Socket
Socket
Sign inDemoInstall

react-native-biometrics

Package Overview
Dependencies
Maintainers
2
Versions
27
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

react-native-biometrics

React Native biometric functionality for signing and encryption


Version published
Weekly downloads
53K
increased by1.05%
Maintainers
2
Weekly downloads
 
Created
Source

react-native-biometrics

React native biometrics is a simple bridge to native iOS and Android keystore management. It allows you to create public private key pairs that are stored in native keystores and protected by biometric authentication. Those keys can then be retrieved later, after proper authentication, and used to create a cryptographic signature.

Getting started

$ npm install react-native-biometrics --save

Automatic installation

$ react-native link react-native-biometrics

Manual installation

iOS
  1. In XCode, in the project navigator, right click LibrariesAdd Files to [your project's name]
  2. Go to node_modulesreact-native-biometrics and add ReactNativeBiometrics.xcodeproj
  3. In XCode, in the project navigator, select your project. Add libReactNativeBiometrics.a to your project's Build PhasesLink Binary With Libraries
  4. Run your project
Android
  1. Open up android/app/src/main/java/[...]/MainActivity.java
  • Add import com.rnbiometrics.ReactNativeBiometricsPackage; to the imports at the top of the file
  • Add new ReactNativeBiometricsPackage() to the list returned by the getPackages() method
  1. Append the following lines to android/settings.gradle:
    include ':react-native-biometrics'
    project(':react-native-biometrics').projectDir = new File(rootProject.projectDir, 	'../node_modules/react-native-biometrics/android')
    
  2. Insert the following lines inside the dependencies block in android/app/build.gradle:
      compile project(':react-native-biometrics')
    

Additional configuration

iOS

This package requires an iOS target SDK verion of iOS 10 or higher

Ensure that you have the NSFaceIDUsageDescription entry set in your react native iOS project, or Face ID will not work properly. This description will be will be presented to the user the first time a biometrics action is taken, and the user will be asked if they want to allow the app to use Face ID. If the user declines the usage of face id for the app, the isSensorAvailable function will return null until the face id permission is specifically allowed for the app by the user.

NOTE: No biometric prompt is displayed in iOS simulators when attempting to retrieve keys for signature generation, it only occurs on actual devices.

Android

This package requires a compiled SDK version of 23 (Android 6.0 Marshmallow) or higher

Usage

This package is designed to make server authentication using biometrics easier. Here is an image from https://android-developers.googleblog.com/2015/10/new-in-android-samples-authenticating.html illustrating the basic use case:

react-native-biometrics

When a user enrolls in biometrics, a key pair is generated. The private key is stored securely on the device and the public key is sent to a server for registration. When the user wishes to authenticate, the user is prompted for biometrics, which unlocks the securely stored private key. Then a cryptographic signature is generated and sent to the server for verification. The server then verifies the signature. If the verification was successful, the server returns an appropriate response and authorizes the user.

Methods

isSensorAvailable()

Detects what type of biometric sensor is available. Returns a Promise that resolves to a string representing the sensor type (TouchID, FaceID, null)

Example

import Biometrics from 'react-native-biometrics'

Biometrics.isSensorAvailable()
  .then((biometryType) => {
    if (biometryType === 'TouchID') {
      console.log('TouchID is supported')
    } else if (biometryType === 'FaceId') {
      console.log('FaceID is supported')
    } else {
      console.log('Biometrics not supported')
    }
  })

createKeys(promptMessage)

Prompts the user for their fingerprint or face id, then generates a public private RSA 2048 key pair that will be stored in the device keystore. Returns a Promise that resolves to a base64 encoded string representing the public key.

Arguments

  • promptMessage - string that will be displayed in the fingerprint or face id prompt

Example

import Biometrics from 'react-native-biometrics'

Biometrics.createKeys('Confirm fingerprint')
  .then((publicKey) => {
    console.log(publicKey)
    sendPublicKeyToServer(publicKey)
  })

deleteKeys()

Deletes the generated keys from the device keystore. Returns a Promise that resolves to true or false indicating if the deletion was successful

Example

import Biometrics from 'react-native-biometrics'

Biometrics.deleteKeys()
  .then((success) => {
    if (success) {
      console.log('Successful deletion')
    } else {
      console.log('Unsuccessful deletion')
    }
  })

createSignature(promptMessage, payload)

Prompts the user for their fingerprint or face id in order to retrieve the private key from the keystore, then uses the private key to generate a RSA PKCS#1v1.5 SHA 256 signature. Returns a Promise that resolves to a base64 encoded string representing the signature.

Arguments

  • promptMessage - string that will be displayed in the fingerprint or face id prompt
  • payload - string of data to be signed by the RSA signature

Example

import Biometrics from 'react-native-biometrics'

let epochTimeSeconds = Math.round((new Date()).getTime() / 1000).toString()
let payload = epochTimeSeconds + 'some message'

Biometrics.createSignature('Sign in', payload)
  .then((signature) => {
    console.log(signature)
    verifySignatureWithServer(signature, payload)
  })

Keywords

FAQs

Package last updated on 12 Apr 2018

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts

SocketSocket SOC 2 Logo

Product

  • Package Alerts
  • Integrations
  • Docs
  • Pricing
  • FAQ
  • Roadmap
  • Changelog

Packages

npm

Stay in touch

Get open source security insights delivered straight into your inbox.


  • Terms
  • Privacy
  • Security

Made with ⚡️ by Socket Inc