The common Android scheme
MediaDrm issues a key request for a licence; the request is the part you can read and reproduce for integration.
Capabilities · DRM & Media
We trace the manifest, entitlement, playback-token and license request flow, then rebuild the callable network path around Media3 and MediaDrm.
GET /manifest.mpd (content + keys) MediaDrm.generateKeyRequest(session) POST /license (signed request) MediaDrm.provideKeyResponse(session, resp) play
The playback context
ExoPlayer and Media3 are the network and playback layer. They fetch the manifest, hand the DRM system a request, and pipe the response back. They are not the protection. That is why tracing them is useful: they name the API calls you want.
How the app asks for content metadata, and what headers or token it sends.
The MediaDrm instance, the scheme, and the request it generates for a license.
The check that decides whether the account may play, and the token that proves it.
The request is the subject. The protection stays where it is.
The request family
Schemes
MediaDrm issues a key request for a licence; the request is the part you can read and reproduce for integration.
ClearKey uses a defined key format without proprietary key wrapping. The keys still come from the content owner or license service.
The request and response flow sits behind the same MediaDrm interface.
Trace it
// the app asks MediaDrm for the bytes to send drm = MediaDrm(UUID.fromString(scheme)) session = drm.openSession() request = drm.getKeyRequest( session, init_data, media_type, KEY_TYPE_STREAMING) // the request body goes to the license endpoint response = client.post(LICENSE_URL, request.data, auth) drm.provideKeyResponse(session, response)
Fig. 01 · the request the app sends, kept inside the platform call
The entitlement that precedes the license is often the harder part. We map the account state, playback token and request headers so the call reaches the server in the same shape as the app.
Project
Manifest, license, entitlement, playback-token and request-header flows.
MediaDrm keeps the device-side key session. We reconstruct the server-facing request chain around it.
Send us the app
Send the app, the title you tested and the playback error. We trace the request chain and quote the exact reconstruction.
Projects start at $120. Most are delivered in 24 to 72 hours.
Python, JavaScript/TypeScript, Postman and complete API documentation cover the same full endpoint set. Your team runs the clients in its own server or system.
The delivery window starts after we receive the APK and any account access needed to run it. The fixed quote states the deadline. Most projects finish sooner.
The package includes signing, encryption, decryption and session handling. We verify device-bound keys and server integrity checks during review and document runtime requirements before you commit.
Report a defect within 30 days of delivery. We fix any delivered call that does not match the tested APK at no extra cost.