@expo/snapback-expo-custody
v0.1.29
Published
First-party native iOS and Android auth custody for Snapback Expo applications. Experimental; custody grades are adapter-reported.
Readme
@expo/snapback-expo-custody
Experimental first-party native ordinary-bearer auth custody for Snapback Expo
applications. The package provides native compare-and-replace adapters backed
by iOS Keychain or Android DataStore plus Android Keystore AES-GCM. Custody
grades are reported by the selected adapter; in v1, both OS adapters declare
only single-runtime.
Both native provider tuples ship in the qualified thirteen-package closure
beginning with 0.1.24. The first qualified publication was governed by the
custody first-publish gate,
whose ceremony record lives in LLP 0041.
| OS | Adapter-reported grade | Source/publication posture |
| --- | --- | --- |
| iOS | single-runtime | Published (0.1.24+). Share-sheet-extension evidence only; the built NSE and simctl push service-stage invocation remain nonclaims. |
| Android | single-runtime | Published (0.1.24+). |
The separate Phase-2 receipts and closure records live in the both-OS Phase-2 close-out and the iOS extension-refusal close-out. The package is a native module and therefore requires an Expo development/production build; it is not available in Expo Go.
import { createNativeAuthCustodyStorage } from '@expo/snapback-expo-custody';
const storage = createNativeAuthCustodyStorage();
const grade = await storage.platformGrade();The Expo config plugin installs the mandatory Android custody-file backup and
device-transfer exclusions. It is not applied automatically: list
@expo/snapback-expo-custody explicitly in the app's Expo plugins array.
The Android carrier retires a permanently invalidated Keystore alias before it
reports the typed custody-absent diagnostic, so a later fresh write can create
a new key. JavaScript fakes cover that restart contract; only the LLP 0263
emulator/device probes can establish real Keystore invalidation, AEAD, backup,
and OEM process-name behavior. A resolved Android process name different from
the application package fails closed as a secondary-process single-runtime
refusal. If every process-identity mechanism fails, custody also fails closed
before I/O with reason process-identity-unresolved. This is deliberate:
single-runtime identity is a security boundary under LLP 0258 D3, not an
optional diagnostic.
This is an optional add-on, not a dependency of the @expo/snapback umbrella.
Documentation outside a checkout
A running Snapback server serves the Guide compiled into that exact build.
These links use the first default development port; use the origin printed by
snapback dev or snapback start if yours differs.
- Read first: the start packets — the budgeted per-template first read (LLP 0259).
- Read password auth and custody for the ordinary bootstrap path and current platform limits.
- Look up (do not linear-read) the capability index before assuming an OS custody grade is available.
- Run
snapback guideorsnapback guide <query>to browse or search the embedded Guide. - Run
snapback mcpfor the same build-bound corpus as read-only MCP resources, starting atsnapback-guide://manifest.
