NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
pub.dev · #164 most downloaded on pub.dev
A Flutter plugin for securely storing sensitive data using encrypted storage.
Last release 22 days ago
16 Sep 2026
Release timing varies
gaps range from 1 weeks to 11 months
Nearly every release is documented
notes for 52 of 54 stable releases
Nothing withdrawn
no release was ever pulled
9 years old
66 releases · first in 2017
android: requireBiometricsPerOperation flag
One column per quarter.
android: read saved key-cipher marker instead of toString() on a KeyCipher
add checkUpgradeStatus() to report data lost on a direct major upgrade
items deprecated in v10 have been removed. Any data saved using deprecated algorithms or features will be unusable after this upgrade. If you used a v…
Breaking changes
items deprecated in v10 have been removed.
Any data saved using deprecated algorithms or features will be unusable after this upgrade. If you used a version prior to v10, upgrade to v10 first so existing data is migrated.
KeyCipherAlgorithm.RSA_ECB_PKCS1Padding. Upgrade to v10 first so existing data is migrated to RSA_ECB_OAEPwithSHA_256andMGF1Padding before upgrading to v11.StorageCipherAlgorithm.AES_CBC_PKCS7Padding. Upgrade to v10 first so existing data is migrated to AES_GCM_NoPadding before upgrading to v11.encryptedSharedPreferences parameter from AndroidOptions and AndroidOptions.biometric. The Jetpack Security (EncryptedSharedPreferences) backend is no longer supported; any remaining data was automatically migrated to custom cipher storage in v10.sharedPreferencesName from AndroidOptions. Use storageNamespace instead for full namespace isolation.minSdk to 24 and compileSdk to 37. Flutter 3.35 raised its own Android minimum to API 24, making API 23 support unverifiable with any supported Flutter version. The legacy AES-CBC cipher path that supported API 21-22 has been removed.flutter_secure_storage v11.0.0-beta.1
flutter_secure_storage v11.0.0-beta.1
Breaking changes
items deprecated in v10 have been removed.
Any data saved using deprecated algorithms or features will be unusable after this upgrade. If you used a version prior to v10, upgrade to v10 first so existing data is migrated.
KeyCipherAlgorithm.RSA_ECB_PKCS1Padding. Upgrade to v10 first so existing data is migrated to RSA_ECB_OAEPwithSHA_256andMGF1Padding before upgrading to v11.StorageCipherAlgorithm.AES_CBC_PKCS7Padding. Upgrade to v10 first so existing data is migrated to AES_GCM_NoPadding before upgrading to v11.encryptedSharedPreferences parameter from AndroidOptions and AndroidOptions.biometric. The Jetpack Security (EncryptedSharedPreferences) backend is no longer supported; any remaining data was automatically migrated to custom cipher storage in v10.sharedPreferencesName from AndroidOptions. Use storageNamespace instead for full namespace isolation.minSdk to 24 and compileSdk to 37. Flutter 3.35 raised its own Android minimum to API 24, making API 23 support unverifiable with any supported Flutter version. The legacy AES-CBC cipher path that supported API 21-22 has been removed.Nothing published for this version
Read saved key-cipher marker instead of toString() on a KeyCipher
Backport release for the v10 line. 11.0.0 remains the current major version.
Backport release for the v10 line. 11.0.0 remains the current major version.
sharedPreferencesName and storageNamespace with the same name; the wrapped key is now moved to the new location instead of the store starting empty.keyCipherAlgorithm/storageCipherAlgorithm being discarded on upgrade: its algorithm markers were stored where v10 doesn't look, so a failed migration deleted it. Markers are now read from the v9 location, and unmarked data that still decrypts with the current cipher is left alone.migrateWithBackup ignoring storageNamespace and backing up the wrong key storage file.NullPointerException when a storage call ran after the Flutter engine detached; it now throws a catchable INIT_FAILED PlatformException.Fixed AEADBadTagException when biometric authentication is cancelled on first launch: a stale IV is now cleared and the cipher re-initialised in encry
AEADBadTagException when biometric authentication is cancelled on first launch: a stale IV is now cleared and the cipher re-initialised in encrypt mode so the next authentication attempt succeeds.NullPointerException when retrying an operation after a cancelled biometric prompt: preferences is now only assigned once cipher initialisation completes successfully, allowing a clean retry.Added AndroidBiometricType enum and biometricType option to AndroidOptions to control which authentication methods are accepted during biometric promp
AndroidBiometricType enum and biometricType option to AndroidOptions to control which authentication methods are accepted during biometric prompts (requires KeyCipherAlgorithm.AES_GCM_NoPadding).
AndroidBiometricType.biometricOrDeviceCredential (default) accepts Class 3 biometrics or device credentials (PIN/pattern/password), preserving previous behaviour.AndroidBiometricType.strongBiometricOnly restricts authentication to Class 3 (strong) biometrics only; device credentials are explicitly rejected.setAllowedAuthenticators on BiometricPrompt and setUserAuthenticationParameters on the KeyStore key. On earlier API levels the system may still permit device credentials.biometricPromptNegativeButton option to AndroidOptions to customise the dismiss button label on the biometric prompt. Required when using strongBiometricOnly or on Android 10 and lower.secStoreAvailabilitySink not being called when protected data availability changes.kSecUseDataProtectionKeychain being added to Keychain queries unconditionally; it is now only set when useDataProtectionKeychain is explicitly enabled.deleteAll and containsKey not acquiring the mutex lock, which could cause data races under concurrent access.
If you are on Dart >=3.10.0, this fix is applied automatically. Otherwise, pin flutter_secure_storage_windows: ^4.2.2 in your pubspec.yaml to opt in and make sure your constraint is set for minimum of Dart >=3.10.0.deleteKeyring storing the string "null" instead of an empty JSON object {}.FormatException on the Dart side; messages are now sanitised before being sent through the method channel.PlatformException with code KeyringLocked.PlatformException with code StorageError instead of sending malformed bytes through the channel.Deprecated KeyCipherAlgorithm.RSA_ECB_PKCS1Padding. Existing data is automatically migrated to the default RSA_ECB_OAEPwithSHA_256andMGF1Padding when…
KeyCipherAlgorithm.RSA_ECB_PKCS1Padding. Existing data is automatically migrated to the default RSA_ECB_OAEPwithSHA_256andMGF1Padding when migrateOnAlgorithmChange is true.StorageCipherAlgorithm.AES_CBC_PKCS7Padding. Existing data is automatically migrated to the default AES_GCM_NoPadding when migrateOnAlgorithmChange is true.build.gradle.iOS 11.3 to iOS 13.0.win32 6.0.0 in flutter_secure_storage_windows 4.2.0.
If you are on Dart >=3.10.0, this fix is applied automatically. Otherwise, pin flutter_secure_storage_windows: ^4.2.0 in your pubspec.yaml to opt in and make sure your constraint is set for minimum of Dart >=3.10.0.Deprecated sharedPreferencesName in favor of storageNamespace, which provides complete isolation rather than data-only isolation.
flutter_secure_storage_windows to 4.2.0 with compatibility fixes for win32 6.0.0.storageNamespace option to AndroidOptions for full namespace isolation across storage instances (SharedPreferences, KeyStore aliases, config/key storage). Use this instead of sharedPreferencesName when running multiple FlutterSecureStorage instances with different cipher configurations.sharedPreferencesName in favor of storageNamespace, which provides complete isolation rather than data-only isolation.migrateWithBackup option to AndroidOptions for crash-resistant migration. When enabled, backup copies of encrypted data are created before migration starts, allowing recovery if migration fails or the app crashes mid-migration. Works in conjunction with migrateOnAlgorithmChange.KeyCipherAlgorithm and StorageCipherAlgorithm public enums.Fixes:
MethodRunner that could cause a crash on Android.useSecureEnclave option to IOSOptions and MacOsOptions to store keys in the device's Secure Enclave for hardware-backed security.Fixes:
kSecAttrSynchronizable being silently dropped when no access control flags are set.readAll not returning Secure Enclave items correctly.Due to the deprecation of Jetpack Security library, the Android implementation has been largely rewritten with custom secure ciphers, enhanced biometr…
This major release brings significant security improvements, platform updates, and modernization across all supported platforms.
Due to the deprecation of Jetpack Security library, the Android implementation has been largely rewritten with custom secure ciphers, enhanced biometrics support, and migration tools.
Breaking Changes:
AndroidOptions().encryptedSharedPreferences is now deprecated due to Jetpack Crypto package deprecation
migrateOnAlgorithmChange: true, which can also be set to false if not wanted.resetOnError: falseRSA_ECB_OAEPwithSHA_256andMGF1PaddingAES_GCM_NoPaddingNew Features:
AndroidOptions(), AndroidOptions.biometric()AndroidOptions().migrateOnAlgorithmChange automatically migrates data to new ciphers when enabledFixes:
enforceBiometrics=falseOther Changes:
flutter_secure_storage_darwin packagehtml to web packagejs in favor of using js-interopuseSessionStorage parameter to WebOptions for saving in session storage instead of local storagewin32 version 5.5.4 to support Dart 3.4 / Flutter 3.22.0FlutterSecureStorage().registerListener()Due to security issues regarding the handling of biometrics in v10.0.0-beta.4, together with the deprecation of Jetpack Security library, it took me s…
Due to security issues regarding the handling of biometrics in v10.0.0-beta.4, together with the deprecation of Jetpack Security library, it took me some time to find a secure alternative. My apologies for the delay.
The Android part has been largely rewritten, reintroducing the customer cipher construction from before, but with secure ciphers, biometrics support, updated default ciphers and migration tools.
