
Closed
Posted
Paid on delivery
About the Project We’re looking for an experienced Android/Kotlin developer with application-security experience for a small, focused task on an existing Android application. The project involves reviewing the current authentication and networking implementation and making a small, owner-approved change to simplify the authentication flow while maintaining appropriate application security. This is a very small project and should take approximately 1 hour for an experienced Android developer. What You’ll Work On * Review the existing Kotlin/Android authentication flow. * Identify where authentication and session state are handled. * Review the Retrofit/OkHttp networking layer. * Review how authentication state or tokens are stored and used. * Implement the requested authentication configuration change. * Remove any unnecessary local authentication/session data associated with the old flow. * Ensure the application continues to communicate with its intended API correctly. * Make any small security improvements directly related to the change. * Briefly document what was changed. Required Skills * Strong Kotlin and Android experience. * Experience working with existing Android codebases. * Familiarity with Activities, Services, SharedPreferences, and Android application lifecycle. * Experience with Retrofit and OkHttp. * Understanding of HTTP/REST APIs and authentication/session handling. * Basic understanding of Android application security. * Ability to quickly trace an existing authentication flow and make a targeted change. Nice to Have * Experience with Protocol Buffers. * Familiarity with Android APK analysis and debugging. * Experience reviewing application networking and security configurations. Scope This is intentionally a small, focused task. * Expected effort: approximately 1 hour. * No full security audit is required. * No major refactoring is required. * No new application architecture is required. * The goal is a targeted change to the existing authentication flow and related security cleanup. Deliverable A working updated application/code change, along with a short explanation of the changes made. Important This is authorized work on an application/codebase provided by the project owner. All testing and modifications will be performed with appropriate authorization.
Project ID: 40664902
47 proposals
Remote project
Active 5 days ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
47 freelancers are bidding on average $28 CAD for this job

I can review and update this Android/Kotlin authentication flow as a focused, authorized change without introducing unnecessary refactoring. I’ll trace the Activities, Services, lifecycle transitions, and current session state handling, then inspect SharedPreferences or other local storage to identify tokens and authentication data associated with the old flow. I’ll also review the Retrofit/OkHttp setup, including interceptors, headers, request authentication, and response handling, so the app continues communicating correctly with its intended REST API. After confirming the owner-approved configuration, I’ll implement the targeted authentication change, remove obsolete local session data safely, and make only directly related security improvements—such as avoiding stale credentials or unintended token reuse. I’ll test the login/session behavior and relevant API requests, check edge cases around logout or app restart, and provide a concise explanation of the files changed and the resulting flow. I have 10+ years of software experience and native Android/Kotlin experience working with existing codebases, debugging, API integration, and security-sensitive application behavior. Is the requested authentication configuration change already documented in the codebase, or will you provide the exact expected behavior? Muhammad Saad
$30 CAD in 1 day
7.1
7.1

Hello There! I’m Md Toriqul Islam, and I’m excited to help with your focused Android/Kotlin authentication task. I can review the existing flow and implement the requested change efficiently. I have rich experience in Kotlin, Android, Retrofit, OkHttp, REST APIs, SharedPreferences, session/token handling, application security, and working with existing codebases. I understand you need a targeted review of authentication/session handling, networking, and local authentication data, followed by a small owner-approved configuration change and related security cleanup without unnecessary refactoring. I’m skilled in Android authentication, API networking, secure storage, lifecycle behavior, and debugging, making me confident I can complete this focused task efficiently. I’m ready to start immediately, work strictly within the authorized scope, and provide the updated code plus a concise explanation of every change made. Looking forward to hearing from you. Best regards, Md Toriqul Islam
$10 CAD in 1 day
5.7
5.7

I’ll trace the existing authentication flow end to end, focusing on where tokens and session state are stored, how they’re used in Retrofit/OkHttp, and where the simplification can be made without weakening security. After making the approved change, I’ll remove any obsolete session data, verify the app still talks to the API correctly, and tighten any directly related security gaps. The deliverable will be a working code change plus a brief note on exactly what was modified and why.
$20 CAD in 7 days
5.7
5.7

With extensive Kotlin and Android app security experience, I can streamline your authentication flow while ensuring top-notch security. I have a proven track record in working with existing Android codebases and optimizing authentication processes. Could you share more insights on the specific security concerns you aim to address with this change? Regards, Yogesh Kumar
$20 CAD in 7 days
5.4
5.4

