# Asking questions
If you want to ask a question about the use of this plugin, please avoid submmitting an issue and ask on [Discussions] instead.
# Submitting bugs
Create a new issue and please use the template
# Contributing
* Fork
* Create new feature branch (git checkout -b feature-or-fix-something)
* Commit your changes (git commit -am 'Add fix for android ...')
* Push to the branch (git push origin feature-or-fix-something)
* Create new Pull Request with description what you did and why you did it
## Tips
* Please avoid changing the indentation of a complete file in your pull request, because that makes reviewing changes hard
* Use the command `npm test PLATFORM` to run automatic and manual tests first
MIT License
Copyright (c) 2016-2018 Niklas Merz
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.
# Cordova Plugin Fingerprint All-In-One
## For **Android** and **iOS**
[![GitHub license](](
[![Issue Count](](
**This plugin provides a single and simple interface for accessing fingerprint APIs on both Android 6+ and iOS.**
## Features
* Check if a fingerprint scanner is available
* Fingerprint authentication
* Ionic Native support
* Fallback options
* **FaceID** support
* **⚡️ Works with [Capacitor]( [Try it out]( ⚡️**
* [Encrypt and save secrets behind a biometric prompt](#show-authentication-dialogue-and-register-secret)
## Version 4.0
Version 4.0 of this plugin is a significant upgrade over the previous versions. Previous versions only allowed a visual fingerprint prompt. Version 4.0 allows **saving an encrypted secret behind the biometric prompt** for true security. Please test it out and report any issues. If this plugin has security issues please check the [security policy]( If you do audits using this plugin please let me know the results. My email is on my Github profile.
_Version 4 was developed almost 100% by other people than me (@NiklasMerz)._ **Please thank these awesome people for their work: @exxbrain, @leolio86400**. This is a community driven plugin and I don't do any real development anymore. But triaging issues and rewiewing and testing PRs is cumbersome work. If you depend on this plugin for your product please consider becoming my sponsor on Github to keep it going for a while. Some day I may consider stop working on it and pass it on to somebody interested.
**Version 4.0 is awesome so please us it and let us fix it:smile:.**
### Platforms
* Android - Minimum SDK 23
* iOS - **latest XCode** is required. Plugin sets Swift version 4.
* _Please set `<preference name="SwiftVersion" value="5.0" />` in your config.xml_
* Mac via Catalyst. If you run the iOS platform on a Mac the plugin will ask for the user password and work with like on other platforms.
* The [cordova-osx]( platform is not supported
## How to use
**[Tutorial about using this plugin with Ionic](** thanks to Paul Halliday (**old plugin version!!**)
### Install
**Install from NPM**
cordova plugin add cordova-plugin-fingerprint-aio --save
If you want to set a FaceID description use:
cordova plugin add cordova-plugin-fingerprint-aio --variable FACEID_USAGE_DESCRIPTION="Login now...."
**Use the release candidate for testing the latest fixes**
You can use preview versions with the `rc` tag on npm.
cordova plugin add cordova-plugin-fingerprint-aio@rc
**Use this Github repo**
Get the latest development version. *Not recommended!*
cordova plugin add
### Check if fingerprint authentication is available
Fingerprint.isAvailable(isAvailableSuccess, isAvailableError, optionalParams);
function isAvailableSuccess(result) {
result depends on device and os.
iPhone X will return 'face' other Android or iOS devices will return 'finger' Android P+ will return 'biometric'
alert("Fingerprint available");
function isAvailableError(error) {
// 'error' will be an object with an error code and message
### Optional parameters
* __allowBackup (iOS)__: If `true` checks if backup authentication option is available, e.g. passcode. Default: `false`, which means check for biometrics only.
### Show authentication dialogue
description: "Some biometric description"
}, successCallback, errorCallback);
function successCallback(){
alert("Authentication successful");
function errorCallback(error){
alert("Authentication invalid " + error.message);
### Optional parameters
* __title__: Title in authentication dialogue. Default: `"<APP_NAME> Biometric Sign On"`
* __subtitle__: Subtitle in authentication dialogue. Default: `null`
* __description__: Description in authentication dialogue. Defaults:
* iOS: `"Authenticate"` (iOS' [evaluatePolicy()]( requires this field)
* Android: `null`
* __fallbackButtonTitle__: Title of fallback button. Defaults:
* When **disableBackup** is true
* `"Cancel"`
* When **disableBackup** is false
* iOS: `"Use PIN"`
* Android: `"Use Backup"` (Because backup could be anything pin/pattern/password ..haven't figured out a reliable way to determine lock type yet [source](
* __disableBackup__: If `true` remove backup option on authentication dialogue. Default: `false`. This is useful if you want to implement your own fallback.
* __cancelButtonTitle__: For cancel button on Android
* __confirmationRequired__ (**Android**): If `false` user confirmation is NOT required after a biometric has been authenticated . Default: `true`. See [docs](
### Register secret
description: "Some biometric description",
secret: "my-super-secret",
invalidateOnEnrollment: true,
disableBackup: true, // always disabled on Android
}, successCallback, errorCallback);
function successCallback(){
alert("Authentication successful");
function errorCallback(error){
alert("Authentication invalid " + error.message);
This **may** show an authentication prompt.
### Optional parameters
* __title__: Title in authentication dialogue. Default: `"<APP_NAME> Biometric Sign On"`
* __subtitle__: Subtitle in authentication dialogue. Default: `null`
* __description__: Description in authentication dialogue. Defaults:
* iOS: `"Authenticate"` (iOS' [evaluatePolicy()]( requires this field)
* Android: `null`
* __fallbackButtonTitle__: Title of fallback button. Defaults:
* When **disableBackup** is true
* `"Cancel"`
* When **disableBackup** is false
* iOS: `"Use PIN"`
* Android: `"Use Backup"` (Because backup could be anything pin/pattern/password ..haven't figured out a reliable way to determine lock type yet [source](
* __disableBackup__: If `true` remove backup option on authentication dialogue. Default: `false`. This is useful if you want to implement your own fallback. NOTE: it will be disabled on Android
* __cancelButtonTitle__: For cancel button on Android
* __confirmationRequired__ (**Android**): If `false` user confirmation is NOT required after a biometric has been authenticated . Default: `true`. See [docs](
* __secret__: String secret to encrypt and save, use simple strings matching the regex [a-zA-Z0-9\-]+
* __invalidateOnEnrollment__: If `true` secret will be deleted when biometry items are deleted or enrolled
### Show authentication dialogue and load secret
description: "Some biometric description",
disableBackup: true, // always disabled on Android
}, successCallback, errorCallback);
function successCallback(secret){
alert("Authentication successful, secret: " + secret);
function errorCallback(error){
alert("Authentication invalid " + error.message);
### Optional parameters
* __title__: Title in authentication dialogue. Default: `"<APP_NAME> Biometric Sign On"`
* __subtitle__: Subtitle in authentication dialogue. Default: `null`
* __description__: Description in authentication dialogue. Defaults:
* iOS: `"Authenticate"` (iOS' [evaluatePolicy()]( requires this field)
* Android: `null`
* __fallbackButtonTitle__: Title of fallback button. Defaults:
* When **disableBackup** is true
* `"Cancel"`
* When **disableBackup** is false
* iOS: `"Use PIN"`
* Android: `"Use Backup"` (Because backup could be anything pin/pattern/password ..haven't figured out a reliable way to determine lock type yet [source](
* __disableBackup__: If `true` remove backup option on authentication dialogue. Default: `false`. This is useful if you want to implement your own fallback. NOTE: it will be disabled on Android
* __cancelButtonTitle__: For cancel button on Android
* __confirmationRequired__ (**Android**): If `false` user confirmation is NOT required after a biometric has been authenticated . Default: `true`. See [docs](
### Constants
- **BIOMETRIC_LOCKED_OUT** = `-111`;
Thanks to the authors of the original fingerprint plugins
Some code is refactored from their projects and I learned how to make Cordova plugins from their great plugins:
@EddyVerbruggen and @mjwheatley
Starting with version 3.0.0 the iOS and Android parts are written from scratch.
## License
The project is MIT licensed: [MIT](
# Cordova Plugin Fingerprint Aio
# Customized
- Added custom message return to cordova when passcode is locked (IOS).
## Getting started
- biometric dependecy upgrade - build.gradle
upgrade to androidx.biometric:biometric:1.1.0
- Add plugin
cordova plugin add ./apps/showroom-mb/local_plugins/cordova-plugin-fingerprint-aio/5.0.1/cordova-plugin-fingerprint-aio
# Security Policy
>This is side project of me. I only work on it on my free time. I try to do my best to keep this project working securely but I cannot guarantee any stability and security fixes or fixes for future OS version. Please consider the steps below before publishing security related bugs.
## Supported Versions
The latest version of the plugin is the only supported version right now. This might change if breaking changes (like a version 2) is introduced.
The only supported iOS version is the latest stable release. The most used Android versions are covered under a best effort basis.
## Reporting a Vulnerability
If you encounter any security related issues please contact me via the e-mail from my [Github]( profile before publishing it. Just hit me up that you have found a bug. You should use PGP if you want to send sensible information to me but I would prefer to use the Github tools. I will add you to the private discussion to go into detail.
I will create a new security advisory as soon as possible. Security advisories allow us to discuss the issue privatly and work on a solution before releasing any details.
