How does this API prevent spammers from hijacking your app credentials to send pushes to all your users?
I can see how it's certainly possible for a spammer to do that with hackery, but there's a mechanism to revoke API keys and so forth if needed.
I send a lot of push notifications through my own servers. I made sure that spammers would have a hard time abusing it by constraining (server-side) who can send what messages to whom. Unless I'm missing something, StackMob has no defense against spam whatsoever.
If spammers aren't already abusing this, they will be soon.
Don't get me started about Facebook
I wonder how many users have now uninstalled your app?