Android and iOS

Where to store mobile access tokens

OAuth, passkeys, biometrics, device registration and recovery.

Identity and sessions1 min readEditorial methods

Storage depends on lifetime, background needs and device-loss risk. Plain preferences and protected platform storage offer different properties.

Evaluation approach

Select appropriate Android and iOS mechanisms. Include logs, backups and logout in the same design.

Application example

A short-lived token may remain in memory while a refresh secret needs different handling. Minimize copies.

Limits and considerations

Encrypted storage does not mean the secret is never exposed during use.

What remains while the app runs?

Data must become usable at some point. Limit memory lifetime, logs and background copies, and retain server expiry and revocation controls.

Checks and decisions

  • Limit lifetime
  • Reduce copies
  • Clean up on logout

Sources

The primary references above provide the technical basis. Example workflows and evaluation suggestions are this publication’s explanations, not independent test results for a particular product.