Skip to content

Configuration

The SDK is configured by a JSON file in your app’s assets/ folder. There is no builder API — the file is the single source of local configuration.

app/src/main/assets/cimka_config.json
{
"validation": {
"licenseKey": "XXXX-XXXX-XXXX-XXXX",
"apiKey": "cmk_your_derived_key_here",
"applicationId": "your-app-id-here",
"baseUrl": "https://your-cimka-backend/api/v1"
},
"clickLogger": { "maskSensitiveInputs": true },
"deviceAudit": { "enabled": true }
}

To use a different file name, pass it to initialize:

Cimka.initialize(this, configFileName = "cimka_config_staging.json")

All four fields are required.

Key Type Description
licenseKey String Secret used to sign every SDK request (HMAC-SHA256). It is never sent over the network.
apiKey String Your application’s API key, sent as the cimkaApiKey header.
applicationId String Your application id, sent as the cimkaAppId header.
baseUrl String Cimka API root, e.g. https://api.example.com/api/v1. A trailing / is trimmed.

You get all three credentials when you create an application in the dashboard.

Key Type Default Description
maskSensitiveInputs Boolean true When true, taps on EditText fields are logged with text *** instead of the field content (XML module).

The batchSize, batchIntervalMillis, maxDiskQueueSize, retryMaxAttempts, retryBaseDelayMillis and enabled fields are accepted but reserved — they currently have no effect.

enabled, detectRoot, detectSimulator, detectCorrupted and sendToBackend are accepted but reserved. Device audit is currently controlled from the dashboard (see below).

Cimka.initialize() returns immediately; most of the work happens on a background thread.

  1. The config file is read. If it is missing or malformed, initialization fails and the SDK stays silent (an error is printed to Logcat in debug builds).
  2. License check — GET /sdk/v1/health/check with a 15 s timeout. If it fails, the SDK stays disabled for this process.
  3. Remote config — GET /sdk/v1/config/check. Returns which log types are enabled and whether the device is blocked.
  4. Once ready, the SDK starts the session observer, installs the crash handler, runs the device audit, uploads the dependency list, loads masked properties, and replays any offline logs.

Each application has remote settings, managed in the dashboard, that the SDK fetches at init, every time the app returns to the foreground, and every 2 minutes while it stays in the foreground.

Setting Effect
isSdkEnabled Master kill switch for the SDK.
logConfig.click / screen / crash / network / trace / lifecycle / session / deviceAudit / dependencies Turn individual log types on or off.
blocked + reason Shows a full-screen blocked screen on this device (see Device gate).
Masked properties Header names and JSON keys to replace with [MASKED] in network logs.

All remote settings fail open: if the backend can’t be reached, the SDK stays enabled with every log type on.