复制安装命令
用 Codex 或 Claude 安装复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它先审查 Skill 页面再帮你安装。
复制前请先查看来源、License 和安全提示。
86 agent skills optimized for iOS 26+ development with Swift 6.
用 Codex 或 Claude 安装复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它先审查 Skill 页面再帮你安装。
复制前请先查看来源、License 和安全提示。
来源文件:README.md
86 agent skills optimized for iOS 26+ development with Swift 6.3 and modern Apple frameworks. All code examples, patterns, and guidance target the latest APIs -- Liquid Glass, approachable concurrency, Foundation Models, StoreKit 2, SwiftData, async/await URLSession, and more. No deprecated patterns.
Compatible with Claude Code, OpenAI Codex, Cursor, GitHub Copilot, and 40+ other agents. Follows the open Agent Skills standard.
Every skill is self-contained. No skill depends on another. Install only what you need.
Release history: CHANGELOG.md.
The skills CLI is the recommended install method.
Interactive install (recommended):
npx skills add dpearson2699/swift-ios-skills
Running the default command opens the skills CLI UI so you can choose which skills to install and which agent(s) to install them for.
Install everything for any coding agent:
npx skills add dpearson2699/swift-ios-skills --all
Use --all when you want the full set of 86 skills installed automatically for any coding agent.
Install specific skills directly:
npx skills add dpearson2699/swift-ios-skills --skill <skill-name> --skill <skill-name>
Check for updates to installed skills:
npx skills check
Update installed skills to the latest versions:
npx skills update
Use these after installing through the skills CLI.
Add the marketplace (one-time):
/plugin marketplace add dpearson2699/swift-ios-skills
Install everything:
/plugin install all-ios-skills@swift-ios-skills
Or install a themed bundle (bundles limit how many skills load into the context window — if you want everything, use all-ios-skills above instead of installing multiple bundles):
/plugin install swiftui-skills@swift-ios-skills
/plugin install swift-core-skills@swift-ios-skills
/plugin install ios-app-framework-skills@swift-ios-skills
/plugin install ios-data-framework-skills@swift-ios-skills
/plugin install ios-ai-ml-skills@swift-ios-skills
/plugin install ios-engineering-skills@swift-ios-skills
/plugin install ios-hardware-skills@swift-ios-skills
/plugin install ios-platform-skills@swift-ios-skills
/plugin install ios-gaming-skills@swift-ios-skills
/plugin install apple-kit-skills@swift-ios-skills
$skill-installer install https://github.com/dpearson2699/swift-ios-skills/tree/main/skills/<skill-name>
| Plugin | Skills included |
|---|---|
| all-ios-skills | All 86 skills |
| apple-kit-skills | 39 skills spanning Apple Kit frameworks plus CarPlay |
| swiftui-skills | focus-engine, swiftui-animation, swiftui-gestures, swiftui-layout-components, swiftui-liquid-glass, swiftui-navigation, swiftui-patterns, swiftui-performance, swiftui-uikit-interop, swiftui-webkit |
| swift-core-skills | core-data, swift-api-design-guidelines, swift-architecture, swift-codable, swift-charts, swift-concurrency, swift-formatstyle, swift-language, swift-testing, swiftdata |
| ios-app-framework-skills | activitykit, adattributionkit, alarmkit, app-clips, app-intents, avkit, carplay, mapkit, paperkit, pdfkit, photokit, push-notifications, storekit, tipkit, widgetkit |
| ios-data-framework-skills | cloudkit, contacts-framework, eventkit, financekit, healthkit, musickit, passkit, weatherkit |
| ios-ai-ml-skills | apple-on-device-ai, coreml, natural-language, speech-recognition, vision-framework |
| ios-engineering-skills | app-store-optimization, app-store-review, authentication, background-processing, cryptokit, debugging-instruments, device-integrity, ios-accessibility, ios-ettrace-performance, ios-localization, ios-memgraph-analysis, ios-networking, swift-security, swiftlint, ios-simulator, metrickit |
