<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Policy clarification for a noncommercial Android playback-queue companion in Spotify for Developers</title>
    <link>https://community.spotify.com/t5/Spotify-for-Developers/Policy-clarification-for-a-noncommercial-Android-playback-queue/m-p/7532625#M21893</link>
    <description>&lt;P&gt;Hello Spotify for Developers team,&lt;/P&gt;&lt;P&gt;I am developing Attacca, a small, noncommercial Android companion for Spotify.&lt;/P&gt;&lt;P&gt;Attacca does not play, download, modify, or redistribute audio. While the user is listening in the official Spotify app with shuffle enabled, Attacca monitors the user-authorized current playback. If a track selected by the user begins playing, Attacca uses the Spotify Web API to add one user-selected follow-up track to that user’s playback queue.&lt;/P&gt;&lt;P&gt;Technical details:&lt;/P&gt;&lt;P&gt;- Android application&lt;BR /&gt;- Authorization Code flow with PKCE&lt;BR /&gt;- No client secret&lt;BR /&gt;- No Attacca server&lt;BR /&gt;- No advertising, analytics, tracking, or monetization&lt;BR /&gt;- Spotify tokens encrypted locally with Android Keystore&lt;BR /&gt;- User-created track-pair rules stored only on the phone&lt;BR /&gt;- Monitoring is explicitly started by the user and shown with an ongoing Android notification&lt;BR /&gt;- Intended only for personal Spotify Premium accounts&lt;BR /&gt;- Requested scopes:&lt;BR /&gt;- user-read-currently-playing&lt;BR /&gt;- user-read-playback-state&lt;BR /&gt;- user-modify-playback-state&lt;BR /&gt;- user-read-private&lt;/P&gt;&lt;P&gt;I would like to comply with the Spotify Developer Terms and Developer Policy before distributing Attacca beyond my own phone.&lt;/P&gt;&lt;P&gt;The Developer Policy says that an SDA must use one Security Code and may not use more than one Security Code per SDA. I found Spotify’s February 2026 forum response acknowledging an existing application in which users bring credentials from their own Development Mode apps, but that response addressed endpoint changes rather than whether this access model complies with the Security Code policy or permits public distribution. I would appreciate clarification on the following:&lt;/P&gt;&lt;P&gt;1. May each Attacca user register their own personal Development Mode app in the Spotify Developer Dashboard and enter that app’s client ID into their local Attacca installation?&lt;/P&gt;&lt;P&gt;2. Would doing that be considered using multiple Security Codes for the same SDA, even though each client ID belongs to a different user’s personal developer account and installation?&lt;/P&gt;&lt;P&gt;3. If that model is not permitted, is the compliant Development Mode model one Attacca client ID with no more than five allowlisted users?&lt;/P&gt;&lt;P&gt;4. May the Attacca APK and source code be publicly available through GitHub or an open-source Android repository if the working application remains limited to the users permitted by Development Mode?&lt;/P&gt;&lt;P&gt;5. Alternatively, may another developer fork the open-source project, register it as their own separately named SDA, and use their own client ID for personal, noncommercial use?&lt;/P&gt;&lt;P&gt;6. Because Attacca sends a request to add an item to the user’s Spotify playback queue, should Attacca be treated as a Streaming SDA under the Developer Terms, even though all playback occurs in the official Spotify application?&lt;/P&gt;&lt;P&gt;I am not requesting Extended Quota Mode at this time. I am trying to determine whether there is a policy-compliant path for personal use, a small closed beta, and potentially a publicly available but noncommercial open-source application.&lt;/P&gt;&lt;P&gt;Please identify whether the answer represents Spotify’s official policy interpretation, since I need to rely on it when deciding whether Attacca can be distributed.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Sun, 16 Aug 2026 15:18:49 GMT</pubDate>
    <dc:creator>bewye</dc:creator>
    <dc:date>2026-08-16T15:18:49Z</dc:date>
    <item>
      <title>Policy clarification for a noncommercial Android playback-queue companion</title>
