Getting Started
Copy a setup prompt with the install steps and the full markdown guide for this plugin.
Set up this Capacitor plugin in the project.
Use the package manager already used by the project.
Install these package(s): `@capgo/capacitor-device-integrity`
Run the required Capacitor sync/update step after installation.
Read this markdown guide for the full setup steps: https://raw.githubusercontent.com/Cap-go/website/refs/heads/main/apps/docs/src/content/docs/docs/plugins/device-integrity/getting-started.mdx
Use that guide for platform-specific steps, native file edits, permissions, config changes, imports, and usage setup.
If that guide references other docs pages, read them too.
Installation
Section titled “Installation”You can use our AI-Assisted Setup to install the plugin. Add the Capgo skills to your AI tool using the following command:
npx skills add https://github.com/Cap-go/capgo-skills --skill capacitor-pluginsThen use the following prompt:
Use the `capacitor-plugins` skill from `Cap-go/capgo-skills` to install the `@capgo/capacitor-device-integrity` plugin in my project.If you prefer Manual Setup, install the plugin by running the following commands and follow the platform-specific instructions below:
-
Install the package
Terminal window bun add @capgo/capacitor-device-integrity -
Sync native projects
Terminal window bunx cap sync -
Configure platform requirements
- Android: set
plugins.DeviceIntegrity.cloudProjectNumberfor Play Integrity when you use attestation APIs. - iOS: enable the App Attest capability in Xcode for attestation APIs.
- Android: set
Why use this plugin
Section titled “Why use this plugin”Use one API to collect integrity signals during sign-up, login, or high-risk actions:
- Probe support before calling native APIs (
getCapabilities) - Fingerprint Android devices with Widevine (
getWidevineFingerprint) - Register and assert with App Attest or Play Integrity (
prepareAttestation,createAttestation,createAssertion) - Request iOS DeviceCheck tokens (
getDeviceCheckToken)
Client values are not trustworthy until your backend verifies tokens and enforces replay protection.
import { DeviceIntegrity } from '@capgo/capacitor-device-integrity';
const capabilities = await DeviceIntegrity.getCapabilities();console.log(capabilities.platform, capabilities.playIntegrity.supported);
if (capabilities.widevine.fingerprintAvailable) { const widevine = await DeviceIntegrity.getWidevineFingerprint(); console.log(widevine.fingerprint, widevine.securityLevel);}
const prepared = await DeviceIntegrity.prepareAttestation();
const registration = await DeviceIntegrity.createAttestation({ keyId: prepared.keyId, challenge: 'backend-one-time-registration-challenge',});
const assertion = await DeviceIntegrity.createAssertion({ keyId: prepared.keyId, payload: 'backend-one-time-request-payload',});
console.log(registration.format, registration.token);console.log(assertion.format, assertion.token);
if (capabilities.deviceCheck.supported) { const deviceCheck = await DeviceIntegrity.getDeviceCheckToken(); console.log(deviceCheck.token);}Widevine options
Section titled “Widevine options”getWidevineFingerprint() accepts optional fields:
| Field | Type | Description |
|---|---|---|
includeRawId | boolean | When true, includes base64 raw Widevine device ID (sensitive). |
hashSalt | string | Salt for fingerprint. Android uses the app package name when omitted. |
Backend requirement
Section titled “Backend requirement”- Verify App Attest and Play Integrity tokens on your server.
- Treat Widevine identifiers as sensitive and disclose use in your privacy policy.
- Do not use Widevine values for advertising or cross-app tracking.
Keep going from Getting Started
Section titled “Keep going from Getting Started”If you are using Getting Started to plan security and compliance, connect it with Using @capgo/capacitor-device-integrity for the native capability in Using @capgo/capacitor-device-integrity, @capgo/capacitor-app-attest for focused App Attest and Play Integrity flows, Encryption for the implementation detail in Encryption, Compliance for the implementation detail in Compliance, and Capgo Security for the product workflow in Capgo Security.