Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
35 commits
Select commit Hold shift + click to select a range
eedabc7
feat(clerk-js,shared): add experimental trusted device resources
mikepitre Sep 27, 2026
06409ce
feat(expo-biometrics): add biometric credential native module
mikepitre Sep 27, 2026
193f277
chore(expo-biometrics): point iOS storage comment at the clerk-ios co…
mikepitre Sep 28, 2026
8ae86de
fix(expo-biometrics): report missing secure key storage
mikepitre Sep 28, 2026
b04b97d
feat(expo-biometrics): add Android support
mikepitre Sep 27, 2026
406e03d
fix(expo-biometrics): report missing secure key storage on Android
mikepitre Sep 28, 2026
b3fe64c
feat(expo): move biometric credentials to @clerk/expo-biometrics
mikepitre Sep 27, 2026
cffd179
fix(expo): keep API error codes on biometric credential errors
mikepitre Sep 27, 2026
8bc206c
fix(expo): treat missing secure key storage as unavailable
mikepitre Sep 28, 2026
76e4e5b
chore(expo): port biometrics to main and fix test typing
mikepitre Sep 29, 2026
3d8a2eb
chore(expo-biometrics): raise the clerk.browser.js size limit and cla…
mikepitre Sep 30, 2026
7ef069b
docs(expo-biometrics): describe the package as the install for useBio…
mikepitre Sep 30, 2026
fa996d4
feat(expo): run biometric reverification in JS
mikepitre Sep 30, 2026
ab01e9d
chore(expo): correct useBiometricCredentials requirements and raise t…
mikepitre Sep 30, 2026
6a7b7fb
chore(expo-biometrics): point storage comments at clerk-android's con…
mikepitre Sep 30, 2026
0d8e5b0
fix(expo-biometrics): serialize Android record saves and deletes
mikepitre Sep 30, 2026
a662774
Merge branch 'main' into mike/expo-biometrics-package
wobsoriano Sep 30, 2026
690bef2
chore(expo): drop the Android re-enrollment note now that clerk-andro…
mikepitre Sep 30, 2026
119ba4e
chore(expo-biometrics): exclude native tests from the published package
wobsoriano Oct 1, 2026
adecbb5
refactor(expo,expo-biometrics): remove unreachable compatibility shims
wobsoriano Oct 1, 2026
413705c
refactor(expo): dedupe local credential cleanup in sign-in and reverify
wobsoriano Oct 1, 2026
32f6c80
test(expo): drop native sync mocks the biometric hook no longer uses
wobsoriano Oct 1, 2026
f854344
chore(clerk-js): raise the clerk.legacy.browser.js size limit
wobsoriano Oct 1, 2026
c720537
chore(repo): simplify biometric credential changesets
wobsoriano Oct 1, 2026
d9f99e6
fix(expo): keep biometric credential error codes consistent
wobsoriano Oct 1, 2026
f253936
docs(expo): describe the @clerk/expo-biometrics requirement on useBio…
wobsoriano Oct 1, 2026
4714f8e
test(e2e): add a biometric availability smoke flow
wobsoriano Oct 1, 2026
4fe93d7
refactor(clerk-js): align native settings parsing with sibling resources
wobsoriano Oct 1, 2026
89da67e
Merge branch 'main' into mike/expo-biometrics-package
wobsoriano Oct 1, 2026
6ec83d4
fix(expo,expo-biometrics): check biometric challenges before promptin…
mikepitre Oct 1, 2026
4ba69f8
feat(expo): export useBiometricCredentials from @clerk/expo/biometrics
wobsoriano Oct 1, 2026
b609ad1
fix(expo-biometrics): settle Android sign() when the prompt cannot show
swolfand Oct 1, 2026
af58d9f
Merge branch 'main' into mike/expo-biometrics-package
mikepitre Oct 1, 2026
d7094a9
ci(repo): copy expo-biometrics Android tests into the packed fixture …
mikepitre Oct 1, 2026
d82987a
Merge branch 'main' into mike/expo-biometrics-package
mikepitre Oct 1, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions .changeset/experimental-trusted-device-resources.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
'@clerk/clerk-js': minor
'@clerk/shared': minor
---

