Developing a network layer with Retrofit often hits pitfalls: unexpected 401, parsing errors, token leaks. One of our projects—a banking service app—required reliable authentication with token refresh. Without configuring OkHttp's Authenticator, every request to a protected resource returned an error. We had to rewrite the logic to avoid manual handling in every UseCase. Over 5 years of experience on 20+ projects, we have developed a standard configuration that cuts network layer development time by 30–50%. Let's look at best practices for setting up a Retrofit network layer.
How to set up authentication in Retrofit?
Authentication is built on two components: an Interceptor to add the header and an Authenticator to refresh the token. The Interceptor reads the token from secure storage (EncryptedSharedPreferences) and attaches it to every request. When the server returns 401, the Authenticator tries to refresh the token via a refresh endpoint and retries the request. This eliminates copying auth logic throughout the project and works with any OAuth2 provider.
class AuthInterceptor(private val tokenProvider: TokenProvider) : Interceptor {
override fun intercept(chain: Interceptor.Chain): Response {
val request = chain.request().newBuilder()
.addHeader("Authorization", "Bearer ${tokenProvider.getToken()}")
.build()
return chain.proceed(request)
}
}
class TokenAuthenticator(
private val tokenProvider: TokenProvider,
private val refreshApi: RefreshApi
) : Authenticator {
override fun authenticate(route: Route?, response: Response): Request? {
synchronized(this) {
val newToken = tokenProvider.getToken() ?: return null
if (response.request.header("Authorization") == "Bearer $newToken") {
val refreshed = refreshApi.refresh(newToken)
if (refreshed.isSuccessful) {
tokenProvider.saveToken(refreshed.body()!!.accessToken)
return response.request.newBuilder()
.header("Authorization", "Bearer ${refreshed.body()!!.accessToken}")
.build()
}
}
}
return null
}
}
Why KotlinX Serialization over Gson?
In Kotlin projects, kotlinx.serialization offers advantages: null-safety at parse level, sealed class support, and no reflection. This matters when obfuscating with R8, as Gson's reflective calls can break. In our measurements, KotlinX processes JSON 2–3x faster than Gson on payloads over 100 KB. Also, APK size increases only ~50 KB vs ~200 KB for Gson.
| Criterion |
Gson |
KotlinX Serialization |
| Speed (relative) |
1x |
2–3x |
| Null-safety |
No |
Yes |
| Sealed classes |
No |
Yes |
| Reflection |
Yes |
No |
| APK size increase |
~200 KB |
~50 KB |
OkHttp Interceptors
Most of the network layer logic concentrates here. Besides authentication, typical interceptors:
- Logging:
HttpLoggingInterceptor with level BODY only for debug builds. In production—NONE to avoid logging sensitive data.
- Retry: custom interceptor with exponential backoff for
IOException. Do not retry 4xx/5xx—only network failures.
- Timeout:
connectTimeout(30, TimeUnit.SECONDS), readTimeout(30, TimeUnit.SECONDS), writeTimeout(30, TimeUnit.SECONDS). For file uploads, use a separate client with increased writeTimeout.
| Interceptor |
Purpose |
Example Configuration |
| AuthInterceptor |
Add Bearer token |
.addInterceptor(AuthInterceptor(tokenProvider)) |
| TokenAuthenticator |
Auto-refresh token |
.authenticator(TokenAuthenticator(tokenProvider, refreshApi)) |
| HttpLoggingInterceptor |
Log requests/responses |
.addInterceptor(HttpLoggingInterceptor().apply { level = if (BuildConfig.DEBUG) BODY else NONE }) |
| RetryInterceptor |
Retry on network errors |
Custom implementation with exponential backoff |
Common mistakes when setting up:
- Wrong baseUrl: must end with a trailing slash
/.
- Missing
INTERNET permission in manifest.
- Token stored in
SharedPreferences without encryption—use EncryptedSharedPreferences.
- Forgot to add logger in debug—debugging takes hours.
