NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
pub.dev
Auth runtime for Antinvestor Flutter apps. OAuth2 + PKCE, adaptive DPoP, rotating refresh tokens with reuse detection, Isolate-isolated tokens, hardware-backed storage, Riverpod providers, Material widgets.
Last release 3 months ago
18 Jun 2026
Ships fairly regularly
a new release about every 3 weeks
Most releases are documented
notes for 3 of 4 stable releases
Nothing withdrawn
no release was ever pulled
5 months old
4 releases · first in 2026
One column per month.
NativeCredentialConfig, a high-level factory configuration for Apple and Google native credential providers. Android apps can now enable the Google Si
NativeCredentialConfig, a high-level factory configuration for Apple and
Google native credential providers. Android apps can now enable the
Google Sign-In v7 Credential Manager / One Tap path with
createAuthRuntime(nativeCredentialConfig: NativeCredentialConfig(...)).preferSilent support for native credentials. Apps can now explicitly
disable the app-start no-UI credential attempt while keeping the interactive
native sheet on sign-in tap.createAuthRuntime rejects simultaneous nativeCredentialConfig and
nativeProviders inputs to prevent ambiguous native credential setup.NativeCredentialConfig as the preferred app
integration path and keeps nativeProviders for tests and custom provider
stacks.Nothing published for this version
flutter_secure_storage 9 → 10. Migrates Android off the deprecated Jetpack Crypto package and unifies iOS/macOS into flutter_secure_storage_darwin. Co…
flutter_web_auth_2 instead of flutter_appauth. Adds web, Windows, and Linux to the supported platforms (previously iOS/Android/macOS only) and removes the AppAuth iOS pod, eliminating the long-standing pod conflict with google_sign_in_ios (AppAuth ~> 2.0). PKCE/state/nonce are now generated by TokenWorker.prepareAuth exclusively — the previous double-generation (worker + flutter_appauth) is gone, and the OAuth state parameter is now actually verified end-to-end.OAuthFlow.authorize now takes an AuthorizeRequest argument and OAuthResult no longer carries verifier/nonce. OAuthFlow is package:antinvestor_auth_runtime/src/... (not exported), so consumers that only depend on createAuthRuntime are unaffected. Tests that subclass OAuthFlow need to update the override signature.redirectScheme (e.g. com.example.app) under CFBundleURLTypes in Info.plist. Universal Links also work — set redirectUri to the https://... URL and flutter_web_auth_2 will use ASWebAuthenticationSession.flutter_web_auth_2's CallbackActivity to AndroidManifest.xml with an intent filter for the redirect scheme. See flutter_web_auth_2 README.auth.html at the redirect URI's path (flutter_web_auth_2 posts the callback URL via window.opener.postMessage).desktop_webview_window by default; pass an http://localhost:{port} redirectUri if you want the loopback fallback.flutter_web_auth_2 opens the IdP login page in the system browser, and FedCM (navigator.credentials.get({ identity })) is invoked by the IdP page itself when the IdP supports it. No client-side wiring is required.flutter_secure_storage 9 → 10. Migrates Android off the deprecated Jetpack Crypto package and unifies iOS/macOS into flutter_secure_storage_darwin. Consumer apps must raise platform mins: Android minSdkVersion >= 23 (was 19), iOS >= 12.0, macOS >= 10.14.pointycastle 3.9 → 4.0. Pure additive: new ciphers (Blowfish, Camellia, Twofish), generics on generateKeyPair. No usage changes required.sign_in_with_apple 6.1 → 7.0. Extended AuthorizationErrorCode cases (our switch already has a default: fall-through, so no code changes).runtime.fetch / runtime.upload accept fully-qualified https://... URLs; when the path starts with http:// or https://, the runtime uses it directly an
runtime.fetch / runtime.upload accept fully-qualified https://... URLs; when the path starts with http:// or https://, the runtime uses it directly and skips apiBaseUrl prepending. Unblocks consumers that talk to multiple service domains with a single OAuth client.Your coding agent can read these notes before it upgrades. Set up the MCP server →