Add experimental APIs for biometric sign-in in native apps. This includes the `trusted_device` strategy for sign-in and session reverification, `nativeSettings` on the auth config, and `__experimental_` methods on `User` for managing biometric credentials. These may change in minor releases.
20 changes: 20 additions & 0 deletions .changeset/expo-biometrics-package.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
---
'@clerk/expo': minor
'@clerk/expo-biometrics': minor
---

Introduce `@clerk/expo-biometrics`, a new package that `useBiometricCredentials()` now requires. Install it and rebuild your app:

```sh
npx expo install @clerk/expo-biometrics
```

If it's missing, the hook throws an error with these same steps.

Import the hook from `@clerk/expo/biometrics`:

```ts
import { useBiometricCredentials } from '@clerk/expo/biometrics';
```

Importing it from `@clerk/expo` still works, but it logs a deprecation warning and will be removed in the next major version.
17 changes: 15 additions & 2 deletions .github/workflows/expo-native-build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ on:
- 'integration/templates/expo-native/**'
- 'integration/tests/expo-native/**'
- 'packages/expo/**'
- 'packages/expo-biometrics/**'
- 'packages/expo-google-signin/**'
workflow_dispatch:

Expand Down Expand Up @@ -84,6 +85,7 @@ jobs:
turbo.json \
packages/clerk-js \
packages/expo \
packages/expo-biometrics \
packages/expo-google-signin \
packages/react \
packages/shared \
Expand Down Expand Up @@ -121,10 +123,11 @@ jobs:
- name: Build and pack Clerk packages
if: steps.native-build-cache.outputs.cache-hit != 'true'
run: |
pnpm --filter @clerk/expo... build
pnpm --filter @clerk/expo... --filter @clerk/expo-biometrics build
mkdir -p "$SDK_PACK_DIR"
pnpm --filter @clerk/expo pack --pack-destination "$SDK_PACK_DIR"
pnpm --filter @clerk/expo-google-signin pack --pack-destination "$SDK_PACK_DIR"
pnpm --filter @clerk/expo-biometrics pack --pack-destination "$SDK_PACK_DIR"

- name: Install fixture dependencies
if: steps.native-build-cache.outputs.cache-hit != 'true'
Expand All @@ -138,7 +141,8 @@ jobs:
# [0-9] keeps this glob off the clerk-expo-google-signin tarball.
SDK_TARBALL="$(ls "$SDK_PACK_DIR"/clerk-expo-[0-9]*.tgz)"
GOOGLE_SIGNIN_TARBALL="$(ls "$SDK_PACK_DIR"/clerk-expo-google-signin-*.tgz)"
pnpm add "$SDK_TARBALL" "$GOOGLE_SIGNIN_TARBALL" -w
BIOMETRICS_TARBALL="$(ls "$SDK_PACK_DIR"/clerk-expo-biometrics-*.tgz)"
pnpm add "$SDK_TARBALL" "$GOOGLE_SIGNIN_TARBALL" "$BIOMETRICS_TARBALL" -w
# expo-dev-client makes even release builds boot into the dev
# launcher (unreachable Metro in CI), which stalls every Maestro
# flow on a blank screen. Skip it on e2e jobs only.
Expand Down Expand Up @@ -209,6 +213,15 @@ jobs:
working-directory: ${{ env.FIXTURE_DIR }}
run: pnpm build:android

# The module's Robolectric tests need an Expo host project for expo-modules-core, so they run in the fixture.
# The packed module leaves out its tests, so they are copied in from the repo.
- name: Test expo-biometrics Android module
if: matrix.platform == 'android' && steps.native-build-cache.outputs.cache-hit != 'true'
working-directory: ${{ env.FIXTURE_DIR }}/android
run: |
cp -R "$GITHUB_WORKSPACE/packages/expo-biometrics/android/src/test" "$(readlink -f ../node_modules/@clerk/expo-biometrics)/android/src/"
./gradlew :clerk-expo-biometrics:testDebugUnitTest

