
Security News
Insecure Agents Podcast: How to Keep AI Agents From Bypassing Security Controls
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.
@limrun/play-auth
Advanced tools
Browser Google authentication and Google Play publishing primitives for Limrun.
Headless building blocks for publishing an AAB asset from the Limrun
registry to Google Play, with a browser-owned Google sign-in. No UI ships
here; embedders render their own buttons and dialogs around the hook,
same as device-install.
The Google access token is minted in the browser via Google Identity Services (token model, no client secret) and sent to the registry once per publish. Limrun never stores it.
import { usePlaystorePublish } from '@limrun/play-auth/react';
const play = usePlaystorePublish({
registryApiUrl: 'https://registry.limrun.com',
token: limrunToken,
organizationId: organizationTid,
googleClientId: GOOGLE_OAUTH_CLIENT_ID,
});
// On dialog open, warm the sign-in script so the click stays popup-safe.
// Optionally await the returned promise (true = ready) to gate the button:
play.preloadGoogle();
// Button handlers:
await play.signInWithGoogle();
await play.publish({ assetName: 'app-release.aab', packageName: 'com.example.app' });
// Render from state: play.status, play.versionCode, play.error, play.errorCode
errorCode carries the registry's machine-readable error code; the
canonical value list lives on PlaystorePublishError's doc comment and
grows additively.
Google access tokens expire after about an hour. A permissionDenied
error long after sign-in usually means the token expired; offer "Sign in
with Google" again rather than pointing users at Play Console
permissions.
import { requestGoogleAccessToken, publishToPlaystore } from '@limrun/play-auth';
const accessToken = await requestGoogleAccessToken({ clientId: GOOGLE_OAUTH_CLIENT_ID });
const { versionCode } = await publishToPlaystore({
registryApiUrl,
token,
organizationId,
accessToken,
assetName: 'app-release.aab',
packageName: 'com.example.app',
});
FAQs
Browser Google authentication and Google Play publishing primitives for Limrun.
The npm package @limrun/play-auth receives a total of 30 weekly downloads. As such, @limrun/play-auth popularity was classified as not popular.
We found that @limrun/play-auth demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 4 open source maintainers collaborating on the project.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.