From 433ccd42118b0b329727c2db48241cf95979d294 Mon Sep 17 00:00:00 2001 From: xodapi <4956501+xodapi@users.noreply.github.com> Date: Sun, 5 Jul 2026 08:38:44 +0700 Subject: [PATCH] docs(android): clarify API key storage (closes #101) --- docs/android.md | 22 ++++++++++++++++++++++ 1 file changed, 22 insertions(+) diff --git a/docs/android.md b/docs/android.md index 389fff4..8e7fe09 100644 --- a/docs/android.md +++ b/docs/android.md @@ -90,6 +90,28 @@ work. This is intentionally not a GitHub Release. Release tags and production release assets stay under the existing release workflow. +## Android API key entry and storage + +For the current test APK, enter the API key directly in the Android UI: + +1. Paste the key into the `VIBEMODE_API_KEY` field. +2. Tap `Сохранить ключ`. +3. Tap `Проверить` to refresh live quota data. + +Do not bake `VIBEMODE_API_KEY` into the APK. Do not commit `.env` files, +keystores, signing passwords, or any real credentials to the repository. + +Current storage model: + +- the key is stored in the app's private Android app storage; +- the value is intended for local app use only and is not logged by the app; +- this is better than shipping a key inside the APK, but it is not yet + encrypted at rest with Android Keystore-backed protection. + +Future hardening should move this secret to Android Keystore or another +encrypted app-storage layer so the device keeps the same simple UI flow with a +stronger storage guarantee. + ## CI Android library check The main CI workflow installs the `aarch64-linux-android` Rust target and runs: