Skip to content

feat: add projectToken and deprecate apiKey - #835

Open
turnipdabeets wants to merge 1 commit into
mainfrom
feat/project-token
Open

turnipdabeets wants to merge 1 commit into
mainfrom
feat/project-token

Conversation

@turnipdabeets

Copy link
Copy Markdown
Contributor

💡 Motivation and Context

Add projectToken to PostHogConfig (core and server) and PostHogAndroidConfig, and deprecate apiKey. This is the Android part of the cross-SDK rename: posthog-ios #573, posthog-flutter #374, posthog-dotnet #183, posthog-kmp #91.

This is a minor release, not a breaking one. The first constructor parameter is renamed apiKey → projectToken. Parameter names are not part of JVM signatures, so the constructors and existing bytecode are unchanged.

Caller code After this PR
PostHogAndroidConfig("phc_...") / new PostHogAndroidConfig("phc_...") Compiles, no warning
PostHogAndroidConfig(projectToken = "phc_...") New form
PostHogAndroidConfig(apiKey = "phc_...", ...) Compiles with a deprecation warning (deprecated Companion.invoke with the same parameters)
config.apiKey / getApiKey() Compiles with a deprecation warning (ReplaceWith("projectToken"))
PostHogConfig.builder("phc_...") (server) Unchanged
Kotlin subclass calling super(apiKey = ...) Breaks. A super call cannot resolve to a factory. Use projectToken = or a positional argument

The same rows apply to core com.posthog.PostHogConfig and server com.posthog.server.PostHogConfig.

  • The deprecated factories are @JvmSynthetic, so Java callers never see them. Java callers never had named arguments anyway.
  • The server builder(apiKey) / Builder(apiKey) parameter names stay the same. Renaming them would break Kotlin named calls such as builder(apiKey = ...), and a deprecated overload would clash with the new one.
  • The deprecation message matches posthog-flutter and kmp: "Deprecated in favor of projectToken. This will be removed in the next major version."
  • The setup and push-registration logs now say "project token". Trimming (fix: trim whitespace from API keys and host config #492), the blank-token no-op setup (fix: no-op setup without api key #503), and invalid-key push handling (fix: stop retrying push registration when the project API key is not valid #790) are unchanged.
  • Storage paths and wire fields (api_key, token) still use the same value, so stored queues and preferences carry over.

External callers checked (origin/main):

  • posthog-flutter: PostHogAndroidConfig(projectToken, host) is positional. No change needed.
  • posthog-js RN plugin: PostHogAndroidConfig(apiKey, host) is positional. No change needed.
  • posthog-kmp: PostHogAndroidConfig(apiKey = ...) and com.posthog.PostHogConfig(apiKey = ...) are named. Both still compile, with a deprecation warning, and switch to projectToken = on the next bump.
  • None of these subclass the config classes.

Docs follow-up: posthog.com still uses apiKey = in contents/docs/libraries/android/index.mdx (lines 58, 181, 217, 269, 365, 380) and contents/docs/integrate/_snippets/install-android.mdx (line 43). Those need a separate posthog.com PR.

💚 How did you test it?

  • Added a test for each config class (deprecated apiKey factory and getter alias projectToken). Each test checks that apiKey = trims into projectToken, that apiKey reads it back, and that the other named arguments are passed through. Existing tests now use projectToken.
  • ./gradlew build :posthog-android-gradle-plugin:build --continue passed: spotlessCheck, apiCheck, lint, and unit tests (posthog 1013, posthog-server 568, posthog-android 1506 with 6 skipped, surveys-compose 75; 0 failures). The only failure was uploadPostHogProguardMappingsRelease in the sample app, because there are no PostHog CLI credentials locally.
  • make testSurveyUI (49 passed), sample assembleDebug, Java and Spring sample builds, checkRelease with no lockfile diff, and sdk_compliance_adapter compile all passed.
  • I compiled a probe file with -Werror and then removed it. It showed deprecation warnings only for apiKey = and .apiKey. Positional and projectToken = calls had no warnings. class X : PostHogAndroidConfig(apiKey = ...) failed to compile, as expected.
  • The .api diff is additive only: getProjectToken() on core and server, plus the synthetic Companion.invoke entries (and a new PostHogAndroidConfig.Companion). getApiKey() and all <init> signatures are unchanged.

📝 Checklist

  • I reviewed the submitted code.
  • I added tests to verify the changes.
  • I updated the docs if needed. (posthog.com follow-up listed above)
  • No breaking change or entry added to the changelog.

