From 5b574f2257de57ec46aebb95b69d37f5cf130fdd Mon Sep 17 00:00:00 2001 From: fhasse95 <49185957+fhasse95@users.noreply.github.com> Date: Sat, 18 Jul 2026 21:33:44 +0200 Subject: [PATCH] Update README.md --- README.md | 19 ++++++++++++++++--- 1 file changed, 16 insertions(+), 3 deletions(-) diff --git a/README.md b/README.md index 8b4e7b6..d30b3cc 100644 --- a/README.md +++ b/README.md @@ -950,11 +950,24 @@ Use `allowsDeviceCredentialFallback: false` when your app presents its own passc ### Platform Notes -On iOS, `BiometricAuthentication` uses `LocalAuthentication.LAContext`. When `allowsDeviceCredentialFallback` is `true`, iOS uses `.deviceOwnerAuthentication`; otherwise it uses `.deviceOwnerAuthenticationWithBiometrics`. On Android, SkipKit uses AndroidX `BiometricPrompt` with strong biometric authenticators. When `allowsDeviceCredentialFallback` is `true`, Android uses `BIOMETRIC_STRONG | DEVICE_CREDENTIAL` and does not show a negative button, because AndroidX does not allow a negative button together with device credentials. +#### Darwin +* On iOS/iPadOS/macOS, SkipKit uses `LocalAuthentication.LAContext`. +* When `allowsDeviceCredentialFallback` is `true`, the system uses `.deviceOwnerAuthentication`; otherwise, it uses `.deviceOwnerAuthenticationWithBiometrics`. -### Android Permissions +iOS/iPadOS Apps using biometric authentication with Face ID must include `NSFaceIDUsageDescription` in their `Info.plist`: + +```xml +NSFaceIDUsageDescription +Use Face ID to securely unlock the app. +``` + +If Face ID is requested without this usage description, iOS/iPadOS will terminate the app. Touch ID does not require a separate usage-description key. + +#### Android +* On Android, SkipKit uses AndroidX `BiometricPrompt` with strong biometric authenticators. +* When `allowsDeviceCredentialFallback` is `true`, the system uses `BIOMETRIC_STRONG | DEVICE_CREDENTIAL`. In this mode, the prompt will not show a cancel button, because AndroidX does not allow a cancel button together with device credentials. -Android apps using biometric authentication must include the biometric permission in their manifest: +Android apps using biometric authentication must include the biometric permission in their `AndroidManifest.xml`: ```xml