Session Storage
This guide covers securely storing and restoring Privacy Boost sessions in React Native, expanding on the persistence options in Key Management.Storage Options
React Native offers several storage options with different security trade-offs:
There are two ways to use the keychain. The SDK can own the vault itself through a
KeychainDelegate you implement in JavaScript, which is the path described next, or the app can export the session and store it with its own code, which the rest of this guide covers.
SDK-Managed Persistence
ImplementKeychainDelegate, register it with registerKeychainDelegate before constructing the SDK, and select persistenceStorage: StorageBackend.OsKeychain plus an unlock method. The delegate stores raw bytes under a key; this one backs it with react-native-keychain, base64-encoding the value because that API stores strings, and keeps one keychain service per key so a biometric-gated item never shares an entry with an unprotected one:
registerKeychainDelegate takes an optional second argument that namespaces the vault items; omit it and the SDK uses its own name. The delegate above already prefixes its own service per key, so it does not need one.
The registration is process-wide: do it before the first PrivacyBoost whose config selects OsKeychain, and note that a later call replaces the delegate for every instance. Construction throws SdkError.ConfigError naming register_keychain_delegate when no delegate is registered; hasKeychainDelegate() tells you whether one is. LocalStorage and IndexedDb are browser backends and are rejected on React Native, as is Passkey unlock.
Unlock methods
Unlocking on the next launch
WithPin or Password, the first launch returns CredentialRequired with challenge.action === CredentialAction.Setup, where the user chooses the credential, and every later launch returns it with CredentialAction.Unlock. submitCredential completes the login either way and can be retried after a wrong credential without calling authenticate again:
logout() and lock(); call deleteVault() to erase it, for example when the user removes the account from the device. Auto-lock below wipes the decrypted keys on a timer and sends the user through this same unlock on the next key access.
Basic: AsyncStorage
The simplest approach, but AsyncStorage is unencrypted. Only suitable for development.Recommended: react-native-keychain
For production apps, usereact-native-keychain to store sessions in the platform’s secure storage (iOS Keychain / Android Keystore).
Install
Session Manager
With Biometric Protection
Add Face ID / fingerprint requirement to access stored sessions:Check Biometric Availability
Usage in a React Native Component
Auto-lock
Auto-lock bounds how long the decrypted keys stay in memory. Two optionalPrivacyBoostConfig fields drive it, both in seconds:
idleTtlSecs: how long the keys may go unused before the SDK wipes them.absoluteTtlSecs: how long after an unlock the SDK wipes them, regardless of activity.
undefined or 0n disables the respective timer, and PrivacyBoostConfig.create() defaults both to undefined. The timers are checked lazily, on the next key access: once one has elapsed, that access zeroizes the resident keys and throws SdkError.NotAuthenticated. They bound key use rather than key residency, so a screen that needs the keys gone at a fixed time should call lock() from its own timer.
lock() does the same on demand. It zeroizes the key material and drops the session JWT but keeps any persisted vault, which makes it the right call when the app moves to the background:
authenticate again. With a persisted vault the SDK reopens it instead of re-deriving keys; without one, authenticate derives them from the wallet signature as on first login. Compare clearSession(), which drops the JWT but leaves the keys in memory for a quick re-auth, and logout(), which ends the session entirely.
Chain-context handles created with createChainContext share the resident keys, so auto-lock and lock() apply to them too, but each keeps its own JWT; call clearSession() on the handle to drop it.
iOS Configuration
Add Face ID usage description toios/YourApp/Info.plist: