To not expose my Google Map API key, it is best to not include the API key in the Android app repo itself. How am I suppose to use Google Map if the API key is not in the app? Storing the API key in a server is the way to go so do I make a network call on app init and request for the API key? After getting the response from server, store the API key in the shared preferences? This is the only way that I could think of but if it is being stored in shared preferences, I believe that the API key can be obtained by reading the values in shared preferences through reverse engineering. Can anyone tell me what is the secure way to use the API key, thank you.