question

pdaz avatar image
pdaz asked

How to revoke developer secret key?

I took a secret key and put it into my apk so some users could ban players.

Yesterday this key was extracted and used to hack my game, so I revoked this key. BUT I still can run any Admin API.

My Title Id is 1941

Old secret key is JX14DQFWFB1R5KWC5EBB3EBCXFNYQJNOT9RH3TA1MQQ******

Please revoke it completely so no Admin API could be run.

I am gong to make a clou script for banning purposes.

1 comment
10 |1200

Up to 2 attachments (including images) can be used with a maximum of 512.0 KiB each and 1.0 MiB total.

pdaz avatar image pdaz commented ·

Yes, old key is not revoked but it's not in the list! This hacker created a new player with tons of GM yesterday.

0 Likes 0 ·

1 Answer

·
brendan avatar image
brendan answered

We've removed your old secret key from the title, so this won't be an issue anymore. To be clear, under the covers all titles have a hidden secret key which is not exposed to you in any way. For older titles, the existing secret key was converted to that hidden secret, which was incorrect. We'll be updating shortly to make it so that these older titles have their original secret key moved to the revocable set, and a new hidden key added.

For others, if you have accidentally exposed your secret key and need it removed before we've completed this update, please let us know and we'll take care of this.

10 |1200

Up to 2 attachments (including images) can be used with a maximum of 512.0 KiB each and 1.0 MiB total.

Write an Answer

Hint: Notify or tag a user in this post by typing @username.

Up to 2 attachments (including images) can be used with a maximum of 512.0 KiB each and 1.0 MiB total.