProGuard/R8 rules
Add to proguard-rules.pro:
-keep class com.cometchat.** { *; }
-keep class com.cometchat.chatuikit.** { *; }
-dontwarn com.cometchat.**
5. Security checklist
- Auth Key removed from client code
- REST API Key stored server-side only
-
loginWithAuthToken()used instead oflogin(uid) - ProGuard rules added
- Network security config allows CometChat domains
- Push token unregistered on logout
Hard rules
- Never ship Auth Key in production APKs. Use
loginWithAuthToken(). - REST API Key ≠ Auth Key. REST API Key is server-only. Auth Key is client-side dev-only.
- Add ProGuard keep rules. R8 can strip CometChat classes needed at runtime.
What ships with it
Read from the repository
Just SKILL.md. No reference files, no scripts.