Join 5,000+ subscribers getting weekly tips on web development, mobile apps, and AI solutions.
The Android system service that creates cryptographic keys and uses them on an app's behalf without ever giving the app the raw key.
Keystore keys can be tied to secure hardware, either a trusted execution environment or a dedicated chip called StrongBox. Apps hold only a handle: they can ask Keystore to encrypt, decrypt or sign, but cannot read the key out. That stops key theft but not misuse: code running as the app, for example malware on a rooted phone, can still ask Keystore to use a key. A key can also be set to require a fresh biometric check for every use, as HostSpica Passkey does for passkey signatures.
A discoverable WebAuthn credential that lets you sign in to a site with a fingerprint, face or screen lock instead of a password.
Evidence provided at registration about the authenticator that created a key, such as a certificate chain showing the key lives in secure hardware.
A separate tamper-resistant secure chip in some Android phones that can store keys and perform cryptography apart from the main processor.
A key derivation function that turns a password into an encryption key by repeating a hash many thousands of times, making each guess slow.
Our expert team can help you leverage Android Keystore in your project.
Get Free Consultation