Skip to content

Getting Started

GitHub

You can use our AI-Assisted Setup to install the plugin. Add the Capgo skills to your AI tool using the following command:

Terminal window
npx skills add https://github.com/Cap-go/capgo-skills --skill capacitor-plugins

Then use the following prompt:

Use the `capacitor-plugins` skill from `Cap-go/capgo-skills` to install the `@capgo/capacitor-device-integrity` plugin in my project.

If you prefer Manual Setup, install the plugin by running the following commands and follow the platform-specific instructions below:

  1. Install the package

    Terminal window
    bun add @capgo/capacitor-device-integrity
  2. Sync native projects

    Terminal window
    bunx cap sync
  3. Configure platform requirements

    • Android: set plugins.DeviceIntegrity.cloudProjectNumber for Play Integrity when you use attestation APIs.
    • iOS: enable the App Attest capability in Xcode for attestation APIs.

Use one API to collect integrity signals during sign-up, login, or high-risk actions:

  • Probe support before calling native APIs (getCapabilities)
  • Fingerprint Android devices with Widevine (getWidevineFingerprint)
  • Register and assert with App Attest or Play Integrity (prepareAttestation, createAttestation, createAssertion)
  • Request iOS DeviceCheck tokens (getDeviceCheckToken)

Client values are not trustworthy until your backend verifies tokens and enforces replay protection.

import { DeviceIntegrity } from '@capgo/capacitor-device-integrity';
const capabilities = await DeviceIntegrity.getCapabilities();
console.log(capabilities.platform, capabilities.playIntegrity.supported);
if (capabilities.widevine.fingerprintAvailable) {
const widevine = await DeviceIntegrity.getWidevineFingerprint();
console.log(widevine.fingerprint, widevine.securityLevel);
}
const prepared = await DeviceIntegrity.prepareAttestation();
const registration = await DeviceIntegrity.createAttestation({
keyId: prepared.keyId,
challenge: 'backend-one-time-registration-challenge',
});
const assertion = await DeviceIntegrity.createAssertion({
keyId: prepared.keyId,
payload: 'backend-one-time-request-payload',
});
console.log(registration.format, registration.token);
console.log(assertion.format, assertion.token);
if (capabilities.deviceCheck.supported) {
const deviceCheck = await DeviceIntegrity.getDeviceCheckToken();
console.log(deviceCheck.token);
}

getWidevineFingerprint() accepts optional fields:

FieldTypeDescription
includeRawIdbooleanWhen true, includes base64 raw Widevine device ID (sensitive).
hashSaltstringSalt for fingerprint. Android uses the app package name when omitted.
  • Verify App Attest and Play Integrity tokens on your server.
  • Treat Widevine identifiers as sensitive and disclose use in your privacy policy.
  • Do not use Widevine values for advertising or cross-app tracking.

If you are using Getting Started to plan security and compliance, connect it with Using @capgo/capacitor-device-integrity for the native capability in Using @capgo/capacitor-device-integrity, @capgo/capacitor-app-attest for focused App Attest and Play Integrity flows, Encryption for the implementation detail in Encryption, Compliance for the implementation detail in Compliance, and Capgo Security for the product workflow in Capgo Security.