BiometricAuthenticator

Android actual — androidx.biometric.BiometricPrompt, gated on BIOMETRIC_STRONG (Class 3).

Class 3 rather than WEAK because the callers this exists for are payment and secrets flows; a Class 2 face unlock is not the factor you want guarding a saved card token. The same constant is used for the pre-flight check and for the prompt, so a device can never pass one and fail the other.

Face/Touch ID on iOS, BiometricPrompt on Android, one suspending call.

Android's half needs a FragmentActivity, which is why :security's BiometricGuard could never move to commonMain — it takes the activity as a parameter. This module inverts that: the host app installs an activity provider once (BiometricAndroid.install { … }), and everything above the seam stays platform-free. :security keeps BiometricGuard as its Android-only, VAPT-surface companion; this is the cross-platform door.

Always check canAuthenticate before offering a biometric affordance at all. authenticate re-checks and returns BiometricResult.Unavailable rather than showing nothing, so a caller that forgets still gets a reason instead of silence.

What the consuming app must declare

  • Android — androidx.biometric needs no manifest permission on API 28+; the prompt host must be a FragmentActivity (ComponentActivity alone is not enough).

  • iOS — NSFaceIDUsageDescription in Info.plist. Without it Face ID evaluation fails at runtime (Touch ID does not need it), which surfaces here as BiometricResult.Failed.

iOS actual — LAContext / LocalAuthentication, the Face ID + Touch ID counterpart to Android's BiometricPrompt. Compiles and links against the simulator framework; an actual prompt needs a real device (the simulator's "Matching Face" menu aside).

A fresh LAContext per call, deliberately. A context caches its evaluation for a few minutes, so reusing one means the second "authenticate to pay" silently succeeds without asking — exactly the kind of invisible weakening this module exists to avoid.

Constructors

Link copied to clipboard
actual constructor()
expect constructor()
actual constructor()

Functions

Link copied to clipboard
actual suspend fun authenticate(title: String, subtitle: String, cancelLabel: String): BiometricResult

Shows the system biometric prompt and suspends until the user resolves it.

expect suspend fun authenticate(title: String, subtitle: String = "", cancelLabel: String = "Cancel"): BiometricResult

Shows the system biometric prompt and suspends until the user resolves it.

actual suspend fun authenticate(title: String, subtitle: String, cancelLabel: String): BiometricResult

Shows the system biometric prompt and suspends until the user resolves it.

Link copied to clipboard

Why biometric authentication can or cannot run right now. See BiometricAvailability.

Why biometric authentication can or cannot run right now. See BiometricAvailability.

Why biometric authentication can or cannot run right now. See BiometricAvailability.