[] Phone Auth `auth/app-not-authorized` — "play_integrity_token passed, but no matching SHA-256" on Play-signed build, despite correct SHA registration

Author: Younes91codingCreated Aug 8, 2026Updated Aug 31, 2026
Labelstype: bugWorkflow: Waiting for User Responseplugin: app-checkStale

Issue

signInWithPhoneNumber fails on the Play-distributed Android build (installed from Play internal testing) with:

[auth/app-not-authorized] This app is not authorized to use Firebase
Authentication... A play_integrity_token was passed, but no matching SHA-256 was
registered in the Firebase console. Please make sure that this application's
packageName/SHA256 pair is registered in the Firebase Console.

Firebase test phone numbers work (they bypass Play Integrity), so the failure is isolated to Play Integrity token verification for real numbers.

Environment

  • @react-native-firebase/app + /auth 20.5.0
  • Expo SDK 51, React Native 0.74, expo-build-properties targetSdk 35
  • Managed/EAS build (google-services.json via expo.android.googleServicesFile)
  • Android package app.dingdrop.mobile, Play App Signing enabled

Everything verified correct

  • App-signing key SHA-256 (from Play Console → App signing) and SHA-1, plus the upload key SHA-256/SHA-1, are all registered on the Firebase Android app (confirmed in Project settings). App-signing SHA-256 matches Play Console exactly.
  • google-services.json is current and matches app ID / package / project number / api_key.
  • Play Integrity API enabled; the Android API key's API restrictions include Play Integrity API + Identity Toolkit API.
  • Play Console → App integrity → Integrity API Cloud project linked to the Firebase project (582947107702).
  • Clean, Play-only install (all sideloaded builds uninstalled).
  • Several days elapsed (well past SHA propagation).

Question

With all of the above verified, why does the SHA-256 inside the play_integrity_token not match the registered app-signing SHA-256? Is this a known Play Integrity ↔ Firebase decryption/propagation issue, and is there a fix or workaround for real-number phone sign-in on the Play build?

Repro

  1. Configure phone auth per docs (SHA-256 + Play Integrity API).
  2. Install the Play-signed build from an internal-testing track.
  3. Call signInWithPhoneNumber(auth, '+<realNumber>') → the error above. (A configured Firebase test number succeeds.)

Source: invertase/react-native-firebase