NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
pub.dev
Biometric security for Flutter: Face ID, Touch ID & fingerprint authentication with hardware-backed encrypted storage and app-lock, on Android and iOS.
Last release 2 months ago
04 Aug 2026
Too new to tell
only 1 release windows
Some releases are documented
notes for 3 of 6 stable releases
Nothing withdrawn
no release was ever pulled
2 months old
6 releases · first in 2026
One column per month.
Nothing published for this version
Added isInvalidated(key:) — a lightweight, non-prompting boolean check for whether a secret's biometric-bound key was invalidated (e.g. by an enrollme
isInvalidated(key:) — a lightweight, non-prompting boolean check for
whether a secret's biometric-bound key was invalidated (e.g. by an
enrollment change). Android uses a Cipher.init probe; iOS uses the biometric
domain-state. Returns false for absent or non-gated secrets.local_auth /
flutter_secure_storage.Fixed the homepage/repository/issue_tracker URLs (they pointed at a non-existent GitHub account, so the pub.dev "Repository" link 404'd).
homepage/repository/issue_tracker URLs (they pointed at a
non-existent GitHub account, so the pub.dev "Repository" link 404'd).Initial public beta. Every implemented flow is validated on physical Android and iOS devices; a few APIs remain stubs (see the "Platform limitations"
Initial public beta. Every implemented flow is validated on physical Android and iOS devices; a few APIs remain stubs (see the "Platform limitations" section of the README). As a pre-1.0 release, the public API may still change.
getAvailability() reports supported vs enrolled
modalities, biometric strength, secure-hardware presence, and what the device
can actually enforce (EnforceableGuarantees).authenticate() backed by a real hardware key
operation (Android BiometricPrompt + CryptoObject; iOS Secure Enclave
signing), not a bare boolean.write/read/contains/delete/deleteAll
using AES-256-GCM envelope encryption with a per-secret data-encryption key
held in the Android Keystore / iOS Keychain.rotateKey, revoke,
revokeAll, and resetInvalidated for recovery after invalidation.SecurityPolicy mapping one intent to both platforms
(strength, device-credential fallback, enrollment binding, auth validity,
hardware requirement, accessibility).BiometricSecurityException hierarchy;
failures never return plaintext or silently regenerate keys.requireSecureHardware on both platforms (rejects software-backed
keys / software auth fallback).signChallenge, lifecycle-event emission, enableProtection/
disableProtection, and policyOf are declared but not yet implemented.Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →