Skip to main content

Mobile Biometric Authentication Implementation

Implement biometric authentication (Face ID, Touch ID, fingerprint) for mobile apps with secure key storage, fallback mechanisms, and session management.

Fill in the placeholders

Edit the values, then copy your finished prompt.

Your Prompt
prompt.txt
You are a mobile security engineer specializing in biometric authentication. Help me implement biometrics for a mobile banking app on iOS and Android.

Step 1: Design the biometric authentication flow. Map the user journey: first-time setup (enable biometrics after password login), subsequent logins (biometric prompt with password fallback), re-authentication for sensitive actions (money transfer, password change, biometric settings change), and biometric enrollment changes (detect when new fingerprints or faces are added). Create a state diagram showing all transitions including error states and fallback paths.

Step 2: Implement iOS biometric authentication using the LocalAuthentication framework. Configure LAContext with the appropriate policy (deviceOwnerAuthenticationWithBiometrics). Set the localizedReason string for the biometric prompt. Handle all LAError cases: biometry not available, biometry not enrolled, biometry lockout (too many failures), user cancel, user fallback, and system cancel. Store the authentication credential in the Secure Enclave-backed Keychain with the biometryCurrentSet access control flag so it is invalidated when biometrics change.

Step 3: Implement Android biometric authentication using the BiometricPrompt API. Configure the PromptInfo with title, subtitle, and allowed authenticators (BIOMETRIC_STRONG). Use the AndroidKeyStore with StrongBox Keystore to generate a cryptographic key bound to biometric authentication. Create a CryptoObject that wraps a Cipher initialized with the biometric-bound key. Handle all error codes: ERROR_HW_UNAVAILABLE, ERROR_LOCKOUT, ERROR_LOCKOUT_PERMANENT, ERROR_NO_BIOMETRICS, and ERROR_NEGATIVE_BUTTON.

Step 4: Build the secure token storage layer. On successful biometric authentication, decrypt the stored JWT refresh token token from the secure enclave and use it for API authentication. Implement token refresh logic that re-encrypts the new token with the biometric-bound key. Set a maximum session duration of 24 hours after which biometric re-authentication is required regardless of app activity.

Step 5: Implement the fallback and recovery mechanisms. When biometrics fail or are unavailable, fall back to PIN or password. After 5 failed biometric attempts, enforce a 30 seconds cooldown period. If the user removes all biometric enrollments from device settings, detect this on next app launch and require full password authentication to re-enable biometrics. Provide an account recovery flow for users who forget their password.

Step 6: Write security tests covering: biometric prompt appears for protected actions, stored tokens are inaccessible without biometric auth, new biometric enrollment invalidates stored credentials, fallback flow works when biometrics are disabled, session expiration forces re-authentication, and rooted/jailbroken device detection using SafetyNet (Android) / DeviceCheck (iOS). Document the threat model and mitigations.

What this prompt does

This prompt implements biometric authentication for a mobile app across iOS and Android, keeping both platforms symmetric and the security-sensitive cases covered. It runs through six steps: mapping the auth flow, implementing iOS LocalAuthentication, implementing Android BiometricPrompt, building secure token storage, adding fallback and recovery, and writing security tests. Because biometrics touch sensitive flows, the prompt is built so you don't freehand them and miss the lockout and enrollment-change cases.

The variables localize the implementation. [app_type] and [platforms] set the context, [sensitive_actions] define what requires re-authentication, and [ios_policy] plus [ios_keychain] and [android_authenticators] plus [android_keystore] configure each platform. [token_type] and [session_duration] govern secure storage and session length, while [fallback_method], [lockout_attempts], [lockout_duration], and [security_library] shape recovery and threat handling. Binding tokens to the secure enclave or Keystore is the detail that keeps stored credentials safe when biometrics change, and the prompt makes that binding explicit on both platforms rather than leaving it to chance. The re-authentication rules for [sensitive_actions] are equally deliberate, since high-risk operations should never ride on a stale session.

When to use it

  • You are adding Face ID, Touch ID, or fingerprint login to a sensitive app.
  • You want the iOS and Android paths kept symmetric rather than diverging.
  • You need tokens bound to the Secure Enclave or Keystore, not stored loosely.
  • You must handle lockout, enrollment changes, and biometry-not-available states.
  • You want re-authentication enforced for high-risk actions like [sensitive_actions].
  • You want security tests written alongside the implementation, not after.

Example output

Expect a state diagram of the auth flow including error and fallback paths. The platform steps produce iOS code using LAContext with policy [ios_policy] and full LAError handling, and Android code using BiometricPrompt with a CryptoObject and [android_keystore], handling every error code. From there you get a secure token layer that decrypts the [token_type] token on success, fallback and lockout logic, and a security test suite covering enrollment-change invalidation, session expiration, and protected-action prompts. It is largely platform-specific code plus a documented threat model with mitigations, written so the two platforms behave the same even though their APIs differ.

Pro tips

  • Keep the iOS and Android paths symmetric; mismatched behavior between [ios_policy] and [android_authenticators] confuses users and reviewers.
  • Bind credentials to biometrics: use the biometryCurrentSet flag on iOS and a biometric-bound Keystore key on Android so new enrollments invalidate stored tokens.
  • Handle every error case explicitly; lockout and biometry-not-enrolled are the states implementations commonly miss.
  • Set [session_duration] to force re-authentication regardless of activity, and require it for each of your [sensitive_actions].
  • Provide a real [fallback_method] and a recovery flow; users who lose biometrics must still get back in.
  • Write the security tests in step 6 as you build, since trusting biometrics in production depends on them rather than on manual checks.

Frequently Asked Questions

Does this keep iOS and Android behavior consistent?
That is a core goal. Step 2 uses iOS LocalAuthentication and step 3 uses Android BiometricPrompt, and the prompt keeps them symmetric in flow and token binding. The platforms differ in API details, so the code is necessarily platform-specific even though the behavior aligns.
What happens when the user adds a new fingerprint or face?
Stored credentials are bound to the current biometric set, using the `biometryCurrentSet` flag on iOS and a biometric-bound Keystore key on Android. When enrollments change, those credentials are invalidated and the app requires full password authentication to re-enable biometrics.
Where are the auth tokens stored?
The `[token_type]` token is stored in the Secure Enclave or `[android_keystore]` and decrypted only after successful biometric authentication. Token refresh re-encrypts the new token with the biometric-bound key, and a `[session_duration]` cap forces re-authentication regardless of activity.
How does it handle repeated failed attempts?
After `[lockout_attempts]` failures, it enforces a `[lockout_duration]` cooldown, and it handles the platform lockout error codes explicitly. If all biometric enrollments are removed in device settings, the app detects this on next launch and falls back to `[fallback_method]`.
Engr Mejba Ahmed

Need this built for real?

Engr Mejba Ahmed

AI Developer · Software Engineer

I'm Mejba — I design and ship production AI systems, automations, and full-stack apps. If you want this turned into a working solution for your team, let's talk.

More in Mobile App Development Prompts

Engr Mejba Ahmed

Engr Mejba Ahmed

AI assistant · trained on my work

👋

Hey there!

Quick Actions

WhatsApp Direct line to me

Chat on WhatsApp

+880 1723 741224 · Replies within the hour on working days

Popular Questions

Engr Mejba Ahmed is connected
Engr Mejba Ahmed is typing...
Engr Mejba Ahmed avatar

✉ Want me to follow up? Drop your email

Engr Mejba Ahmed avatar

📞 Connect Directly

Choose how you'd like to reach me

WhatsApp

+880 1723 741224

Email

mejba.13@gmail.com

✓ Details sent! I'll get back to you shortly.

Powered by OpenAI

335+

Blog Posts

25

AI Courses

63

Projects

Services & Expertise

Pricing & Process

Learning & Resources

Connect & Support