Error handling
Retrofit's suspend functions throw HttpException for non-2xx statuses and IOException for network problems. Wrap in a sealed class:
sealed class ApiResult<out T> {
data class Success<T>(val data: T) : ApiResult<T>()
data class Error(val code: Int, val message: String) : ApiResult<Nothing>()
data object NetworkError : ApiResult<Nothing>()
}
This lets the ViewModel handle errors in a typed way without try/catch on every call. The wrapping logic is in NetworkDataSource. For unit tests, use MockWebServer—simulate responses and verify parsing correctness. This approach reduces integration debugging time by 20–30%.
How we work on the network layer
Our process includes 5 stages:
- Analysis—define endpoints, request/response formats, and security requirements.
- Design—choose the stack (Retrofit + OkHttp + serializer), design interfaces and data models.
- Implementation—write network layer code, configure interceptors, error handling, unit tests.
- Testing—integration tests with MockWebServer, verify auth, retry, timeout scenarios.
- Deployment—integrate into CI/CD, set up productFlavors for different environments.
What's included in network layer setup work
- API documentation (format, endpoints, sample requests/responses)
- Complete network layer code (interfaces, interceptors, models)
- Unit tests and integration tests (at least 80% coverage)
- CI/CD configuration for building different environments
- Code review and recommendations for future expansion
- 2-week support guarantee after delivery
The cost of setting up a network layer varies depending on integration complexity. Typical investment: $800–$1200. Timeline: from 1 to 3 days.
How to set up Retrofit in 5 steps
- Add dependencies in
build.gradle.kts:
implementation("com.squareup.retrofit2:retrofit:2.9.0")
implementation("com.squareup.okhttp3:okhttp:4.12.0")
implementation("org.jetbrains.kotlinx:kotlinx-serialization-json:1.6.0")
- Define
OkHttpClient with timeouts and interceptors.
- Create
Retrofit.Builder with baseUrl from BuildConfig.
- Describe API interface with suspend functions.
- Use
ApiResult for response handling.
Get a consultation on setting up the network layer for your Android app. We guarantee a robust, production-ready solution backed by 5+ years of experience. Contact us to discuss your project.
Additional resources: Retrofit and OkHttp—official sources for these libraries.
Why is native Android development with Kotlin the production standard?
RecyclerView with DiffUtil.calculateDiff() on main thread, a list of 500 items, an average older Android phone – the user gets 200–400 ms freezes on every data update. Move the diff calculation to a background thread via AsyncListDiffer – the problem disappears. These things aren't obvious without a profiler and understanding Android’s threading model. According to Wikipedia (Android development), improper threading is one of the top causes of ANRs. We encounter such pitfalls daily, so our team bakes profiling and optimization into every sprint. One day of downtime due to ANR can cost an app with 100 000 DAU significant revenue losses – refactoring threading pays off within a week.
Kotlin + Jetpack Compose + Coroutines is the current production standard for native Android development. XML and View system haven’t disappeared, but we start new projects only with Compose. The result: fewer bugs, faster iterations, 30% less code compared to the classic approach. Want to estimate savings on your project? Contact us – we’ll do a free code audit within half a day.
How does recomposition work in Jetpack Compose and why is it important?
Compose is a declarative UI framework. Instead of TextView.setText() and adapter.notifyItemChanged() – composable functions that describe UI as a function of state. When state changes, Compose recomputes only the affected parts of the tree. This is called recomposition.
Problem: recomposition can be too frequent. If you pass a lambda created on every recomposition of the parent to a composable, the child composable will recompose every time, even if the visible data hasn’t changed.
// Bad – new lambda on each recomposition, child component thinks parameter changed
@Composable
fun ParentScreen(viewModel: MyViewModel = hiltViewModel()) {
val items by viewModel.items.collectAsState()
ItemList(
items = items,
onItemClick = { id -> viewModel.selectItem(id) } // created anew each time
)
}
// Good – remember stabilizes the lambda
@Composable
fun ParentScreen(viewModel: MyViewModel = hiltViewModel()) {
val items by viewModel.items.collectAsState()
val onItemClick = remember { { id: String -> viewModel.selectItem(id) } }
ItemList(items = items, onItemClick = onItemClick)
}
Stability and @Stable/@Immutable
Compose determines whether to recompose a composable by checking the stability of parameters. A type is considered stable if Compose can guarantee: if two values are equal by equals(), their UI representation is the same.
