Skip to content
Contact us

Moatgator Attest

Trust the device before you trust the transaction.

Signed verdicts that tell your backend whether the app and the device are genuine, before a sensitive action runs.

Your app, Attest, Your backend, Genuine, Tampered, Allow, Block

A verdict your backend can verify.

Attest combines platform integrity signals with Moatgator's own checks and returns a single signed verdict. Your backend verifies the signature and decides whether to continue.

  • Built on Play Integrity and App Attest signals
  • Signed verdicts, verified on your side
  • Decide before a sensitive action runs

What Attest gives you

  • 01

    Genuine app

    Confirms the running app is the one you published, unmodified and correctly signed.

  • 02

    Genuine device

    Combines Play Integrity and App Attest results with runtime checks for a fuller picture than any single source.

  • 03

    One signed verdict

    Every signal is merged into a single verdict that is signed, so your backend does not have to trust the network or the client.

  • 04

    Low-latency service

    A multi-region service built so that attestation does not slow down the moment a customer taps pay.

  • 05

    Verify in your language

    Verify verdicts with the Node.js SDK, or with the Java, Go, Python and .NET SDKs and guides.

  • 06

    Decide per action

    Allow, step up or block depending on the risk of the action, using the verdict fields you choose.

How a verdict is issued

  1. 1

    The app asks

    Before a sensitive action, the app requests an integrity token bound to that action.

  2. 2

    Moatgator evaluates

    Platform signals and runtime checks are combined and returned as one signed verdict.

  3. 3

    Your backend decides

    Your server verifies the signature and the fields it cares about, then allows, steps up or blocks.

verdict.jsonIllustrative example
{  "app": {    "package": "com.example.pay",    "signature": "match"  },  "device": {    "integrity": "MEETS_DEVICE_INTEGRITY",    "rooted": false  },  "session": { "hooking": false, "overlay": false },  "risk": "low",  "nonce": "b7f1c3…",  "signature": "MEUCIQ…"}

What a verdict contains

App

  • Package name and signature match
  • Build and version
  • Tamper state

Device

  • Play Integrity or App Attest result
  • Root and jailbreak state
  • Emulator state

Session

  • Hooking, debugging and overlay signals
  • Risk level
  • Timestamp and nonce

Frequently asked questions

Which plans include Attest?

Attest is included on Startup, and fully available on Scale and Enterprise.

Does Attest replace Play Integrity or App Attest?

No. It builds on them and adds Moatgator's own runtime signals into a single verdict.

How does my backend verify a verdict?

Verify the signature with our Node.js SDK, or with the Java, Go, Python and .NET SDKs, then read the fields that matter for the action.

What if the attestation service is unreachable?

That is a policy choice. You decide whether a sensitive action fails open or closed when no verdict arrives.

Where does the service run?

In multiple regions, to keep latency low for customers wherever they are.

Ready to protect your app?

Start free, or tell us what you need.