Test with mobile
Use mobile when a person needs to review, approve, or sign something produced by a Gora app.Test against the live testnet
The iOS and Android apps ship preconfigured with the live bridge:mobile_signing_request, the node publishes it to the live bridge with POST /mobile/signing-requests. The mobile app reads the same inbox through GET /mobile/signing-requests and shows the pending request for review and signing.
Quick checks against the live bridge:
Neither flow gives Gora the user’s private key.
When to use mobile
Use mobile for:- transfers
- wallet actions
- smart-wallet approvals
- gateway fulfillment signatures
- any result that moves value or changes chain state
App output shape
A mobile-signing app can return:Local Dev Bridge (secondary path)
Use this only when you run your own local devnet instead of the live testnet. During development, a bridge service may expose pending actions to the mobile app.gora devnet up starts the bridge by default and exposes it through your public tunnel (ngrok, Caddy, or any HTTPS tunnel works):
gora node serve manually, configure a signing-request sink with:
What users should review
Mobile should show:- app name and app id
- chain
- sender
- recipient
- amount and unit
- policy or package hash
- attestation/result hash when available
- risk notes
Dev keys
For local devnet tests, import only dev-only keys:- Base hex private key
- Solana JSON/base58/base64/hex keypair
- Algorand 25-word mnemonic or raw key format
After approval or signing
After mobile signs, the signed response still needs to be submitted or fulfilled. Common submission modes:
Your contract or gateway should still verify:
- Gora result or attestation
- app id
- output hash
- user signature
- policy limits
- replay protection
Quick test flow (live testnet)
Only Algorand is live on the public testnet today, so use--chain algorand: