Skip to content

[πŸ›] Phone Auth auth/app-not-authorized β€” "play_integrity_token passed, but no matching SHA-256" on Play-signed build, despite correct SHA registrationΒ #9167

Description

@Younes91coding

Issue

signInWithPhoneNumber fails on the Play-distributed Android build (installed
from Play internal testing) with:

[auth/app-not-authorized] This app is not authorized to use Firebase
Authentication... A play_integrity_token was passed, but no matching SHA-256 was
registered in the Firebase console. Please make sure that this application's
packageName/SHA256 pair is registered in the Firebase Console.

Firebase test phone numbers work (they bypass Play Integrity), so the failure
is isolated to Play Integrity token verification for real numbers.

Environment

  • @react-native-firebase/app + /auth 20.5.0
  • Expo SDK 51, React Native 0.74, expo-build-properties targetSdk 35
  • Managed/EAS build (google-services.json via expo.android.googleServicesFile)
  • Android package app.dingdrop.mobile, Play App Signing enabled

Everything verified correct

  • App-signing key SHA-256 (from Play Console β†’ App signing) and SHA-1,
    plus the upload key SHA-256/SHA-1, are all registered on the Firebase
    Android app (confirmed in Project settings). App-signing SHA-256 matches Play
    Console exactly.
  • google-services.json is current and matches app ID / package / project number
    / api_key.
  • Play Integrity API enabled; the Android API key's API restrictions include
    Play Integrity API + Identity Toolkit API.
  • Play Console β†’ App integrity β†’ Integrity API Cloud project linked to the
    Firebase project (582947107702).
  • Clean, Play-only install (all sideloaded builds uninstalled).
  • Several days elapsed (well past SHA propagation).

Question

With all of the above verified, why does the SHA-256 inside the
play_integrity_token not match the registered app-signing SHA-256? Is this a known
Play Integrity ↔ Firebase decryption/propagation issue, and is there a fix or
workaround for real-number phone sign-in on the Play build?

Repro

  1. Configure phone auth per docs (SHA-256 + Play Integrity API).
  2. Install the Play-signed build from an internal-testing track.
  3. Call signInWithPhoneNumber(auth, '+<realNumber>') β†’ the error above.
    (A configured Firebase test number succeeds.)

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions