How to implement FIDO2 (WebAuthn) for Android and IOS

Viewed 2340

I developed a web app which uses WebAuthn API to authenticate using hardware security keys. It works fine.

I am trying to implement it natively using Flutter with compatibility for both IOS and Android. Are there any libraries or starting point for these platforms? I don't want to use ChromeTabs or SFSafariViewController.

Please advice.

2 Answers

For Android, you have their FIDO2 API. Some example codelabs and implementations already exist:

  1. codelab
  2. kotlin example
  3. java example.

On iOS, however, FIDO2 is only supported inside the Safari browser (not sure about the other browsers) and only since iOS 13.3 (link).

You may consider using the native FIDO2 API on Android and opening Safari on iOS until the underlying platform support is added.

As @mackie pointed out, however, if you are using FIDO2 in the authentication portion of an OAuth flow, the recommended path is to use a web browser with ASWebAuthenticationSession or Chrome custom tabs.

You should open a browser window to get user authenticated and on successful login use my-app://myapp/auth/succeed=true&token=xyz as redirect url (private-use URI scheme redirects) and before that register that url pattern for your app "my-app" as protocol. Browser will automatically open your app with given redirect url and you must handle that url to put your app in appropriate state...

Related