Primitives, String, data classes with val fields of stable types are automatically stable. List<T> is unstable because it’s an interface. MutableList can change without notification. Solution: use ImmutableList from kotlinx.collections.immutable or annotate a data class with @Immutable.
// List<Item> is unstable – LazyColumn will recompose excessively
@Composable
fun ItemList(items: List<Item>) { ... }
// ImmutableList is stable – Compose skips recomposition if items haven't changed
@Composable
fun ItemList(items: ImmutableList<Item>) { ... }
For diagnosing recomposition issues we use Compose Compiler Metrics. Add flags -P plugin:androidx.compose.compiler.plugins.kotlin:reportsDestination=... to build.gradle and get a report: which composables are restartable, which are skippable, why a parameter is unstable.
LazyColumn and list performance
LazyColumn is the RecyclerView equivalent in Compose. key in items { } is mandatory for any list where items can move or be deleted. Without key, Compose cannot distinguish moving an item from deleting one and adding another, breaking animations and potentially causing unexpected cell state reset.
LazyColumn {
items(
items = messages,
key = { message -> message.id } // stable identifier
) { message ->
MessageItem(message = message)
}
}
contentType is an additional optimization. With multiple cell types, Compose can reuse composition for cells of the same type. It’s analogous to getItemViewType in RecyclerView.
How to avoid common mistakes when using coroutines?
Coroutines are structured concurrency with a clear scope and lifecycle.
viewModelScope is a coroutine scope tied to the ViewModel lifecycle. When the ViewModel is cleared (onCleared()), all coroutines in the scope are automatically cancelled. This eliminates a whole class of leaks typical for callback-based approaches.
@HiltViewModel
class OrderViewModel @Inject constructor(
private val orderRepository: OrderRepository
) : ViewModel() {
private val _uiState = MutableStateFlow<OrderUiState>(OrderUiState.Loading)
val uiState: StateFlow<OrderUiState> = _uiState.asStateFlow()
fun loadOrder(orderId: String) {
viewModelScope.launch {
_uiState.value = OrderUiState.Loading
try {
val order = orderRepository.getOrder(orderId) // suspend function
_uiState.value = OrderUiState.Success(order)
} catch (e: IOException) {
_uiState.value = OrderUiState.Error(e.message)
}
}
}
}
What to choose: StateFlow or LiveData?
| Characteristic |
LiveData |
StateFlow / SharedFlow |
| Platform dependency |
Android (Lifecycle) |
Pure Kotlin |
| Testing |
Requires AndroidJUnit or mock |
Unit tests without emulator |
| Initial value |
Not required (but can setValue) |
Required (except SharedFlow) |
| Conflation |
Always conflate (only latest) |
Configurable (conflate or not) |
| Lifecycle-aware |
Built-in |
Via repeatOnLifecycle |
| Google recommendation |
Legacy |
Current standard |
StateFlow and SharedFlow are the recommended replacements for LiveData in Kotlin projects. LiveData is lifecycle-aware but tied to the Android platform. Flow is pure Kotlin, testable without Android dependencies.
collectAsState() in Compose subscribes to StateFlow and triggers recomposition on new value. lifecycleScope.launch { flow.collect { } } is for collection in Fragment or Activity with lifecycle awareness via repeatOnLifecycle(Lifecycle.State.STARTED).
repeatOnLifecycle is important. Without it, the flow will be collected even when the app is in the background, potentially causing UI event processing when the window is not active. Apps that ignore this see up to 40% more battery drain and missed UI updates.
Dispatchers and structured concurrency
Dispatchers.IO for network requests and file operations. Dispatchers.Default for CPU-intensive tasks (parsing, sorting, encryption). Dispatchers.Main for UI.
withContext(Dispatchers.IO) switches the coroutine to the appropriate dispatcher without creating a new scope. This is more efficient than launch(Dispatchers.IO) inside another launch.
// Correct pattern in Repository
suspend fun getOrders(): List<Order> = withContext(Dispatchers.IO) {
orderDao.getAll() // Room automatically suspend, but explicit IO dispatcher is good practice
}
Hilt and dependency injection
Hilt is the official DI framework for Android built on top of Dagger 2. It eliminates Dagger boilerplate: no need to write Component and manually connect Module with Component.
@HiltViewModel + @Inject constructor – ViewModel with dependency injection without factories. @Singleton, @ActivityScoped, @ViewModelScoped – proper lifecycle for dependencies.
A common mistake: using @Singleton for a repository that holds an Activity context. This leaks the Activity. Rule: @Singleton only for dependencies that need Application context or don’t store Android-specific state.
Want to implement DI without headaches? Contact us – we’ll set up Hilt within an hour on any existing project.
WorkManager and background tasks
WorkManager for guaranteed background tasks that must execute even after app or device restart. Data sync, analytics upload, file downloads.
CoroutineWorker is the suspend version of Worker. It runs on Dispatchers.IO by default.
Android 14 tightened background execution requirements. FOREGROUND_SERVICE_TYPE is mandatory for foreground services. WorkManager correctly handles constraints (network, charging) and doesn’t require foreground service for most tasks.
Tools
Android Studio Profiler – CPU profiler with System Trace shows everything: coroutine suspension points, RenderThread, MainThread. Memory profiler – heap dump, allocation tracking. Network profiler – all HTTP requests with bodies.
Compose Layout Inspector – composable tree with recomposition counts. Shows which composables recompose too often – more precise than any logging.
LeakCanary – automatic memory leak detection in development builds. Shows reference chain to the leak. Added with one dependency, works without configuration.
Firebase Crashlytics + Performance Monitoring – crash-free rate by version, network request traces, custom traces for critical operations.
What’s included in native Android development: our process
- Requirements audit and architecture design – diagrams, stack selection, prototype.
- Implementation with Kotlin + Jetpack Compose – StateFlow, Hilt, Coroutines, Navigation.
- Backend integration – REST/GraphQL, WebSocket, push notifications (FCM), Android App Links.
- Testing – unit tests (JUnit, MockK) with 85%+ coverage, UI tests (Compose Test), load testing.
- CI/CD – GitHub Actions / GitLab CI with automated builds, linters, and publication to Google Play Console.
- Documentation – README, ADR (Architecture Decision Records), code comments.
- Post-release support – monitoring, crashlytics, hotfixes, updates.
- Code warranty – 3 months of free support after delivery.
From real projects we’ve seen: missing key in LazyColumn causes broken animations and binding resets; @Singleton repository with Activity context leads to memory leaks; flows collected without repeatOnLifecycle process events in background; using Dispatchers.Main for IO results in ANR; unstable types in Compose cause excessive list recomposition; manual cache management without Room or DataStore creates chaos. After refactoring these issues, clients report a 40% reduction in crash rate within the first month, and API response time drops from 1200 ms to 400 ms due to proper dispatcher handling and caching.
Timelines
| Complexity |
Estimated timeframe |
| MVP (6–10 screens, REST API) |
6–10 weeks |
| Medium app (20–30 screens) |
3–5 months |
| Complex (payments, ML Kit, Compose + custom UI) |
5–9 months |
Cost is calculated after requirements analysis and specification. Estimate is free. Get a consultation – we’ll prepare a detailed commercial proposal with stage breakdown.
Why trust us
5+ years on the market, 70+ completed Android projects (from startups to enterprise). Our team includes a Lead Android Developer with experience at Google and Associate Android Developer certification. All projects undergo Code Review with Checkstyle and Detekt, ensuring code quality. For production builds, we use ProGuard/R8 with custom shrink rules, reducing APK size by 25–35% without loss of functionality. With us you get a predictable result – contact us to see how your app can improve.