From 5b574f2257de57ec46aebb95b69d37f5cf130fdd Mon Sep 17 00:00:00 2001
From: fhasse95 <49185957+fhasse95@users.noreply.github.com>
Date: Sat, 18 Jul 2026 21:33:44 +0200
Subject: [PATCH] Update README.md
---
README.md | 19 ++++++++++++++++---
1 file changed, 16 insertions(+), 3 deletions(-)
diff --git a/README.md b/README.md
index 8b4e7b6..d30b3cc 100644
--- a/README.md
+++ b/README.md
@@ -950,11 +950,24 @@ Use `allowsDeviceCredentialFallback: false` when your app presents its own passc
### Platform Notes
-On iOS, `BiometricAuthentication` uses `LocalAuthentication.LAContext`. When `allowsDeviceCredentialFallback` is `true`, iOS uses `.deviceOwnerAuthentication`; otherwise it uses `.deviceOwnerAuthenticationWithBiometrics`. On Android, SkipKit uses AndroidX `BiometricPrompt` with strong biometric authenticators. When `allowsDeviceCredentialFallback` is `true`, Android uses `BIOMETRIC_STRONG | DEVICE_CREDENTIAL` and does not show a negative button, because AndroidX does not allow a negative button together with device credentials.
+#### Darwin
+* On iOS/iPadOS/macOS, SkipKit uses `LocalAuthentication.LAContext`.
+* When `allowsDeviceCredentialFallback` is `true`, the system uses `.deviceOwnerAuthentication`; otherwise, it uses `.deviceOwnerAuthenticationWithBiometrics`.
-### Android Permissions
+iOS/iPadOS Apps using biometric authentication with Face ID must include `NSFaceIDUsageDescription` in their `Info.plist`:
+
+```xml
+NSFaceIDUsageDescription
+Use Face ID to securely unlock the app.
+```
+
+If Face ID is requested without this usage description, iOS/iPadOS will terminate the app. Touch ID does not require a separate usage-description key.
+
+#### Android
+* On Android, SkipKit uses AndroidX `BiometricPrompt` with strong biometric authenticators.
+* When `allowsDeviceCredentialFallback` is `true`, the system uses `BIOMETRIC_STRONG | DEVICE_CREDENTIAL`. In this mode, the prompt will not show a cancel button, because AndroidX does not allow a cancel button together with device credentials.
-Android apps using biometric authentication must include the biometric permission in their manifest:
+Android apps using biometric authentication must include the biometric permission in their `AndroidManifest.xml`:
```xml