What this prompt does
This prompt implements biometric authentication for a mobile app across iOS and Android, keeping both platforms symmetric and the security-sensitive cases covered. It runs through six steps: mapping the auth flow, implementing iOS LocalAuthentication, implementing Android BiometricPrompt, building secure token storage, adding fallback and recovery, and writing security tests. Because biometrics touch sensitive flows, the prompt is built so you don't freehand them and miss the lockout and enrollment-change cases.
The variables localize the implementation. [app_type] and [platforms] set the context, [sensitive_actions] define what requires re-authentication, and [ios_policy] plus [ios_keychain] and [android_authenticators] plus [android_keystore] configure each platform. [token_type] and [session_duration] govern secure storage and session length, while [fallback_method], [lockout_attempts], [lockout_duration], and [security_library] shape recovery and threat handling. Binding tokens to the secure enclave or Keystore is the detail that keeps stored credentials safe when biometrics change, and the prompt makes that binding explicit on both platforms rather than leaving it to chance. The re-authentication rules for [sensitive_actions] are equally deliberate, since high-risk operations should never ride on a stale session.
When to use it
- You are adding Face ID, Touch ID, or fingerprint login to a sensitive app.
- You want the iOS and Android paths kept symmetric rather than diverging.
- You need tokens bound to the Secure Enclave or Keystore, not stored loosely.
- You must handle lockout, enrollment changes, and biometry-not-available states.
- You want re-authentication enforced for high-risk actions like
[sensitive_actions]. - You want security tests written alongside the implementation, not after.
Example output
Expect a state diagram of the auth flow including error and fallback paths. The platform steps produce iOS code using LAContext with policy [ios_policy] and full LAError handling, and Android code using BiometricPrompt with a CryptoObject and [android_keystore], handling every error code. From there you get a secure token layer that decrypts the [token_type] token on success, fallback and lockout logic, and a security test suite covering enrollment-change invalidation, session expiration, and protected-action prompts. It is largely platform-specific code plus a documented threat model with mitigations, written so the two platforms behave the same even though their APIs differ.
Pro tips
- Keep the iOS and Android paths symmetric; mismatched behavior between
[ios_policy]and[android_authenticators]confuses users and reviewers. - Bind credentials to biometrics: use the
biometryCurrentSetflag on iOS and a biometric-bound Keystore key on Android so new enrollments invalidate stored tokens. - Handle every error case explicitly; lockout and biometry-not-enrolled are the states implementations commonly miss.
- Set
[session_duration]to force re-authentication regardless of activity, and require it for each of your[sensitive_actions]. - Provide a real
[fallback_method]and a recovery flow; users who lose biometrics must still get back in. - Write the security tests in step 6 as you build, since trusting biometrics in production depends on them rather than on manual checks.