Hacker News new | past | comments | ask | show | jobs | submit
What does client assertion mean here? I don't see any mention in the GitHub issue.
It means that the request to the API contains cryptographic proof that is was generated by a legitimate, reviewed app running on a unmodified and non-rooted mobile device controlled by Apple or Google.
loading story #48320935