Android Backend Subsystem

Android Backend Subsystem An architecture diagram generated by Archify. Master Token · durable record · bearer authority Master Token durable record gpsoauth Mint · MintService · bearer authority gpsoauth Mint MintService BearerProvider · shared · generation · bearer authority · repr-safe BearerProvider shared · generation repr-safe Evidence Profile · pinned app version · Architecture component Evidence Profile pinned app version NotebookLMClient · backend=android · Architecture component NotebookLMClient backend=android Android APIs · _android/*.py · gRPC control plane · 11 namespaces Android APIs _android/*.py 11 namespaces Proto Codecs · _android/codecs/ · gRPC control plane Proto Codecs _android/codecs/ AndroidSession · lazy · supervised · gRPC control plane · epoch fenced AndroidSession lazy · supervised epoch fenced NotebookLM PA · notebooklm-pa.googleapis.com · Architecture component NotebookLM PA notebooklm-pa.googleapis.com HTTPS Data Plane · upload · download · Architecture component HTTPS Data Plane upload · download Asset Hosts · lh3 · usercontent · Architecture component Asset Hosts lh3 · usercontent assembles typed proto unary call gRPC TLS gpsoauth OAuth token Authorization user-agent bearer GET upload control per-hop bearer bearer authority gRPC control plane

Control plane

  • • The channel opens lazily on first use and is fenced to the client resource epoch
  • • Unary and streaming calls carry deadlines and typed gRPC status mapping

Identity

  • • The OAuth spec pins the app package, client signature and seven scopes
  • • BearerCredential never exposes its token through repr

Data plane

  • • AndroidUploadPipeline and AndroidAssetDownloadService bypass gRPC entirely
  • • Asset hops clear ambient cookies and strip credentials once off the allowlist