| ios-hardware-skills | accessorysetupkit, core-bluetooth, core-motion, core-nfc, dockkit, pencilkit, realitykit, sensorkit |
| ios-platform-skills | appmigrationkit, audioaccessorykit, browserenginekit, callkit, cryptotokenkit, energykit, homekit, permissionkit, relevancekit, shareplay-activities |
| ios-gaming-skills | gamekit, scenekit, spritekit, tabletopkit |
| Skill | What it covers |
|---|---|
| focus-engine | @FocusState, defaultFocus, focusSection, focused scene values, focus restoration, UIFocusGuide |
| swiftui-animation | Spring animations, PhaseAnimator, KeyframeAnimator, matchedGeometryEffect, SF Symbols |
| swiftui-gestures | Tap, drag, magnify, rotate, long press, simultaneous and sequential gestures |
| swiftui-layout-components | Grid, LazyVGrid, Layout protocol, ViewThatFits, custom layouts |
| swiftui-liquid-glass | iOS 26 Liquid Glass, glassEffect, GlassEffectContainer, morphing transitions |
| swiftui-navigation | NavigationStack, NavigationSplitView, programmatic navigation, deep linking |
| swiftui-patterns | @Observable, state ownership, environment wiring, view composition, async loading, MV-pattern architecture |
| swiftui-performance | Rendering performance, view update optimization, layout thrash, Instruments profiling |
| swiftui-uikit-interop | UIViewRepresentable, UIHostingController, Coordinator, incremental UIKit-to-SwiftUI migration |
| swiftui-webkit | WebView, WebPage, navigation policies, JavaScript calls, local content, custom URL schemes |
| Skill | What it covers |
|---|---|
| swift-api-design-guidelines | Swift API Design Guidelines -- argument labels, mutating/nonmutating pairs, documentation comments, naming conventions |
| swift-architecture | Architecture patterns: MV (@Observable), MVVM, MVI, TCA, Clean Architecture, Coordinator, decision framework |
| swift-codable | Swift Codable, JSONDecoder, JSONEncoder, CodingKeys, custom decoding, nested JSON |
| swift-charts | Bar, line, area, pie, donut, and 3D charts, scrolling, selection, annotations |
| swift-concurrency | Swift 6.2 concurrency, Sendable, actors, structured concurrency, data-race safety |
| swift-formatstyle | FormatStyle protocol, number/currency/date/duration/measurement formatting, custom styles |
| swift-language | Swift 6.3 language idioms, result builders, property wrappers, typed throws |
| swift-testing | Swift Testing framework, @Test, @Suite, #expect, parameterized tests, mocking |
| core-data | Core Data persistence, NSPersistentContainer, NSFetchedResultsController, batch operations, staged migration |
| swiftdata | @Model, @Query, #Predicate, ModelContainer, migrations, CloudKit sync, @ModelActor |
| Skill | What it covers |
|---|---|
| activitykit | ActivityKit, Dynamic Island, Lock Screen Live Activities, push-to-update |
| adattributionkit | Privacy-preserving ad attribution, postbacks, conversion values, re-engagement |
| alarmkit | AlarmKit system alarms and countdown timers, Lock Screen, Dynamic Island, Live Activities |
| app-clips | App Clips, invocation URLs, NFC, QR, App Clip Codes, App Group handoff |
| app-intents | App Intents for Siri, Shortcuts, Spotlight, widgets, and Apple Intelligence |
| avkit | AVPlayerViewController, VideoPlayer, Picture-in-Picture, AirPlay, subtitles |
| carplay | CarPlay templates, navigation, audio, communication, EV charging apps |
| mapkit | MapKit, CoreLocation, annotations, geocoding, directions, geofencing |
| paperkit | PaperMarkupViewController, markup editing, drawing, shapes (iOS 26) |
| pdfkit | PDFView, PDFDocument, annotations, text search, form filling, thumbnails |
| photokit | PhotosPicker, AVCaptureSession, photo library, video recording, media permissions |
| push-notifications | UNUserNotificationCenter, APNs, rich notifications, silent push, service extensions |
| storekit | StoreKit 2 purchases, subscriptions, SubscriptionStoreView, transaction verification |
| tipkit | Feature discovery tooltips, contextual tips, tip rules, tip events |
| widgetkit | Home Screen, Lock Screen, and StandBy widgets, Control Center controls, timeline providers |
| Skill | What it covers |
|---|---|
| cloudkit | CKContainer, CKRecord, subscriptions, sharing, CKSyncEngine, SwiftData sync |
| contacts-framework | CNContactStore, fetch requests, key descriptors, CNContactPickerViewController, save requests |
| eventkit | EKEventStore, EKEvent, EKReminder, recurrence rules, EventKitUI editors and choosers |
| financekit | Apple Card, Apple Cash, Wallet orders, transaction queries, account balances |
| healthkit | HKHealthStore, queries, statistics, workout sessions, background delivery |
| musickit | MusicKit authorization, catalog search, ApplicationMusicPlayer, MPRemoteCommandCenter |
| passkit | Apple Pay, PKPaymentRequest, PKPaymentAuthorizationController, Wallet passes |
| weatherkit | WeatherService, current/hourly/daily forecasts, alerts, attribution requirements |
| Skill | What it covers |
|---|---|
| apple-on-device-ai | Foundation Models framework, Core ML, MLX Swift, on-device LLM inference |
| coreml | Core ML model loading, prediction, MLTensor, compute unit configuration, VNCoreMLRequest, MLComputePlan |
| natural-language | NLTokenizer, NLTagger, sentiment analysis, language identification, embeddings, Translation |
| speech-recognition | SpeechAnalyzer, SpeechTranscriber, SFSpeechRecognizer, on-device recognition, audio buffer processing |
| vision-framework | Vision text recognition, face/barcode detection, image segmentation, VisionKit DataScannerViewController |
| Skill | What it covers |
|---|---|
| app-store-optimization | ASO keyword strategy, description writing, screenshot optimization, Custom Product Pages, A/B testing |
| app-store-review | App Review guidelines, rejection prevention, privacy manifests, ATT, HIG compliance |
| authentication | Sign in with Apple, ASAuthorizationController, passkeys, biometric auth (LAContext), credential management |
| background-processing | BGTaskScheduler, background refresh, URLSession background transfers |
| cryptokit | SHA-2/SHA-3, HMAC, AES-GCM, ChaChaPoly, HPKE, ML-KEM/ML-DSA, P256/Curve25519 signing, ECDH, Secure Enclave |
| debugging-instruments | Xcode debugger, Instruments, os_signpost, MetricKit, crash symbolication |
| device-integrity | DeviceCheck (DCDevice per-device bits), App Attest (DCAppAttestService attestation and assertion flows) |
| ios-accessibility | VoiceOver, Dynamic Type, custom rotors, accessibility focus, assistive-technology support |
| ios-ettrace-performance | ETTrace launch/runtime capture, exact-build dSYM matching, processed flamegraph JSON, comparable verification |
| ios-localization | String Catalogs, pluralization, FormatStyle, right-to-left layout |
| ios-memgraph-analysis | Simulator memgraph capture, leak ownership paths, reachable heap growth, raw evidence preservation |
| ios-networking | URLSession async/await, REST APIs, downloads/uploads, WebSockets, pagination, retry, caching |
| swift-security | Keychain Services, CryptoKit symmetric/asymmetric, biometric authentication, Secure Enclave, certificate trust, credential storage, OWASP compliance · Based on ivan-magda/swift-security-skill |
| ios-simulator | xcrun simctl commands, device lifecycle, push/location/privacy simulation, log streaming, simulator limitations |
| metrickit | MetricManager async reports, hang/crash diagnostics, production performance telemetry |
| swiftlint | SwiftLint setup, .swiftlint.yml, build tool plugin, rule selection, baselines, suppressions, CI integration |
| Skill | What it covers |
|---|---|
| accessorysetupkit | Privacy-preserving BLE/Wi-Fi accessory discovery, ASAccessorySession, picker UI |
| core-bluetooth | CBCentralManager, CBPeripheral, BLE scanning/connecting, services, characteristics, background modes |
