AndroidGoogleSignIn

constructor(activityContext: Context, config: GoogleSignInConfig = GoogleSignInConfig(), credentialManager: CredentialManager = CredentialManager.create(activityContext), nonceSource: () -> String = { newRawNonce() })(source)

Parameters

activityContext

must be an Activity, not the application context. Below Android 14 the bottom sheet is hosted by the calling Activity, and an application context throws at runtime rather than at compile time. Keeping the parameter typed as Context matches the platform signature; the requirement is real regardless.

The nonce

Only sha256(rawNonce) is sent to Google; the raw value comes back in SocialIdentity.rawNonce for the server to compare against the ID token's nonce claim. Sending the raw nonce in both places would defeat the point — anyone who intercepts the token would also hold the value that proves it fresh.

Why the retry exists

A filtered request (filterByAuthorizedAccounts = true) is the quiet returning-user path, but it throws NoCredentialException for every user who has never signed in to this app — i.e. all of them, on day one. GoogleSignInConfig.signUpFallback retries once unfiltered so the button works for new users. Skipping that is a "sign-in is broken" bug report that reproduces only on a fresh install.