Cometchat android v6 production
Skill cometchat/cometchat-skills/skills/cometchat-android-v6-production
CometChat Android UIKit v6 production readiness — token auth, ProGuard/R8, security checklist, release configurationFrom its SKILL.md
npx -y skills add cometchat/cometchat-skills --skill cometchat-android-v6-productionAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
What its file declares
Copied from the file, not written here
The file declares its own license as MIT. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.
SKILL.md
6.0 KB, ~1.4k tokens by cl100k_base, as published. Nobody here has run it
Ground truth:
com.cometchat:chatuikit-{compose,kotlin}-android:6.x(+calls-sdk-android:5.x) — resolved AAR (javap) +ui-kit/android/v6. Official docs: https://www.cometchat.com/docs/fundamentals/user-auth · Docs MCP:claude mcp add --transport http cometchat-docs https://www.cometchat.com/docs/mcp(or fetch the URL directly without MCP). Verify symbols against the installed package/source before relying on them.
Companion skills: cometchat-android-v6-core (init/login), cometchat-android-v6-builder-settings (UIKitSettings), cometchat-android-v6-push (FCM)
Purpose
Prepare a CometChat v6 Android app for production release — switch to token-based auth, configure ProGuard/R8, apply security best practices, and optimize the release build.
Use this skill when
- Preparing an app for production/release
- Switching from authKey to token-based authentication
- Configuring ProGuard/R8 rules for CometChat
- Reviewing security best practices
Do not use this skill when
- Setting up for development (use
cometchat-android-v6-core) - Debugging issues (use
cometchat-android-v6-troubleshooting)
1. Token-Based Authentication
1.1 Never Ship authKey
// ❌ NEVER in production
val settings = UIKitSettings.UIKitSettingsBuilder()
.setAppId("APP_ID")
.setRegion("us")
.setAuthKey("AUTH_KEY") // REMOVE THIS
.build()
CometChatUIKit.login("uid", callback) // Uses authKey internally
// ✅ Production pattern
val settings = UIKitSettings.UIKitSettingsBuilder()
.setAppId("APP_ID")
.setRegion("us")
// No authKey
.build()
// Get token from your backend server
val authToken = yourServer.getAuthToken(userId)
CometChatUIKit.loginWithAuthToken(authToken, callback)
1.2 Server-Side Token Generation
Your backend generates auth tokens using the CometChat REST API:
- Endpoint:
POST https://{appId}.api-{region}.cometchat.io/v3/users/{uid}/auth_tokens - Header:
apiKey: YOUR_API_KEY(server-side only)
The auth token is then passed to the client for loginWithAuthToken().
2. ProGuard / R8 Configuration
2.1 Consumer Rules
CometChat UIKit modules include consumer-rules.pro that are automatically applied. Check that your app's build.gradle.kts has:
android {
buildTypes {
release {
isMinifyEnabled = true
proguardFiles(
getDefaultProguardFile("proguard-android-optimize.txt"),
"proguard-rules.pro"
)
}
}
}
2.2 Additional ProGuard Rules
If you encounter issues with minification, add these rules:
# CometChat SDK
-keep class com.cometchat.chat.** { *; }
-keep class com.cometchat.calls.** { *; }
# CometChat UIKit
-keep class com.cometchat.uikit.** { *; }
# Gson (used for FCM DTO parsing)
-keep class com.google.gson.** { *; }
-keepattributes Signature
-keepattributes *Annotation*
# Firebase
-keep class com.google.firebase.** { *; }
3. Security Checklist
| Item | Status | Notes |
|---|---|---|
Remove authKey from client code | Required | Use loginWithAuthToken() |
Store appId securely | Recommended | Use BuildConfig or encrypted prefs |
| Use HTTPS for all custom endpoints | Required | overrideAdminHost / overrideClientHost |
| Validate auth tokens server-side | Required | Tokens should expire |
| Do not log sensitive data | Required | Remove debug logs in release |
| Enable R8/ProGuard | Recommended | Obfuscates code |
| Pin SSL certificates | Optional | For high-security apps |
4. Release Build Configuration
android {
compileSdk = 36
defaultConfig {
minSdk = 28
targetSdk = 36
}
buildTypes {
release {
isMinifyEnabled = true
isShrinkResources = true
proguardFiles(
getDefaultProguardFile("proguard-android-optimize.txt"),
"proguard-rules.pro"
)
}
}
compileOptions {
sourceCompatibility = JavaVersion.VERSION_11
targetCompatibility = JavaVersion.VERSION_11
}
kotlinOptions {
jvmTarget = "11"
}
}
5. Dependency Management
5.1 Compose BOM
For Compose stack, use the BOM to align Compose library versions:
implementation(platform("androidx.compose:compose-bom:2024.x.x"))
implementation("androidx.compose.ui:ui")
implementation("androidx.compose.material3:material3")
5.2 Version Pinning
Pin CometChat SDK versions explicitly:
implementation("com.cometchat:chatuikit-compose-android:6.0.+")
// or
implementation("com.cometchat:chatuikit-kotlin-android:6.0.+")
Never pin
6.0.0-beta2(or any-betapreview) in a production build — V6 went GA on 2026-05-25. The6.0.+dynamic pin tracks GA patches forward (ENG-35701). Pin an exact GA patch (e.g.6.0.1) if your release process requires reproducible builds.
6. minSdk 28 Implications
v6 requires minSdk = 28 (Android 9.0 Pie). This means:
- No support for Android 7.0-8.1 devices
- Full TLS 1.3 support
- Native BiometricPrompt API available
- Adaptive icons required
Hard rules
- NEVER ship
authKeyin production builds — it allows anyone to create users and login - ALWAYS use
loginWithAuthToken()with server-generated tokens in production - ALWAYS test the release build with ProGuard/R8 enabled before shipping — CometChat uses reflection in some areas
minSdkmust be 28 — do NOT lower it, v6 APIs depend on API 28+ features- Remove all
Log.d()/ debug logging in release builds — useBuildConfig.DEBUGguards
What ships with it
Read from the repository
Just SKILL.md. No reference files, no scripts.
Gives 0 of the 12 instructions most ship operate skills give in ~1.4k tokens
Counted across 1,077 of the 1,713 authors here whose files we hold, read 2026-09-06
- Create GitHub releasein 44 of 1077, across 43 files
- Run the test suitein 30 of 1077, across 25 files
- Create and push git tagin 27 of 1077, across 26 files
- Push commits and tagsin 27 of 1077
- Create annotated tagin 25 of 1077, across 22 files
- Ensure working tree is cleanin 24 of 1077
- Check for product marketing context firstin 23 of 1077, across 6 files
- Commit version bump changesin 22 of 1077, across 21 files
- Update CHANGELOG.mdin 21 of 1077, across 20 files
- Structure launch marketing across three channel typesin 20 of 1077, across 5 files
- Commit and tag the releasein 20 of 1077, across 18 files
- Update the CHANGELOG for new releasesin 19 of 1077
Said here and by no other author read
- Switch to token-based authentication
- Configure ProGuard and R8 rules
- Enable minification in release builds
- Set minimum SDK to 28
Grouped from the skills themselves: near-identical wordings counted once, and counted by distinct author, so one author publishing three of these counts once. Length counted with cl100k_base; the agent that loads this file may tokenize it differently.