SecureStore

actual class SecureStore(source)

Android actual — EncryptedSharedPreferences keyed by an Android Keystore MasterKey (AES-256-GCM), by way of :settings' SecureSettingsFactory.

Takes an application Context; anything else would outlive its owner.

expect class SecureStore(source)

A small encrypted key/value store for secrets — session tokens, payment-method handles, PINs — with one API across Android and iOS.

What backs it

  • Android — EncryptedSharedPreferences under an Android Keystore MasterKey (AES-256-GCM).

  • iOS — the Keychain (KeychainSettings, service com.siddharth.kmp.secure).

Both come from :settings' SecureSettingsFactory, which already owns that crypto. This module is the cross-platform door onto it, not a second implementation of it.

How this differs from :security's KeystoreSecureStore

:security stays Android-only on purpose — it is the VAPT surface (hook/SSL-bypass/root detection, FLAG_SECURE, certificate pinning), and its KeystoreSecureStore additionally hashes key names so even the names of stored secrets never hit disk. Reach for that one when the threat model is a rooted device with a filesystem dump. Reach for this one when the requirement is "the same secret, on both platforms, encrypted at rest".

Writes report, they do not pretend

Mutators return Boolean rather than Unit. A store that cannot be opened and silently accepts a payment token is the shareText no-op with money attached: the caller believes the token is saved, the next launch disagrees, and nothing anywhere said why. false means not stored — call isAvailable for the reason.

Construction is per-platform (Android needs a Context), which is the whole point of the expect/actual seam; there is no common constructor to call.

actual class SecureStore(source)

iOS actual — the Keychain, by way of :settings' KeychainSettings (service com.siddharth.kmp.secure), the same store :llm-chat's SecureKeyStore already writes to.

No second Keychain wrapper: one kSecAttrService for the whole toolkit means a secret written through one module is readable through another, and there is exactly one place to change if that service name ever has to move.

Constructors

Link copied to clipboard
constructor(context: Context)
constructor()

Functions

Link copied to clipboard
actual fun clear(): Boolean

Deletes everything in this store. Returns false if the store is unavailable.

expect fun clear(): Boolean

Deletes everything in this store. Returns false if the store is unavailable.

actual fun clear(): Boolean

Deletes everything in this store. Returns false if the store is unavailable.

Link copied to clipboard
actual fun contains(key: String): Boolean

Whether key holds a value. false when the store is unavailable.

expect fun contains(key: String): Boolean

Whether key holds a value. false when the store is unavailable.

actual fun contains(key: String): Boolean

Whether key holds a value. false when the store is unavailable.

Link copied to clipboard
actual fun getString(key: String): String?

The value stored under key, or null if absent — or if the store is unavailable.

expect fun getString(key: String): String?

The value stored under key, or null if absent — or if the store is unavailable.

actual fun getString(key: String): String?

The value stored under key, or null if absent — or if the store is unavailable.

Link copied to clipboard

Why this store can or cannot hold a secret right now. See SecureStoreStatus.

Why this store can or cannot hold a secret right now. See SecureStoreStatus.

Why this store can or cannot hold a secret right now. See SecureStoreStatus.

Link copied to clipboard
actual fun putString(key: String, value: String): Boolean

Stores value under key. Returns false if the store is unavailable and nothing was written.

expect fun putString(key: String, value: String): Boolean

Stores value under key. Returns false if the store is unavailable and nothing was written.

actual fun putString(key: String, value: String): Boolean

Stores value under key. Returns false if the store is unavailable and nothing was written.

Link copied to clipboard
actual fun remove(key: String): Boolean

Deletes key. Returns false if the store is unavailable and nothing was deleted.

expect fun remove(key: String): Boolean

Deletes key. Returns false if the store is unavailable and nothing was deleted.

actual fun remove(key: String): Boolean

Deletes key. Returns false if the store is unavailable and nothing was deleted.