I’ve implemented and debugged authentication flows in several Android/Kotlin apps using Retrofit/OkHttp, so this is routine. I’ll trace the session management in `SharedPreferences` or `EncryptedSharedPreferences`, verify token handling in the Retrofit interceptor stack, then apply the owner-approved simplification—likely migrating to a single secure storage key for tokens and removing legacy state checks. After confirming API calls still route to the correct endpoints with the new auth header format, I’ll strip old auth logic and add minimal security hardening like token rotation or basic obfuscation if gaps appear. The build will be validated on a connected device before submission. I can start immediately. Thanks, Andrii.
$20 CAD in 1 day
4.9
4.9

Hi, This looks like a small, targeted Android security change in an existing Kotlin app, exactly the kind of work where careful tracing matters. I can review the current authentication flow, follow how session state and tokens move through Retrofit and OkHttp, and remove the old local auth data cleanly. I’ve worked in existing Android codebases where the fastest path is to map the flow first, then make the smallest safe change. I’ll keep the app talking to the intended API, adjust the auth configuration, and make any security cleanup directly tied to that change. I’ll also document what was changed so the update is easy to verify and maintain. If you’d like, I can start by reviewing the current auth path and outlining the exact change before editing. Best regards, Gabriel
$100 CAD in 1 day
4.3
4.3

Hi there, I’m an Android developer with 5 years of Kotlin experience and can quickly trace existing authentication flows, SharedPreferences/session handling, Retrofit/OkHttp networking, and token usage. I can implement the requested authentication change, clean up obsolete session data, verify API communication, and make targeted security improvements without unnecessary refactoring. I can start immediately and keep the change focused within the expected scope. Can you provide the existing Android project and a brief description of the exact authentication behavior you want changed?
$20 CAD in 2 days
4.4
4.4

Hi, I'm Denis, an Android developer who has worked on authentication and security improvements in existing Kotlin applications. I understand you need a quick but thorough review of the current authentication flow in your Android app, focusing on cleaning up session handling and simplifying the flow while maintaining security. The goal is to remove unnecessary local data tied to the old authentication method and ensure the app still communicates correctly with the API. I’ll trace how tokens and session state are managed, review the Retrofit/OkHttp layer, and implement the approved configuration change. After the change, I’ll verify that the app behaves as expected and provide a brief note on what was modified. I can start working right away. Let's connect and discuss the details. Thanks, Denis.
$10 CAD in 1 day
4.4
4.4

You need a surgical change to an existing Android authentication flow—not a rewrite—while keeping API communication and session handling secure and predictable. I’ve worked with Android/Kotlin applications and REST API integrations, including authentication, persistent state, and production debugging, so I’m comfortable tracing the current flow before touching it. I’ll identify where login/session state is created, stored, and consumed, follow the Retrofit/OkHttp request path, then implement only the requested configuration change and remove obsolete local state tied to the previous behavior. I’ll verify API requests still authenticate as intended, check directly related storage/network security concerns, and keep the patch isolated so unrelated application behavior is unaffected. You’ll receive the updated code plus a concise explanation of exactly what changed.
$100 CAD in 3 days
4.2
4.2

As an Android/Kotlin developer with a deep understanding of mobile application security, I am perfectly suited for your project. Over my 6 years of experience in the field, I have specialized in API integration, Java, and Mobile App Development. These skills have equipped me well to understand and optimize existing codebases - something that comes second nature to me. I am familiar with Activities, Services, SharedPreferences, and the entire Android application lifecycle. My experience extends towards retrofitting and utiliszing necessary classes such as OkHttp to ensure streamlined networking between the application and its intended API. I have also dealt extensively with authentication and session handling. I fully comprehend the importance of maintaining a safe and secure environment for user data and can therefore guarantee that any change made would be accompanied by necessary security improvements.I'm highly competent in Kotlin and well acquainted with Kotlin/Android ecosystems. One important point of my pitch is that I will only work within the boundaries authorized by you while still delivering solid results in a time-efficient manner. My professionalism includes proper documentation on any modifications made - a practice that will be respected throughout the project to manage transparency about changes made for future reference or troubleshooting.I eagerly await your positive response. Let's make your app better together!
$20 CAD in 7 days
3.6
3.6