      <link>https://community.spotify.com/t5/Spotify-for-Developers/Policy-clarification-for-a-noncommercial-Android-playback-queue/m-p/7532625#M21893</link>
      <description>&lt;P&gt;Hello Spotify for Developers team,&lt;/P&gt;&lt;P&gt;I am developing Attacca, a small, noncommercial Android companion for Spotify.&lt;/P&gt;&lt;P&gt;Attacca does not play, download, modify, or redistribute audio. While the user is listening in the official Spotify app with shuffle enabled, Attacca monitors the user-authorized current playback. If a track selected by the user begins playing, Attacca uses the Spotify Web API to add one user-selected follow-up track to that user’s playback queue.&lt;/P&gt;&lt;P&gt;Technical details:&lt;/P&gt;&lt;P&gt;- Android application&lt;BR /&gt;- Authorization Code flow with PKCE&lt;BR /&gt;- No client secret&lt;BR /&gt;- No Attacca server&lt;BR /&gt;- No advertising, analytics, tracking, or monetization&lt;BR /&gt;- Spotify tokens encrypted locally with Android Keystore&lt;BR /&gt;- User-created track-pair rules stored only on the phone&lt;BR /&gt;- Monitoring is explicitly started by the user and shown with an ongoing Android notification&lt;BR /&gt;- Intended only for personal Spotify Premium accounts&lt;BR /&gt;- Requested scopes:&lt;BR /&gt;- user-read-currently-playing&lt;BR /&gt;- user-read-playback-state&lt;BR /&gt;- user-modify-playback-state&lt;BR /&gt;- user-read-private&lt;/P&gt;&lt;P&gt;I would like to comply with the Spotify Developer Terms and Developer Policy before distributing Attacca beyond my own phone.&lt;/P&gt;&lt;P&gt;The Developer Policy says that an SDA must use one Security Code and may not use more than one Security Code per SDA. I found Spotify’s February 2026 forum response acknowledging an existing application in which users bring credentials from their own Development Mode apps, but that response addressed endpoint changes rather than whether this access model complies with the Security Code policy or permits public distribution. I would appreciate clarification on the following:&lt;/P&gt;&lt;P&gt;1. May each Attacca user register their own personal Development Mode app in the Spotify Developer Dashboard and enter that app’s client ID into their local Attacca installation?&lt;/P&gt;&lt;P&gt;2. Would doing that be considered using multiple Security Codes for the same SDA, even though each client ID belongs to a different user’s personal developer account and installation?&lt;/P&gt;&lt;P&gt;3. If that model is not permitted, is the compliant Development Mode model one Attacca client ID with no more than five allowlisted users?&lt;/P&gt;&lt;P&gt;4. May the Attacca APK and source code be publicly available through GitHub or an open-source Android repository if the working application remains limited to the users permitted by Development Mode?&lt;/P&gt;&lt;P&gt;5. Alternatively, may another developer fork the open-source project, register it as their own separately named SDA, and use their own client ID for personal, noncommercial use?&lt;/P&gt;&lt;P&gt;6. Because Attacca sends a request to add an item to the user’s Spotify playback queue, should Attacca be treated as a Streaming SDA under the Developer Terms, even though all playback occurs in the official Spotify application?&lt;/P&gt;&lt;P&gt;I am not requesting Extended Quota Mode at this time. I am trying to determine whether there is a policy-compliant path for personal use, a small closed beta, and potentially a publicly available but noncommercial open-source application.&lt;/P&gt;&lt;P&gt;Please identify whether the answer represents Spotify’s official policy interpretation, since I need to rely on it when deciding whether Attacca can be distributed.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Sun, 16 Aug 2026 15:18:49 GMT</pubDate>
      <guid>https://community.spotify.com/t5/Spotify-for-Developers/Policy-clarification-for-a-noncommercial-Android-playback-queue/m-p/7532625#M21893</guid>
      <dc:creator>bewye</dc:creator>
      <dc:date>2026-08-16T15:18:49Z</dc:date>
    </item>
  </channel>
</rss>