Breaking Changes:
AndroidOptions().encryptedSharedPreferences is now deprecated due to Jetpack Crypto package being deprecated
For now you can still use deprecated encryptedSharedPreferences by setting encryptedSharedPreferences: true
and migrateOnAlgorithmChange: false. If encryptedSharedPreferences is true and migrateOnAlgorithmChange
is true, data will be automatically migrated to the new cipher, and encryptedSharedPreferences
cannot be used anymore.RSA_ECB_OAEPwithSHA_256andMGF1PaddingAES_GCM_NoPaddingNew Features:
AndroidOptions(), AndroidOptions.biometric()AndroidOptions().migrateOnAlgorithmChange automatically migrates data to new ciphers when enabledKey Fixes:
enforceBiometrics=falseresetOnError behavior (now defaults to true)Other Changes:
[Apple] Merged ios and macos implementation into a new package flutter_secure_storage_darwin
[Android] Fix deprecation warning.
[Web] Update flutter_secure_storage_platform_interface to be compatible with WASM.
Migrated from deprecated Jetpack Crypto library to Google Tink Crypto library.
This new major release has some big changes. This plugin requires a minimum dart sdk of 3.3.0 or higher and a minimum flutter version of 3.19.0.
[Android]
[iOS]
[Web]
[Windows]
win32 version 5.5.4 to support Dart 3.4 / Flutter 3.22.0.[Platform Interface]
[Android] Fix errors when building for release by upgrading Tink to 1.9.0.
[iOS] Fix for issue #711: The specified item already exists in the keychain.
[iOS, macOS] Fixed an issue which caused the readAll and deleteAll to not work properly.
[iOS, macOS] Fixed an issue which caused the readAll and deleteAll to not work properly.
Fix async race condition bug in storage operations.
[iOS, macOS] Reintroduced isProtectedDataAvailable.
New Features:
FlutterSecureStorage().registerListener()Bugs Fixed:
Reverts new feature because of breaking changes.
Reverts new feature because of breaking changes.
[iOS, macOS] Added isProtectedDataAvailable, A boolean value that indicates whether content protection is active.
New Features:
Improvements:
[Windows] Migrated to FFI with win32 package.
Breaking changes:
[Android] Upgraded to Gradle 8.
[macOS] The minimum macOS version supported is now 10.14.
Breaking changes:
Other changes:
[Android] Reverted double initialization of the SharedPreferences because this will break mixed usage of secureSharedPreference on Android.
[Android] Reverted double initialization of the SharedPreferences because this will break mixed usage of secureSharedPreference on Android.
[macOS] The minimum macOS version supported is now 10.13.
Breaking changes:
Other changes:
[Android] Fix deprecation warnings.
[iOS] Migrated from objective C to Swift. This also fixes issues with containsKey and possibly other issues.
[Android] Upgrade to Android SDK 33.
This version reverts some breaking changes of update 5.1.0. These changes will become available in version 6.0.0
This version reverts some breaking changes of update 5.1.0. These changes will become available in version 6.0.0
Example app dependencies updated
[Android] You can now select your own key prefix or database name.
[Android] Fixed bug where sharedPreference object was not yet initialized.
[Android] Added java 8 requirement for gradle build.
First stable release of flutter_secure_storage for multi-platform! Please see all beta release notes for changes.
First stable release of flutter_secure_storage for multi-platform! Please see all beta release notes for changes.
This first release also fixes several stability issues on Android regarding encrypted shared preferences.
[Linux, iOS & macOS] Add containsKey function.
[Windows] Fixed application crashing when key doesn't exists.
[Android] Add possibility to reset data when an error occurs.
[Android] Removed deprecated classes
Initial BETA support for macOS, web & Windows. Development is still ongoing so expect some functions to not work correctly! Please read the readme.md
Initial BETA support for macOS, web & Windows. Development is still ongoing so expect some functions to not work correctly! Please read the readme.md for information about every platform.
Changed deprecated jcenter to mavenCentral #246
Remove Strongbox for Android 225. Thanks JordyLangen.
Add support for Linux 185. Thanks talhabalaj
Introduce null-safety. Thanks Steve Alexander
Fix thread safety issues in android code to close 161. Thanks koskimas
Fix Android hanging UI on StorageCipher initialization #116 by morrica
Fix compatibility with non-AndroidX project. AndroidX Migration is recommended.
Migrate to Android v2 embedder.
Fix Android Manifest error Issue 77 and Issue 79. Thanks nate-eisner.
* Fix crash without iOSOptions.
Added groupId for iOS keychain sharing. Thanks Maleandr.
gradle-wrapper.properties. Thanks blasten.Fix Android 9.0 Pie KeyStore exception.
Nothing published for this version
Breaking change. Migrate from the deprecated original Android Support Library to AndroidX. This shouldn't result in any functional changes, but it req…
Fix Android 9.0 Pie KeyStore exception. Thanks hacker1024
Added recreating secretKey if its decoding failed. Fix for unwrap key. Thanks hnvn.
Your coding agent can read these notes before it upgrades. Set up the MCP server →