| core-motion | CMMotionManager, CMPedometer, accelerometer, gyroscope, activity recognition, altitude |
| core-nfc | NFCNDEFReaderSession, NFCTagReaderSession, NDEF reading/writing, background tag reading |
| dockkit | DockAccessoryManager, camera subject tracking, motor control, framing |
| pencilkit | PKCanvasView, PKDrawing, PKToolPicker, Apple Pencil drawing and annotation |
| realitykit | RealityView, entities, anchors, ARKit world tracking, raycasting, scene understanding |
| sensorkit | Research-grade sensor data, ambient light, keyboard metrics, device usage (approved studies) |
| Skill | What it covers |
|---|---|
| appmigrationkit | Cross-platform data transfer, AppMigrationExtension export/import (iOS 26) |
| audioaccessorykit | Audio accessory features, automatic switching, device placement (iOS 26.4) |
| browserenginekit | Alternative browser engines (EU), process management, web content extensions |
| callkit | CXProvider, CXCallController, PushKit VoIP registration, call directory extensions |
| cryptotokenkit | TKTokenDriver, TKSmartCard, iOS 26 NFC smart cards, certificate-based auth |
| energykit | ElectricityGuidance, EnergyVenue, grid forecasts, load event submission, electricity insights |
| homekit | HMHomeManager, accessories, rooms, actions, triggers, MatterSupport commissioning |
| permissionkit | AskCenter, PermissionQuestion, child communication safety, CommunicationLimits |
| relevancekit | Widget relevance signals, time/location-based relevance providers (watchOS 26) |
| shareplay-activities | GroupActivity, GroupSession, GroupSessionMessenger, coordinated media playback |
| Skill | What it covers |
|---|---|
| gamekit | Game Center, GKLocalPlayer, leaderboards, achievements, real-time and turn-based multiplayer |
| scenekit | SCNView, SCNScene, 3D geometry, materials, lighting, physics, SceneView |
| spritekit | SKScene, SKSpriteNode, SKAction, physics simulation, particle effects, SpriteView |
| tabletopkit | Multiplayer spatial board games, pieces, cards, dice, Group Activities (visionOS) |
Each skill follows the open Agent Skills standard:
skills/
skill-name/
SKILL.md # Required — instructions and metadata
references/ # Optional — detailed reference material
some-topic.md
SKILL.md contains YAML frontmatter (name, description) and markdown instructions. The references/ folder holds longer examples, advanced patterns, and lookup tables that the main file points to.
This repository contains original instructional content and examples for Apple platform development. Where Apple frameworks, APIs, documentation, WWDC sessions, or trademarks are referenced, those materials remain the property of Apple Inc. The license for this repository applies to this project's original content only and does not claim ownership of or relicense Apple's documentation, trademarks, sample code, or other third-party materials.
These skills work with any agent that supports the Agent Skills standard, including:
v3.0 is a major release. If you previously installed v2.x skills, note the following changes:
Skill count: 57 skills in v2.2.0, 76 skills in v3.0.0.
Skill renames: 12 existing skills renamed to use Apple Kit framework names. Old skill paths no longer resolve. Uninstall all skills and reinstall to upgrade.
| v2.x name | v3.0 name |
|---|---|
live-activities | activitykit |
mapkit-location | mapkit |
photos-camera-media | photokit |
homekit-matter | homekit |
callkit-voip | callkit |
metrickit-diagnostics | metrickit |
pencilkit-drawing | pencilkit |
passkit-wallet | passkit |
musickit-audio | musickit |
cloudkit-sync | cloudkit |
eventkit-calendar | eventkit |
realitykit-ar | realitykit |
19 new Kit framework skills: avkit, gamekit, cryptokit, pdfkit, paperkit, spritekit, scenekit, financekit, accessorysetupkit, adattributionkit, carplay, appmigrationkit, browserenginekit, dockkit, sensorkit, tabletopkit, relevancekit, audioaccessorykit, cryptotokenkit.
New bundles: apple-kit-skills (all 39 Apple Kit framework skills) and ios-gaming-skills (GameKit, SpriteKit, SceneKit, TabletopKit).
PaperKit standalone: PaperKit content removed from pencilkit and is now its own paperkit skill.
Beta frameworks: permissionkit, energykit, paperkit, relevancekit, appmigrationkit, and audioaccessorykit require iOS/watchOS 26 beta and are subject to API changes before GM.
All skills remain self-contained: No skill references or depends on another.
To upgrade via the skills CLI:
npx skills add dpearson2699/swift-ios-skills
To upgrade Claude Code bundles, reinstall the bundles you use (old skill paths will no longer resolve).
If these skills save you time or improve your workflow, you can support ongoing maintenance through GitHub Sponsors.
Support helps keep the collection current with new Apple releases, evolving framework APIs, updated examples, and compatibility work across Claude Code, Codex, Cursor, Copilot, and other agents.
Thanks to the following people for supporting this project:
PolyForm Perimeter 1.0.0 -- see LICENSE
What this means in practice:
This project is not affiliated with, endorsed by, or sponsored by Apple Inc.
name: device-integrity
description: "Verify device legitimacy and app integrity using DeviceCheck (DCDevice per-device bits) and App Attest (DCAppAttestService key generation, attestation, and assertion flows). Use when implementing fraud prevention, detecting compromised devices, validating app authenticity with Apple's servers, protecting sensitive API endpoints with attested requests, or adding device verification to a backend architecture."Verify that requests to your server come from a genuine Apple device running a legitimate instance of your app. DeviceCheck provides per-device bits for simple flags (e.g., "claimed promo offer"). App Attest uses Secure Enclave keys and Apple attestation to cryptographically prove app legitimacy on sensitive requests.
DCDevice generates a
unique, ephemeral token that identifies a device. Treat each token as
single-use: generate a new token for each server operation instead of caching or
reusing one. The token is sent to your server, which then communicates with
Apple's servers to read or set two per-device bits. Available on iOS 11+.
import DeviceCheck
func generateDeviceToken() async throws -> Data {
guard DCDevice.current.isSupported else {
throw DeviceIntegrityError.deviceCheckUnsupported
}
return try await DCDevice.current.generateToken()
}
func sendTokenToServer(_ token: Data) async throws {
let tokenString = token.base64EncodedString()
var request = URLRequest(url: serverURL.appending(path: "verify-device"))
request.httpMethod = "POST"
request.setValue("application/json", forHTTPHeaderField: "Content-Type")
request.httpBody = try JSONEncoder().encode(["device_token": tokenString])
let (_, response) = try await URLSession.shared.data(for: request)
guard let httpResponse = response as? HTTPURLResponse,
httpResponse.statusCode == 200 else {
throw DeviceIntegrityError.serverVerificationFailed
}
}
The server exchanges each fresh token with Apple's authenticated DeviceCheck API. Load DeviceCheck Server Endpoints for endpoint and environment details.
Apple stores two Boolean values per device per developer team. You decide what they mean. Common uses:
Bits persist across app reinstall. You control when to reset them via the server API.
DCAppAttestService
validates that a specific instance of your app on a specific device is
legitimate. It uses a hardware-backed key in the Secure Enclave to create
cryptographic attestations and assertions. Available on iOS 14+.
The flow has three phases:
import DeviceCheck
let attestService = DCAppAttestService.shared
guard attestService.isSupported else {
// Fall back to DCDevice token or other risk assessment.
// App Attest is not available on simulators or all device models.
return
}
For app extensions, App Attest is supported only in Action, extensible SSO, and
watchOS extensions. Treat other extension types as unsupported even if
isSupported returns true.
Generate one cryptographic key pair per user account on each device. The
private key stays in the Secure Enclave. The returned keyId is the only
identifier your app can later use to access the key, so record and reuse the
account/device-scoped keyId; do not share one key across users. Avoid
unnecessary regeneration because each new key affects App Attest key-count risk
metrics. Only treat the keyId as usable after your server verifies
attestation. If server verification fails, discard the keyId and generate a
new key before retrying.
import DeviceCheck
actor AppAttestManager {
private let service = DCAppAttestService.shared
private var keyId: String?
/// Generate and record a key pair for App Attest.
func generateKeyIfNeeded() async throws -> String {
if let existingKeyId = loadKeyIdFromKeychain() {
self.keyId = existingKeyId
return existingKeyId
}
let newKeyId = try await service.generateKey()
saveKeyIdToKeychain(newKeyId)
self.keyId = newKeyId
return newKeyId
}
// MARK: - Keychain helpers (simplified)
private func saveKeyIdToKeychain(_ keyId: String) {
let data = Data(keyId.utf8)
let query: [String: Any] = [
kSecClass as String: kSecClassGenericPassword,
kSecAttrAccount as String: "app-attest-key-id-\(currentAccountID)",
kSecAttrService as String: Bundle.main.bundleIdentifier ?? "",
kSecValueData as String: data,
kSecAttrAccessible as String: kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly
]
SecItemDelete(query as CFDictionary) // Remove old if exists
SecItemAdd(query as CFDictionary, nil)
}
private func loadKeyIdFromKeychain() -> String? {
let query: [String: Any] = [
kSecClass as String: kSecClassGenericPassword,
kSecAttrAccount as String: "app-attest-key-id-\(currentAccountID)",
kSecAttrService as String: Bundle.main.bundleIdentifier ?? "",
kSecReturnData as String: true,
kSecMatchLimit as String: kSecMatchLimitOne
]
var result: AnyObject?
let status = SecItemCopyMatching(query as CFDictionary, &result)
guard status == errSecSuccess, let data = result as? Data else { return nil }
return String(data: data, encoding: .utf8)
}
}
Attestation proves that the key was generated on a genuine Apple device running
a legitimate instance of your app. You perform attestation once per key, then
store the verified public key and receipt on your server. The app stores the
keyId for future assertions after the server accepts the attestation.
import DeviceCheck
import CryptoKit
extension AppAttestManager {
/// Attest the key with Apple. Send the attestation object to your server.
func attestKey() async throws -> Data {
guard let keyId else {
throw DeviceIntegrityError.keyNotGenerated
}
// 1. Request a one-time challenge from your server
let challenge = try await fetchServerChallenge()
// 2. Hash the challenge (Apple requires a SHA-256 hash)
let challengeHash = Data(SHA256.hash(data: challenge))
// 3. Ask Apple to attest the key
let attestation = try await service.attestKey(keyId, clientDataHash: challengeHash)
// 4. Send the attestation object to your server for verification
try await sendAttestationToServer(
keyId: keyId,
attestation: attestation,
challenge: challenge
)
return attestation
}
private func fetchServerChallenge() async throws -> Data {
let url = serverURL.appending(path: "attest/challenge")
let (data, _) = try await URLSession.shared.data(from: url)
return data
}
private func sendAttestationToServer(
keyId: String,
attestation: Data,
challenge: Data
) async throws {
var request = URLRequest(url: serverURL.appending(path: "attest/verify"))
request.httpMethod = "POST"
request.setValue("application/json", forHTTPHeaderField: "Content-Type")
let payload: [String: String] = [
"key_id": keyId,
"attestation": attestation.base64EncodedString(),
"challenge": challenge.base64EncodedString()
]
request.httpBody = try JSONEncoder().encode(payload)
let (_, response) = try await URLSession.shared.data(for: request)
guard let httpResponse = response as? HTTPURLResponse,
httpResponse.statusCode == 200 else {
throw DeviceIntegrityError.attestationVerificationFailed
}
}
}
The server must verify the attestation before the client treats keyId as usable,
then store the verified public key and receipt. Load
Server-Side Attestation Verification
for the certificate, App ID, environment, counter, credential, and nonce checks.
After attestation, use assertions to sign sensitive requests. Each assertion proves the request came from the attested app instance and includes a server-issued, one-time challenge to prevent replay.
import DeviceCheck
import CryptoKit
extension AppAttestManager {
/// Generate an assertion for encoded client data.
