Skip to main content
@capgo/capacitor-app-attest Auth & Security Open source

App Attest Capacitor plugin

Capacitor plugin for cross-platform device attestation using Apple App Attest and Google Play Integrity Standard

Install

bun add @capgo/capacitor-app-attest bunx cap sync
npm, pnpm or yarn
  • npm install @capgo/capacitor-app-attest
  • pnpm add @capgo/capacitor-app-attest
  • yarn add @capgo/capacitor-app-attest

Guide

How to use App Attest in Capacitor

Test on device

Download the Capgo app, then scan the QR code.

App Attest plugin preview QR code

Using @capgo/capacitor-app-attest

Unified cross-platform attestation plugin for Capacitor.

Install

bun add @capgo/capacitor-app-attest
bunx cap sync

What This Plugin Exposes

  • isSupported - Checks whether native attestation is available on this device.
  • prepare - Prepares attestation state and returns the key handle used for later calls.
  • createAttestation - Creates a registration attestation token bound to a backend-issued challenge.
  • createAssertion - Creates a request assertion token bound to a request payload.

Example Usage

isSupported

Checks whether native attestation is available on this device.

import { AppAttestNative } from '@capgo/capacitor-app-attest';

const result = await AppAttestNative.isSupported();
console.log(result);

prepare

Prepares attestation state and returns the key handle used for later calls.

import { AppAttestNative } from '@capgo/capacitor-app-attest';

const result = await AppAttestNative.prepare();
console.log(result);

createAttestation

Creates a registration attestation token bound to a backend-issued challenge.

import { AppAttestNative } from '@capgo/capacitor-app-attest';

const result = await AppAttestNative.createAttestation({
  keyId: 'key-id-123',
  challenge: 'challenge',
});
// The result holds sensitive values: use it without logging it.

createAssertion

Creates a request assertion token bound to a request payload.

import { AppAttestNative } from '@capgo/capacitor-app-attest';

const result = await AppAttestNative.createAssertion({
  keyId: 'key-id-123',
  payload: 'payload',
});
// The result holds sensitive values: use it without logging it.

Full Reference

Keep going from Using @capgo/capacitor-app-attest

If you are using Using @capgo/capacitor-app-attest to plan security and compliance, connect it with @capgo/capacitor-app-attest for the implementation detail in @capgo/capacitor-app-attest, Getting Started for the implementation detail in Getting Started, Encryption for the implementation detail in Encryption, Compliance for the implementation detail in Compliance, and Capgo Security Scanner for the product workflow in Capgo Security Scanner.

FAQ

App Attest plugin FAQ

How do I install the App Attest plugin in a Capacitor app?

Run "bun add @capgo/capacitor-app-attest" (or "npm install @capgo/capacitor-app-attest"), then run "bunx cap sync" so the iOS and Android projects pick up the native code. Import it from "@capgo/capacitor-app-attest" in your app code.

Does @capgo/capacitor-app-attest work with React, Vue and Angular?

Yes. App Attest is a Capacitor package, so it works with any web framework that runs inside Capacitor, including Ionic, React, Vue, Angular, Svelte and plain JavaScript.

Which Capacitor version does @capgo/capacitor-app-attest support?

Capgo plugins follow Capacitor's major version: use the plugin major version that matches your Capacitor major version (for example plugin v8 with Capacitor 8). The compatibility table in the GitHub README lists the maintained versions.

Is @capgo/capacitor-app-attest free and open source?

Yes. The source code is public on GitHub at https://github.com/Cap-go/capacitor-app-attest/ and the package is free to install from npm. Bug reports and pull requests are welcome.

Can I update code that uses App Attest without an App Store review?

Installing or upgrading the plugin changes native code, so it needs a new store build. After that, JavaScript, HTML and CSS changes that call the plugin can ship instantly with Capgo live updates.

Ship App Attest changes without waiting for app review

Once the plugin is in your store build, Capgo live updates push your JavaScript, HTML and CSS changes to users in minutes.

Start with Capgo