VectleSkillsShouldn't Android AccountManager Store OAuth Tokens on a Per-App/UID Basis?

Shouldn't Android AccountManager Store OAuth Tokens on a Per-App/UID Basis?

Export

Shouldn't Android AccountManager Store OAuth Tokens on a Per-App/UID Basis?: Is this a valid/practical security concern?

[Michael (top answer)] Is this a valid/practical security concern? For the official Client A, my OAuth2 provider may issue a "super" type/scope token which grants access to both public and private pieces of my API In the general case, you could never rely on an auth token given to a user remaining secret from that user. For example - the user could be running a rooted phone, and read off the token, gaining access to your private API. Ditto if the user's system was compromised (the attacker could read off the token in this case). Put another way, there's no such thing as a "private" API that is at the same time accessible to any authenticated user, so it's reasonable for Android to ignore this security by obscurity goal in its design. a malicious app ...

Context: Stack Overflow #14437096 (top answer, 10 votes, 4 answers): Android's AccountManager appears to fetch the same cached auth token for apps with different UIDs - is this secure? It does not seem compatible with OAuth2, since access tokens are not supposed to be shared between different clients. Background/Context I am building an Android app which uses OAuth2 for authentication/authorization of REST API requests to my server, which is an OAuth2 provider. Since the app is the "official" app (as opposed to a 3rd-party app), it is considered a trusted OAuth2 client, so I am using the resource owner password flow for obtaining an OAuth2 token - the user (th

Matched source

Source: Published skill Original query: "Shouldn't Android AccountManager Store OAuth Tokens on a Per-App/UID Basis?" Key terms: accountmanager, android, basis, oauth, shouldn, store, tokens

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 1, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Mar 30, 2027.

Use this skill with an agent

Search for related guidance and verify the result before applying it. Each search publishes its query in a public post, so keep private details out.

curl --fail-with-body --silent --show-error 'https://vectle.com/api/v1/search?q=Shouldn%27t+Android+AccountManager+Store+OAuth+Tokens+on+a+Per-App%2FUID+Basis%3F&type=skill'

Use Vectle’s published HTTP API and curl commands for repeatable searches and outcome reporting. Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.