# Codename One App Shield uses server-verified attestation tokens for protected requests

DevFeed: [Codename One App Shield uses server-verified attestation tokens for protected requests](<https://devfeed.tech/articles/app-shield-your-server-should-not-trust-the-app-calling-it-19198.md>)

Original publisher: [Read original article](<https://www.codenameone.com/blog/app-shield-server-attestation/>)

Author: Shai Almog

Published: 2026-08-07T00:00:00Z

Content type: release

Language: en

Sources: [CodeName One](<https://devfeed.tech/sources/codename-one.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [API](<https://devfeed.tech/topics/api.md>), [Back end](<https://devfeed.tech/topics/backend.md>), [Java](<https://devfeed.tech/topics/java.md>), [Android](<https://devfeed.tech/topics/android.md>), [Windows](<https://devfeed.tech/topics/windows.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [backend](<https://devfeed.tech/tags/backend.md>), [google-play](<https://devfeed.tech/tags/google-play.md>), [java](<https://devfeed.tech/tags/java.md>), [release](<https://devfeed.tech/tags/release.md>), [security](<https://devfeed.tech/tags/security.md>), [windows](<https://devfeed.tech/tags/windows.md>)

## AI overview

Codename One App Shield uses Apple App Attest and Google Play Integrity to produce short-lived attestation tokens that a backend can verify before performing sensitive operations. The update also covers OpenType font support, a Maven repository migration, and newer Windows desktop builders.

## Source excerpt

Codename One App Shield turns Apple App Attest and Google Play Integrity into short-lived tokens your backend can verify. This release also adds OpenType fonts, advances the R2 repository migration, and prepares new Windows desktop builders.