keypass_backend library

Trusted adapter/test integration. Each factory invocation owns a fresh backend. Backends are security components, not application authentication callbacks.

Classes

AuthenticatorState
Persisted WebAuthn backup flags and signature-counter verification state.
HardwareConnection
A connection offered by this operation, not an enrolled credential. Return the exact offered object; stale options from other operations fail.
HardwareInteraction
Adapter-internal bundle. Public callers use Keypass.hardware's arguments.
HardwarePinRequest
Keypass
Immutable configuration for verified passkey-derived encryption material. Construction accesses no provider or device. Each call owns its backend; this client needs no disposal.
PasskeyAssertion
Transfers exclusive ownership of secret to the core. It must be a writable 32-byte buffer. The backend clears its own/native copies before completion, and must not retain or use this buffer afterward, including on cancellation.
PasskeyAvailability
Readiness to attempt a ceremony, never proof of a provider's PRF support.
PasskeyBackend
Trusted native integration. All ceremony verification happens here, before returning a binding or secret. Implementations must follow the backend contract, including challenge, RP/origin, credential, signature and UV checks.
PasskeyBinding
Immutable, nonsecret credential metadata. Integrity-protect it with the data it unlocks; deserialization is structural validation, not authentication.
PasskeyCancellation
One-way cancellation signal. Create a new token for each user operation.
PasskeyEvaluationRequest
PasskeyReadiness
Prompt-free attempt readiness, not a guarantee of credential PRF support.
PasskeyRecord
Immutable, nonsecret metadata required to recover a credential's secret. Integrity-protect stored records; decoding does not establish authenticity. v2 system and v3 hardware encodings preserve existing development records.
PasskeyRegistrationRequest
PasskeyResult
Owned temporary secret and its new/updated recovery record. Use try/finally and dispose even if encryption or persistence fails. Successful completion transfers ownership; later cancellation cannot revoke it.
UnavailablePasskeyBackend
Deliberately unavailable until a qualified native adapter is connected.

Enums

HardwareEvent
Informational events. These never prove that authentication succeeded.
HardwareTransport
PasskeyErrorCode
PasskeyRoute
The access route is part of the integrity-protected credential binding.

Functions

bindingFromRecord(PasskeyRecord record) → PasskeyBinding
keypassWithBackendFactory({required PasskeyBackend createBackend(), required String rpId, String? displayName, PasskeyRoute route = PasskeyRoute.system}) → Keypass
Adapter integration only: return a FRESH operation-owned backend each time.
recordFromBinding(PasskeyBinding binding) → PasskeyRecord
Trusted adapter/test conversions; not exported by the consumer library.

Typedefs

HardwareConnectionPicker = Future<HardwareConnection?> Function(List<HardwareConnection> connections, PasskeyCancellation cancellation)
Return an offered connection from this invocation, or null to cancel.
HardwarePinPrompt = Future<Uint8List?> Function(HardwarePinRequest request, PasskeyCancellation cancellation)
Return owned, writable UTF-8 PIN bytes or null to cancel. Keypass clears the bytes, including late replies after cancellation. Close UI on cancellation. PINs are never automatically retried.

Exceptions / Errors

PasskeyException
Stable, redacted error. Raw provider diagnostics are deliberately excluded.