/// Client data should include a one-time server challenge and request context.
func generateAssertion(for clientData: Data) async throws -> Data {
guard let keyId else {
throw DeviceIntegrityError.keyNotGenerated
}
let clientDataHash = Data(SHA256.hash(data: clientData))
return try await service.generateAssertion(keyId, clientDataHash: clientDataHash)
}
}
struct AppAttestClientData: Encodable {
let challenge: String
let method: String
let path: String
let bodySHA256: String
}
extension AppAttestManager {
/// Perform an attested API request.
func makeAttestedRequest(
to url: URL,
method: String = "POST",
body: Data
) async throws -> (Data, URLResponse) {
let challenge = try await fetchAssertionChallenge()
let bodyHash = Data(SHA256.hash(data: body)).base64EncodedString()
let clientData = try JSONEncoder().encode(
AppAttestClientData(
challenge: challenge,
method: method,
path: url.path,
bodySHA256: bodyHash
)
)
let assertion = try await generateAssertion(for: clientData)
var request = URLRequest(url: url)
request.httpMethod = method
request.setValue("application/json", forHTTPHeaderField: "Content-Type")
request.setValue(assertion.base64EncodedString(), forHTTPHeaderField: "X-App-Attest-Assertion")
request.setValue(clientData.base64EncodedString(), forHTTPHeaderField: "X-App-Attest-Client-Data")
request.httpBody = body
return try await URLSession.shared.data(for: request)
}
private func fetchAssertionChallenge() async throws -> String {
let url = serverURL.appending(path: "assert/challenge")
let (data, _) = try await URLSession.shared.data(from: url)
return String(decoding: data, as: UTF8.self)
}
}
The server must verify each assertion's signature, RP ID, counter, one-time challenge, and request binding before authorizing the request. Load Server-Side Assertion Verification for the complete algorithm.
See references/device-integrity-patterns.md for full server architecture guidance including attestation vs. assertion comparison, recommended endpoint design, and risk assessment.
App Attest proves app-instance integrity for selected requests. It does not replace user authentication, OAuth/JWT/session handling, API token design, entitlement or subscription authorization, TLS, certificate pinning, or general networking security. Treat those as handoffs to authentication, networking, or broader security guidance, and still enforce normal authentication and authorization after App Attest passes.
Handle DCError codes from DeviceCheck operations. Key cases:
.serverUnavailable — retry with exponential backoff.invalidKey — the key was already attested, assertion used an unattested key, or the service rejected the key.featureUnsupported — fall back to DCDevice tokens.invalidInput — malformed clientDataHash or keyIdFor attestKey, retry .serverUnavailable later with the same keyId and the
same clientDataHash. For other attestation errors, discard the key identifier
and create a new key before retrying. See
references/device-integrity-patterns.md
for full error handling code, retry strategy, and rejected-key recovery.
Set the App Attest environment in your entitlements file. Use development
during testing and production for App Store builds. Load
Environment Entitlement
for the XML, default sandbox behavior, distribution behavior, and extension limits.
See references/device-integrity-patterns.md for the full integration manager pattern, gradual rollout guidance, and error type definition.
keyId, and keep key counts low.DCDevice tokens. Treat generated tokens as single-use. Generate a new token for each server operation.DCDevice tokens or other risk assessment as fallback.SHA256(authData || SHA256(challenge)), not SHA256(challenge) alone.DCError.invalidKey. Check for repeated attestation, unattested assertion keys, or service rejection; regenerate only after the state is known bad.DCDevice tokens generated per server operation and never cached for reuseDCAppAttestService.isSupported checked before use; unsupported devices and extension types have a fallbackkeyId persisted only for that app account/deviceaaguid, credential ID, and nonce SHA256(authData || SHA256(challenge))DCError cases handled: .serverUnavailable retries attestation with the same key/hash; bad keys are discarded and regenerated
评论 (0)
暂无评论,成为第一个评论者吧!