- name: Prebuild iOS fixture
if: matrix.platform == 'ios' && steps.native-build-cache.outputs.cache-hit != 'true'
working-directory: ${{ env.FIXTURE_DIR }}
Expand Down
2 changes: 2 additions & 0 deletions integration/templates/expo-native/App.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,7 @@ import { tokenCache } from '@clerk/expo/token-cache';
import { useState } from 'react';
import { Button, Modal, StyleSheet, Text, View } from 'react-native';

import { BiometricAvailabilityButton } from './components/BiometricAvailabilityButton';
import { GoogleSignInButton } from './components/GoogleSignInButton';

const publishableKey = process.env.EXPO_PUBLIC_CLERK_PUBLISHABLE_KEY;
Expand Down Expand Up @@ -64,6 +65,7 @@ function NativeBuildFixture() {
onPress={() => setIsAuthOpen(true)}
/>
{!isSignedIn && <GoogleSignInButton />}
{!isSignedIn && <BiometricAvailabilityButton />}
{isSignedIn && (
<Button
testID='open-embedded-profile-button'
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
import { useBiometricCredentials } from '@clerk/expo/biometrics';
import { useState } from 'react';
import { Button, Text } from 'react-native';

export function BiometricAvailabilityButton() {
const { getAvailability } = useBiometricCredentials();
const [result, setResult] = useState<string | null>(null);

return (
<>
<Button
testID='biometric-availability-button'
title='Check biometric availability'
onPress={() => {
void getAvailability().then(
availability => setResult(`biometric availability: ${availability.unavailableReason ?? 'available'}`),
(error: unknown) => {
const message = error instanceof Error ? error.message : String(error);
setResult(`biometric availability failed: ${message.replace(/\s+/g, ' ')}`);
},
);
}}
/>
{result && <Text testID='biometric-availability-result'>{result}</Text>}
</>
);
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
appId: com.clerk.exponativebuildfixture
name: useBiometricCredentials reaches the expo-biometrics native module
---
- runFlow: subflows/open-app.yaml
- tapOn:
id: 'biometric-availability-button'
- extendedWaitUntil:
visible: 'biometric availability: .*'
timeout: 15000
6 changes: 3 additions & 3 deletions packages/clerk-js/bundlewatch.config.json
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
{
"files": [
{ "path": "./dist/clerk.js", "maxSize": "554KB" },
{ "path": "./dist/clerk.browser.js", "maxSize": "81KB" },
{ "path": "./dist/clerk.legacy.browser.js", "maxSize": "124.5KB" },
{ "path": "./dist/clerk.js", "maxSize": "556KB" },
{ "path": "./dist/clerk.browser.js", "maxSize": "83KB" },
{ "path": "./dist/clerk.legacy.browser.js", "maxSize": "126KB" },
{ "path": "./dist/clerk.no-rhc.js", "maxSize": "322.25KB" },
{ "path": "./dist/clerk.native.js", "maxSize": "82KB" },
{ "path": "./dist/vendors*.js", "maxSize": "7KB" },
Expand Down
37 changes: 36 additions & 1 deletion packages/clerk-js/src/core/resources/AuthConfig.ts
Original file line number Diff line number Diff line change
@@ -1,4 +1,11 @@
import type { AuthConfigJSON, AuthConfigJSONSnapshot, AuthConfigResource, PhoneCodeChannel } from '@clerk/shared/types';
import type {
AuthConfigJSON,
AuthConfigJSONSnapshot,
AuthConfigResource,
NativeSettingsJSON,
NativeSettingsResource,
PhoneCodeChannel,
} from '@clerk/shared/types';

import { unixEpochToDate } from '../../utils/date';
import { BaseResource } from './internal';
Expand All @@ -9,6 +16,7 @@ export class AuthConfig extends BaseResource implements AuthConfigResource {
singleSessionMode: boolean = false;
preferredChannels: Record<string, PhoneCodeChannel> | null = null;
sessionMinter: boolean = false;
nativeSettings: NativeSettingsResource | null = null;

public constructor(data: Partial<AuthConfigJSON> | null = null) {
super();
Expand All @@ -25,6 +33,7 @@ export class AuthConfig extends BaseResource implements AuthConfigResource {
this.singleSessionMode = this.withDefault(data.single_session_mode, this.singleSessionMode);
this.preferredChannels = this.withDefault(data.preferred_channels, this.preferredChannels);
this.sessionMinter = this.withDefault(data.session_minter, this.sessionMinter);
this.nativeSettings = this.withDefault(nativeSettingsFromJSON(data.native_settings), this.nativeSettings);
return this;
}