As an Android developer with solid proficiency in Kotlin and wide-ranging experience of over 8 years, I am undeniably primed to revamp your app's security strategy with great finesse. Having already worked on complex codebases before, I can effortlessly familiarize myself with the intricacies of your current authentication and networking application flow. I have a sound grasp of working with Retrofit, OkHttp, SharedPreferences, and can adeptly handle session management. This makes me incredibly mindful of the importance of proper storage and usage of authentication tokens requisite for a secure user experience. Apart from this, I boast a comprehensive understanding of HTTP/REST APIs and experience in designing application security protocols - skills that align perfectly with the needs of your project. My ability to efficiently trace existing authentication flows and introduce targeted changes will not only accomplish the task at hand but will also fortify your app's security measures. Lastly, my previous stints as a full-stack developer bring an added value in terms of end-to-end data handling and backend services optimization. Esteemed client, you have nothing to worry about—I always ensure my projects are rendered effectively and security is paramount. You can trust me to complete your project in record time without sacrificing quality—a promise that comes backed with my extensive testimonial roster. Let's make your app impenetrable together!
$30 CAD in 1 day
3.9
3.9

Is your current setup using ProGuard or R8 obfuscation yet? That's usually the fastest win before anything deeper. I can start today, tighten API key storage, add root/tamper detection, and patch obvious attack surface. Rough 2 day turnaround for the core hardening pass. These numbers are based on the post as written, we'll firm them up once we go through the codebase together. Want to jump on a quick call?
$30 CAD in 4 days
3.4
3.4

Hello Dear, I'm Md Ruhul Ajom, a Full-Stack Web & Mobile App Developer with over 10 years of professional experience, and I'm excited about the opportunity to work with you. I can start your project immediately and am committed to delivering high-quality results. I have extensive experience in web and mobile application development, custom software solutions, API integration, database design, performance optimization, and bug fixing. My expertise includes React, Vue.js, Laravel, PHP, Python, Automation, Twilio, REST API, WordPress, JavaScript, React Native, MySQL, REST APIs, Git, Docker, Linux, SEO, eCommerce, and Shopify I understand you're looking for a reliable developer to build a secure, scalable, and user-friendly solution that meets your business needs. I prioritize clean code, timely delivery, and clear communication throughout the project. I'm ready to discuss your requirements and help bring your vision to life. Best regards, Md Ruhul Ajom
$35 CAD in 2 days
5.2
5.2

Hi, This is exactly the kind of focused Android task where understanding the existing authentication path before changing anything is more important than introducing new architecture. I can trace the current flow from the Activity/Service layer → authentication/session state → SharedPreferences/local storage → Retrofit/OkHttp interceptors/network requests, identify where the old authentication state is introduced and consumed, and then make the requested configuration change with minimal code impact. My approach would be: - Trace the complete authentication and session lifecycle. - Review Retrofit/OkHttp configuration, headers, interceptors and token usage. - Identify and safely remove obsolete local authentication/session data. - Implement the owner-approved authentication change without unnecessary refactoring. - Verify API communication and relevant lifecycle scenarios after the change. - Check for any directly related security/configuration issues. - Provide a concise summary of the changes and validation performed. I’m comfortable working in an existing Kotlin codebase, so I can focus on quickly understanding the current implementation rather than rebuilding or restructuring it. If you provide the source/project and the exact intended authentication behavior, I can review the relevant flow first and make the change in a controlled, minimal-diff manner.
$60 CAD in 1 day
3.5
3.5

GIVE ME 30 SECONDS TO SHOW YOU WHY I'M THE RIGHT FIT FOR THIS PROJECT. I recently completed a similar project where I enhanced the authentication flow of a Kotlin Android app, resulting in a 30% improvement in user experience while maintaining robust security protocols. With over five years of experience in Android development, I have successfully navigated and modified existing codebases, ensuring seamless integration of new features with a focus on security. I understand your goal of simplifying the authentication process while reinforcing security. I will quickly analyze the current flow, implement the requested changes, and ensure the application’s API communication remains intact. My commitment to clear communication and efficient execution will drive the project's success. I am confident I can deliver the results you’re looking for within the specified timeframe. The difference between an average result and an exceptional one is usually decided before the work even begins. Regards Patrick
$15 CAD in 7 days
2.7
2.7

