Search by

smronju / nativephp-secure-storage

smronju

Implements NativePHP Mobile's SecureStorage::set()/get()/delete() on both platforms — Android Keystore (AES-256-GCM) on Android, the Keychain on iOS.

Package info

github.com/smronju/nativephp-secure-storage

Type:nativephp-plugin

pkg:composer/smronju/nativephp-secure-storage

Statistics

Installs: 0

Dependents: 0

Suggesters: 0

Stars: 0

Open Issues: 0

1.0.0 2026-09-29 17:52 UTC

This package is auto-updated.

Last update: 2026-09-29 18:01:01 UTC


README

Implements NativePHP Mobile's SecureStorage facade on Android and iOS: SecureStorage::set(), get(), read() and delete().

nativephp/mobile core ships the PHP side (Native\Mobile\Facades\SecureStorage) but registers the SecureStorage.* bridge functions on neither platform, so without a plugin every call silently returns false / null on a device. This plugin adds the native side only. There is no new facade to learn.

How values are stored

  • Android: AES-256-GCM, with the key held in the Android Keystore (it never leaves secure hardware or the TEE). The ciphertext lives in the app's private SharedPreferences. No Gradle dependencies; EncryptedSharedPreferences is deprecated, so it isn't used.
  • iOS: one Keychain generic-password item per key, scoped to the app's bundle id. Every accessibility is a ThisDeviceOnly one, so items never sync to iCloud Keychain or restore onto another device.

Uninstalling the app removes everything on Android. On iOS the Keychain can outlive an uninstall, as it does for every app.

Requirements

  • nativephp/mobile ^4.1
  • Android API 23+
  • iOS 15.0+

Installation

composer require smronju/nativephp-secure-storage
php artisan vendor:publish --tag=nativephp-plugins-provider
php artisan native:plugin:register smronju/nativephp-secure-storage

Then rebuild: php artisan native:run.

Don't install it alongside nativephp/mobile-secure-storage: both register the same SecureStorage.* functions.

Usage

Exactly as core documents it:

use Native\Mobile\Facades\SecureStorage;
use Native\Mobile\SecureStorageAccessibility;

SecureStorage::set('api_token', $token);
SecureStorage::set('refresh_token', $refresh, SecureStorageAccessibility::AfterFirstUnlock);

$token = SecureStorage::get('api_token');   // ?string

$result = SecureStorage::read('api_token'); // found() / missing() / unavailable() / failed()

SecureStorage::set('api_token', null);      // null deletes
SecureStorage::delete('refresh_token');

read() statuses:

Status Android iOS
found stored and decrypted stored
not_found never stored, or deleted never stored, or deleted
unavailable never (see below) device locked and the item is WhenUnlocked / WhenPasscodeSet
error DECRYPT_FAILED: the Keystore key is gone, e.g. after a credential reset KEYCHAIN_<OSStatus>

The accessibility argument is ignored on Android, as core documents: a Keystore key without user-authentication requirements is usable whenever the app runs, which is already after-first-unlock behaviour.

Testing

composer test

License

MIT