requireAuthentication property
Android/iOS/macOS Whether the key requires user authentication at use
time (signing/decryption). Defaults to true.
When false, the key is created without a user-authentication constraint
and can be used to sign/decrypt without any biometric or device-credential
prompt. This is useful for a non-interactive, device-bound key that lives
alongside an interactive (biometric) key under a different keyAlias.
Platform behaviour:
- Android: the keystore key is generated without
setUserAuthenticationRequired(true), and signing/decryption skip theBiometricPrompt. - iOS/macOS: the Secure Enclave key is created with only
.privateKeyUsageaccess control (no.biometryAny/.userPresence) andkSecAttrAccessibleAfterFirstUnlockThisDeviceOnly, so signing never prompts while the device is unlocked. - Windows: ignored — Windows Hello always authenticates.
Security note: a non-interactive key provides device binding ("something you have") only; it does not verify user presence and cannot satisfy inherence-based SCA requirements.
Implementation
bool? requireAuthentication;