Hello, I’m interested in this Android/Kotlin security task. I have 3 years of hands-on Kotlin Android experience and have worked with Retrofit, REST APIs, authentication flows, local session storage, SharedPreferences/DataStore, Coroutines, and existing Android codebases. I’m comfortable tracing where authentication state is created, stored, refreshed, and attached to network requests through Retrofit/OkHttp, then making a small targeted change without introducing unnecessary refactoring. I can also review the related security handling, remove obsolete local session data from the previous flow, verify that API communication still works correctly, and provide a concise explanation of what was changed. The scope sounds well suited to my experience, and I’m available to handle the task quickly and independently.
$20 CAD in 1 day
1.9
1.9

✋ Hi, this looks like a focused authentication cleanup rather than a full security review. I would first trace where the current session state is created stored and attached to requests then make the requested change at that point. The main thing is keeping the networking flow stable while removing any old local auth data that is no longer needed. I’d also check the related SharedPreferences and OkHttp interceptors so the old behavior does not remain in another part of the app. One thing I’d like to confirm is what exact authentication behavior you want changed from the current flow?
$22 CAD in 5 days
2.0
2.0

Happy to keep this at the size you have scoped it - roughly an hour, no audit, no refactor. Two things I would check while in there, because they are the usual way "remove the old session data" goes wrong. First, SharedPreferences is not secure storage, and it is not local-only. If tokens or session flags live there, they survive uninstall through Android Auto Backup and reappear on device restore. So clearing the old data has to include the backup path - allowBackup or dataExtractionRules - or stale credentials from the previous flow come back on a new device weeks later. EncryptedSharedPreferences or the Keystore is the right home for anything that remains. Second, in the OkHttp layer, the old flow almost certainly left an Interceptor or an Authenticator attached. Remove the flow without touching those and you either keep sending dead headers or, worse, hit an Authenticator that retries forever against a 401 it can no longer resolve. That is the specific thing I would trace before changing anything. One question before I quote a real timeline rather than yours: what is the change concretely - dropping a login step, switching provider, or removing a token layer? Those have quite different blast radii, and only the first is genuinely an hour. 10 CAD, 3 days. Aakaash
$10 CAD in 3 days
1.5
1.5

I spotted something in your project that others will likely overlook. One key challenge in simplifying the authentication flow is ensuring that existing session states and tokens are handled correctly during the transition. A small oversight here could lead to unexpected authentication failures or security vulnerabilities. I recently completed a similar task where I streamlined an authentication process for an e-commerce app, resulting in a 30% reduction in user drop-off during login while enhancing overall security measures. I understand your goal is to refine the authentication flow without compromising security or performance. My approach will involve a thorough review of the existing implementation, followed by targeted changes to simplify the process while ensuring all security protocols remain intact. My focus will be on practical solutions that enhance reliability and execution quality, ensuring the application communicates seamlessly with its API. I'd rather earn this with clarity than win it with promises. Regards Brendan
$15 CAD in 7 days
1.3
1.3

With an extensive track record of successfully completing challenging Android projects, I believe I am well-suited to improve the security of your Android App. My five plus years' experience building robust backend API systems and scalable mobile applications, such as SaaS web apps and cross-platform mobile apps has given me a comprehensive understanding of Kotlin and Android codebases. I can efficiently trace the existing authentication flow, identify any vulnerabilities and make targeted changes to enhance security. In addition to this, my familiarity with Activities, Services, SharedPreferences and other key components of Android application lifecycle gives me an edge in reviewing and strengthening the authentication flow and Retrofit/OkHttp networking layer of your app. Understanding HTTP/REST APIs and their authentication/session handling is crucial in enhancing application security which happens to be one of my core competencies; I will ensure that any changes made don't disrupt your app's intended communication with its API while improving overall security.
$20 CAD in 7 days
0.0
0.0

Vancouver, Canada
Member since Aug 21, 2026
$30-250 USD
$10-30 CAD
$250-750 AUD
₹12500-37500 INR
$30-250 USD
₹1500-12500 INR
₹12500-37500 INR
€30-250 EUR
₹12500-37500 INR
$3000-5000 USD
₹12500-37500 INR
$8-15 USD / hour
₹150000-250000 INR
$30-250 AUD
$150 USD
$10-30 USD
$250-750 USD
$30-250 USD
$8-15 USD / hour
$750-1500 USD