If releasing new changes

  • Ran pnpm changeset to generate a changeset file (written by hand: .changeset/project-token-rename.md)

🤖 Generated with Claude Code

@turnipdabeets turnipdabeets self-assigned this Oct 2, 2026
@greptile-apps

greptile-apps Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Retrigger

[Medium risk] Renames apiKey parameter to projectToken across SDK configuration.

The PR appears safe to merge within its explicitly acknowledged compatibility limits.

Reviews (1) · Last reviewed commit: "feat: add projectToken and deprecate api..."

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

posthog-android Compliance Report

Date: 2026-10-03 00:00:04 UTC
Duration: 117841ms

✅ All Tests Passed!

46/46 tests passed


Capture Tests

✅ 29/29 tests passed

View Details
Test Status Duration
Format Validation.Event Has Required Fields ✅ 272ms
Format Validation.Event Has Uuid ✅ 24ms
Format Validation.Event Has Lib Properties ✅ 22ms
Format Validation.Distinct Id Is String ✅ 21ms
Format Validation.Token Is Present ✅ 21ms
Format Validation.Custom Properties Preserved ✅ 22ms
Format Validation.Event Has Timestamp ✅ 19ms
Retry Behavior.Retries On 503 ✅ 7033ms
Retry Behavior.Does Not Retry On 400 ✅ 4022ms
Retry Behavior.Does Not Retry On 401 ✅ 4023ms
Retry Behavior.Respects Retry After Header ✅ 7024ms
Retry Behavior.Implements Backoff ✅ 17019ms
Retry Behavior.Retries On 500 ✅ 7018ms
Retry Behavior.Retries On 502 ✅ 7017ms
Retry Behavior.Retries On 504 ✅ 7019ms
Retry Behavior.Max Retries Respected ✅ 17033ms
Deduplication.Generates Unique Uuids ✅ 26ms
Deduplication.Preserves Uuid On Retry ✅ 7012ms
Deduplication.Preserves Uuid And Timestamp On Retry ✅ 12019ms
Deduplication.Preserves Uuid And Timestamp On Batch Retry ✅ 7015ms
Deduplication.No Duplicate Events In Batch ✅ 26ms
Deduplication.Different Events Have Different Uuids ✅ 17ms
Compression.Sends Gzip When Enabled ✅ 11ms
Batch Format.Uses Proper Batch Structure ✅ 12ms
Batch Format.Flush With No Events Sends Nothing ✅ 7ms
Batch Format.Multiple Events Batched Together ✅ 27ms
Error Handling.Does Not Retry On 403 ✅ 4013ms
Error Handling.Does Not Retry On 413 ✅ 4015ms
Error Handling.Retries On 408 ✅ 5020ms

Feature_Flags Tests

✅ 17/17 tests passed

View Details
Test Status Duration
Request Payload.Request With Person Properties Device Id ✅ 22ms
Request Payload.Flags Request Uses V2 Query Param ✅ 14ms
Request Payload.Flags Request Hits Flags Path Not Decide ✅ 15ms
Request Payload.Flags Request Omits Authorization Header ✅ 16ms
Request Payload.Token In Flags Body Matches Init ✅ 22ms
Request Payload.Groups Round Trip ✅ 16ms
Request Payload.Groups Default To Empty Object ✅ 15ms
Request Payload.Disable Geoip False Propagates As Geoip Disable False ✅ 12ms
Request Payload.Disable Geoip Omitted Defaults To False ✅ 12ms
Request Payload.Flag Keys To Evaluate Contains Only Requested Key ✅ 12ms
Request Lifecycle.No Flags Request On Init Alone ✅ 4ms
Request Lifecycle.No Flags Request On Normal Capture ✅ 12ms
Request Lifecycle.Two Flag Calls Produce Two Remote Requests ✅ 26ms
Request Lifecycle.Mock Response Value Is Returned To Caller ✅ 13ms
Retry Behavior.Retries Flags On 502 ✅ 317ms
Retry Behavior.Retries Flags On 504 ✅ 314ms
Side Effect Events.Get Feature Flag Captures Feature Flag Called Event ✅ 13ms

@turnipdabeets

Copy link
Copy Markdown
Contributor Author

@marandaneto looks like this didn't make it to a few PRs. OK to continue? It seems like parity is useful.

@turnipdabeets
turnipdabeets marked this pull request as ready for review October 3, 2026 01:42
@turnipdabeets
turnipdabeets requested a review from a team as a code owner October 3, 2026 01:42

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant