Android and iOS

Is local biometrics proof of identity to a server?

OAuth, passkeys, biometrics, device registration and recovery.

Identity and sessions1 min readEditorial methods

Local biometrics authenticates interaction with the device user. A client-supplied success field is not sufficient account evidence.

Evaluation approach

Bind local verification to suitable key operations and server challenges where required. Preserve server authorization.

Application example

Even after biometric success, a transfer's recipient and amount must match the approved content.

Limits and considerations

A modifiable boolean cannot support lasting financial authority.

How should biometric flows be tested?

Check more than the screen: verify the key operation, challenge match and approved business content separately.

Checks and decisions

  • Separate local and remote evidence
  • Bind transactions
  • Authorize server-side

Sources

The primary references above provide the technical basis. Example workflows and evaluation suggestions are this publication’s explanations, not independent test results for a particular product.