I am trying to setup Firebase AppCheck for my flutter app .
I am calling activate in my app code
await FirebaseAppCheck.instance.activate(
webProvider: ReCaptchaV3Provider('recaptcha-v3-site-key'),
androidProvider: AndroidProvider.playIntegrity,
appleProvider: AppleProvider.appAttestWithDeviceCheckFallback,
);
Also I have added sha-256 key to my firebase console App Check section from Play Console so correct key is added.
Play Console is linked to correct Google Cloud account.
I have uploaded app bundle to play console and submitted to internal testing and download to android device, I see this error:
>Error returned from API. code: 403 body: App attestation failed.
Looks like I have tried every variant and got same error. What it can be?
This is almost always a SHA-256 certificate mismatch between what's registered in Firebase App Check and what's actually signing your release build — especially if you're using Play App Signing (which is the default for new apps on Play Console).
Here's the key detail: when you upload your app bundle, Google re-signs it with its own key before distributing to devices. So the SHA-256 you need in Firebase App Check isn't your local upload certificate, it's the App signing certificate.
Steps to verify:
Go to Play Console → your app → Setup → App integrity (or App signing in older UI)
Copy the SHA-256 under App signing key certificate (not "Upload key certificate")
Go to Firebase Console → Project Settings → App Check → your Android app → add/verify this exact SHA-256
Also double-check in Google Cloud Console that the Play Integrity API is enabled for your project (App Check setup usually does this, but worth confirming manually)
Also common: since you're testing via Internal Testing track, Play Integrity attestation can take some time to propagate after first upload — I've seen it take anywhere from 15 minutes to a few hours before release builds start passing reliably, even with correct SHA-256 configured. If your debug token route worked immediately but release still fails right after upload, give it some time before assuming it's a config issue.
One more thing to check in your Flutter setup specifically: make sure you're not accidentally still using a debug App Check provider flavor for your release build — double check your build.gradle / flavor config doesn't override AndroidProvider.playIntegrity with AndroidProvider.debug in release.
shehrozdev