Expand All @@ -36,6 +45,32 @@ export class AuthConfig extends BaseResource implements AuthConfigResource {
reverification: this.reverification,
single_session_mode: this.singleSessionMode,
session_minter: this.sessionMinter,
native_settings: nativeSettingsToJSON(this.nativeSettings),
};
}
}

function nativeSettingsFromJSON(data: NativeSettingsJSON | null | undefined): NativeSettingsResource | null {
if (!data) {
return null;
}
return {
apiEnabled: data.api_enabled,
trustedDeviceSignInEnabled: data.trusted_device_sign_in_enabled,
trustedDeviceEnrollmentPromptAfterSignInEnabled: data.trusted_device_enrollment_prompt_after_sign_in_enabled,
trustedDeviceEnrollmentPromptAfterSignUpEnabled: data.trusted_device_enrollment_prompt_after_sign_up_enabled,
};
}

function nativeSettingsToJSON(settings: NativeSettingsResource | null): NativeSettingsJSON | null {
if (!settings) {
return null;
}
return {
object: 'native_settings',
api_enabled: settings.apiEnabled,
trusted_device_sign_in_enabled: settings.trustedDeviceSignInEnabled,
trusted_device_enrollment_prompt_after_sign_in_enabled: settings.trustedDeviceEnrollmentPromptAfterSignInEnabled,
trusted_device_enrollment_prompt_after_sign_up_enabled: settings.trustedDeviceEnrollmentPromptAfterSignUpEnabled,
};
}
117 changes: 117 additions & 0 deletions packages/clerk-js/src/core/resources/BiometricCredential.ts
Original file line number Diff line number Diff line change
@@ -0,0 +1,117 @@
import type {
AttemptBiometricCredentialParams,
BiometricCredentialJSON,
BiometricCredentialJSONSnapshot,
BiometricCredentialPlatform,
BiometricCredentialResource,
BiometricCredentialStatus,
PrepareBiometricCredentialParams,
TrustedDeviceAlgorithm,
TrustedDeviceChallengeJSON,
TrustedDeviceChallengeResource,
} from '@clerk/shared/types';

import { unixEpochToDate } from '../../utils/date';
import { BaseResource } from './internal';
import { trustedDeviceChallengeFromJSON } from './TrustedDeviceChallenge';

const PATH_ROOT = '/me/biometric_credentials';

function toEnrollmentBody(params: PrepareBiometricCredentialParams | AttemptBiometricCredentialParams) {
const { publicKeyJwk, ...rest } = params;
return {
...rest,
publicKeyJwk: typeof publicKeyJwk === 'string' ? publicKeyJwk : JSON.stringify(publicKeyJwk),
};
}

export class BiometricCredential extends BaseResource implements BiometricCredentialResource {
id!: string;
pathRoot = PATH_ROOT;
platform!: BiometricCredentialPlatform;
appIdentifier!: string;
name: string | null = null;
algorithm!: TrustedDeviceAlgorithm;
status!: BiometricCredentialStatus;
lastUsedAt: Date | null = null;
revokedAt: Date | null = null;
createdAt!: Date;
updatedAt!: Date;

public constructor(data: BiometricCredentialJSON | BiometricCredentialJSONSnapshot) {
super();
this.fromJSON(data);
}

static async list(): Promise<BiometricCredentialResource[]> {
const json = (await BaseResource._fetch({ path: PATH_ROOT, method: 'GET' }))
?.response as unknown as BiometricCredentialJSON[];
return (json || []).map(credential => new BiometricCredential(credential));
}