Keybase is another secure channel:
"name": "cordova-plugin-fingerprint-aio",
"version": "5.0.1",
"description": "Cordova plugin to use fingerprint authentication on Android and iOS",
"cordova": {
"id": "cordova-plugin-fingerprint-aio",
"platforms": [
"repository": {
"type": "git",
"url": "git+"
"keywords": [
"author": "Niklas Merz",
"funding": "",
"license": "MIT",
"bugs": {
"url": ""
"homepage": "",
"devDependencies": {
"cordova-plugin-xml": "^0.1.2",
"eslint": "^6.5.1",
"jasmine": "^3.2.0"
"scripts": {
"test": "npm run eslint",
"eslint": "npx eslint www",
"test-travis": "npm run test-ios",
"test-appveyor": "npm run test-browser",
"test-local": "npm run test-browser && npm run test-android && npm run test-ios",
"test-android": "npx cordova-paramedic --platform android --plugin $(pwd) --verbose",
"test-ios": "npx cordova-paramedic --platform ios --plugin $(pwd) --verbose",
"test-windows": "npx cordova-paramedic --platform windows --plugin $(pwd)",
"test-browser": "npx cordova-paramedic --platform browser --plugin $(pwd)",
"test-saucelabs": "npm run test-saucelabs-ios && npm run test-saucelabs-android",
"test-saucelabs-ios": "npx cordova-paramedic --config ./pr/ios-10.0 --plugin $(pwd) --shouldUseSauce",
"test-saucelabs-android": "npx cordova-paramedic --config ./pr/android-7.0 --plugin $(pwd) --shouldUseSauce",
"plugin-version": "cordova-plugin-xml setVersion"
"engines": {
"cordovaDependencies": {
">=3.0.0": {
"cordova-android": ">=8.0.0"
\ No newline at end of file
<?xml version="1.0" encoding="UTF-8"?>
<plugin xmlns="" xmlns:android="" id="cordova-plugin-fingerprint-aio" version="5.0.1">
<description>Cordova plugin to use fingerprint on Android and iOS</description>
<js-module src="www/Fingerprint.js" name="Fingerprint">
<clobbers target="Fingerprint"/>
<!-- ios -->
<platform name="ios">
<header-file src="src/ios/Bridging-Header.h" type="BridgingHeader"/>
<source-file src="src/ios/Fingerprint.swift"/>
<config-file target="config.xml" parent="/*">
<feature name="Fingerprint">
<param name="ios-package" value="Fingerprint"/>
<!-- Usage description of Face ID for iOS 11+ -->
<preference name="FACEID_USAGE_DESCRIPTION" default=" "/>
<config-file target="*-Info.plist" parent="NSFaceIDUsageDescription">
<!-- android -->
<platform name="android">
<config-file target="config.xml" parent="/*">
<platform name="android">
<preference name="AndroidXEnabled" value="true"/>
<config-file target="res/xml/config.xml" parent="/*">
<feature name="Fingerprint">
<param name="android-package" value="de.niklasmerz.cordova.biometric.Fingerprint"/>
<config-file target="AndroidManifest.xml" parent="/*">
<uses-permission android:name="android.permission.USE_BIOMETRIC"/>
<uses-permission android:name="android.permission.USE_FINGERPRINT"/>
<config-file target="AndroidManifest.xml" parent="application">
<activity android:name="de.niklasmerz.cordova.biometric.BiometricActivity" android:theme="@style/TransparentTheme" android:exported="false"/>
<framework src="src/android/build.gradle" custom="true" type="gradleReference"/>
<resource-file src="src/android/res/biometric_activity.xml" target="res/layout/biometric_activity.xml"/>
<resource-file src="src/android/res/styles.xml" target="res/values/biometric-styles.xml"/>
<source-file src="src/android/" target-dir="src/de/niklasmerz/cordova/biometric"/>
<source-file src="src/android/" target-dir="src/de/niklasmerz/cordova/biometric"/>
<source-file src="src/android/" target-dir="src/de/niklasmerz/cordova/biometric"/>
<source-file src="src/android/" target-dir="src/de/niklasmerz/cordova/biometric"/>
<source-file src="src/android/" target-dir="src/de/niklasmerz/cordova/biometric"/>
<source-file src="src/android/" target-dir="src/de/niklasmerz/cordova/biometric"/>
<source-file src="src/android/" target-dir="src/de/niklasmerz/cordova/biometric"/>
<source-file src="src/android/" target-dir="src/de/niklasmerz/cordova/biometric"/>
<source-file src="src/android/" target-dir="src/de/niklasmerz/cordova/biometric"/>
<source-file src="src/android/" target-dir="src/de/niklasmerz/cordova/biometric"/>
<source-file src="src/android/" target-dir="src/de/niklasmerz/cordova/biometric"/>
<engine name="cordova-android" version=">=9.0.0"/>