static async prepare(params: PrepareBiometricCredentialParams): Promise<TrustedDeviceChallengeResource> {
const json = (
await BaseResource._fetch({
path: `${PATH_ROOT}/prepare`,
method: 'POST',
body: toEnrollmentBody(params) as any,
})
)?.response as unknown as TrustedDeviceChallengeJSON;
return trustedDeviceChallengeFromJSON(json) as TrustedDeviceChallengeResource;
}

static async attempt(params: AttemptBiometricCredentialParams): Promise<BiometricCredentialResource> {
const json = (
await BaseResource._fetch({
path: `${PATH_ROOT}/attempt`,
method: 'POST',
body: toEnrollmentBody(params) as any,
})
)?.response as unknown as BiometricCredentialJSON;
return new BiometricCredential(json);
}

static async revoke(biometricCredentialId: string): Promise<BiometricCredentialResource> {
const json = (
await BaseResource._fetch({
path: `${PATH_ROOT}/${biometricCredentialId}`,
method: 'DELETE',
})
)?.response as unknown as BiometricCredentialJSON;
return new BiometricCredential(json);
}

protected fromJSON(data: BiometricCredentialJSON | BiometricCredentialJSONSnapshot | null): this {
if (!data) {
return this;
}

this.id = data.id;
this.platform = data.platform;
this.appIdentifier = data.app_identifier;
this.name = data.name ?? null;
this.algorithm = data.algorithm;
this.status = data.status;
this.lastUsedAt = data.last_used_at ? unixEpochToDate(data.last_used_at) : null;
this.revokedAt = data.revoked_at ? unixEpochToDate(data.revoked_at) : null;
this.createdAt = unixEpochToDate(data.created_at);
this.updatedAt = unixEpochToDate(data.updated_at);
return this;
}

public __internal_toSnapshot(): BiometricCredentialJSONSnapshot {
return {
object: 'trusted_device',
id: this.id,
platform: this.platform,
app_identifier: this.appIdentifier,
name: this.name,
algorithm: this.algorithm,
status: this.status,
last_used_at: this.lastUsedAt?.getTime() ?? null,
revoked_at: this.revokedAt?.getTime() ?? null,
created_at: this.createdAt.getTime(),
updated_at: this.updatedAt.getTime(),
};
}
}
3 changes: 3 additions & 0 deletions packages/clerk-js/src/core/resources/Session.ts
Original file line number Diff line number Diff line change
Expand Up @@ -270,6 +270,9 @@ export class Session extends BaseResource implements SessionResource {
case 'passkey':
config = {};
break;
case 'trusted_device':
config = { trustedDeviceId: factor.trustedDeviceId };
break;
case 'enterprise_sso':
config = {
emailAddressId: factor.emailAddressId,
Expand Down
34 changes: 34 additions & 0 deletions packages/clerk-js/src/core/resources/TrustedDeviceChallenge.ts
Original file line number Diff line number Diff line change
@@ -0,0 +1,34 @@
import type { TrustedDeviceChallengeJSON, TrustedDeviceChallengeResource } from '@clerk/shared/types';

export function trustedDeviceChallengeFromJSON(
data: TrustedDeviceChallengeJSON | null | undefined,
): TrustedDeviceChallengeResource | null {
if (!data) {
return null;
}
return {
challenge: data.challenge,
challengeId: data.challenge_id,
trustedDeviceId: data.trusted_device_id ?? null,
clientData: data.client_data,
expiresAt: data.expires_at ? new Date(data.expires_at * 1000) : null,
algorithm: data.algorithm,
};
}

export function trustedDeviceChallengeToJSON(
challenge: TrustedDeviceChallengeResource | null,
): TrustedDeviceChallengeJSON | null {
if (!challenge) {
return null;
}
return {
object: 'trusted_device_challenge',
challenge: challenge.challenge,
challenge_id: challenge.challengeId,
...(challenge.trustedDeviceId ? { trusted_device_id: challenge.trustedDeviceId } : {}),
client_data: challenge.clientData,
expires_at: challenge.expiresAt ? Math.floor(challenge.expiresAt.getTime() / 1000) : 0,
algorithm: challenge.algorithm,
};
}
Loading
Loading