SkillAtlasSkill 详情

device-integrity

86 agent skills optimized for iOS 26+ development with Swift 6.

审核状态:已审核Quality 72Security 78

复制安装命令

用 Codex 或 Claude 安装复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它先审查 Skill 页面再帮你安装。

复制前请先查看来源、License 和安全提示。

项目 README

来源文件:README.md

抓取于 2026年8月22日

Swift iOS Skills — Agent Skills for iOS 26+ & SwiftUI Development

GitHub stars Swift 6.3 Platform Claude Code OpenAI Codex Agent Skills tessl License: PolyForm Perimeter

86 agent skills optimized for iOS 26+ development with Swift 6.3 and modern Apple frameworks. All code examples, patterns, and guidance target the latest APIs -- Liquid Glass, approachable concurrency, Foundation Models, StoreKit 2, SwiftData, async/await URLSession, and more. No deprecated patterns.

Compatible with Claude Code, OpenAI Codex, Cursor, GitHub Copilot, and 40+ other agents. Follows the open Agent Skills standard.

Every skill is self-contained. No skill depends on another. Install only what you need.

Release history: CHANGELOG.md.

Contents

Install

Recommended: any agent via skills CLI

The skills CLI is the recommended install method.

Interactive install (recommended):

npx skills add dpearson2699/swift-ios-skills

Running the default command opens the skills CLI UI so you can choose which skills to install and which agent(s) to install them for.

Install everything for any coding agent:

npx skills add dpearson2699/swift-ios-skills --all

Use --all when you want the full set of 86 skills installed automatically for any coding agent.

Install specific skills directly:

npx skills add dpearson2699/swift-ios-skills --skill <skill-name> --skill <skill-name>

Check for updates to installed skills:

npx skills check

Update installed skills to the latest versions:

npx skills update

Use these after installing through the skills CLI.

Claude Code (via plugin marketplace)

Add the marketplace (one-time):

/plugin marketplace add dpearson2699/swift-ios-skills

Install everything:

/plugin install all-ios-skills@swift-ios-skills

Or install a themed bundle (bundles limit how many skills load into the context window — if you want everything, use all-ios-skills above instead of installing multiple bundles):

/plugin install swiftui-skills@swift-ios-skills
/plugin install swift-core-skills@swift-ios-skills
/plugin install ios-app-framework-skills@swift-ios-skills
/plugin install ios-data-framework-skills@swift-ios-skills
/plugin install ios-ai-ml-skills@swift-ios-skills
/plugin install ios-engineering-skills@swift-ios-skills
/plugin install ios-hardware-skills@swift-ios-skills
/plugin install ios-platform-skills@swift-ios-skills
/plugin install ios-gaming-skills@swift-ios-skills
/plugin install apple-kit-skills@swift-ios-skills

OpenAI Codex

$skill-installer install https://github.com/dpearson2699/swift-ios-skills/tree/main/skills/<skill-name>

Claude Web App / Claude Desktop

  1. Download the skill folder(s) you want from this repo
  2. Zip each skill folder
  3. Go to Settings > Capabilities and enable "Code execution and file creation"
  4. Go to Customize > Skills, click +, then Upload a skill
  5. Upload the zip

ChatGPT

  1. Download the skill folder(s) you want from this repo
  2. Zip each skill folder
  3. Click your profile icon in ChatGPT and select Skills
  4. Click New skill and select Upload from your computer
  5. Upload the zip

Plugin Bundles (Claude Code)

PluginSkills included
all-ios-skillsAll 86 skills
apple-kit-skills39 skills spanning Apple Kit frameworks plus CarPlay
swiftui-skillsfocus-engine, swiftui-animation, swiftui-gestures, swiftui-layout-components, swiftui-liquid-glass, swiftui-navigation, swiftui-patterns, swiftui-performance, swiftui-uikit-interop, swiftui-webkit
swift-core-skillscore-data, swift-api-design-guidelines, swift-architecture, swift-codable, swift-charts, swift-concurrency, swift-formatstyle, swift-language, swift-testing, swiftdata
ios-app-framework-skillsactivitykit, adattributionkit, alarmkit, app-clips, app-intents, avkit, carplay, mapkit, paperkit, pdfkit, photokit, push-notifications, storekit, tipkit, widgetkit
ios-data-framework-skillscloudkit, contacts-framework, eventkit, financekit, healthkit, musickit, passkit, weatherkit
ios-ai-ml-skillsapple-on-device-ai, coreml, natural-language, speech-recognition, vision-framework
ios-engineering-skillsapp-store-optimization, app-store-review, authentication, background-processing, cryptokit, debugging-instruments, device-integrity, ios-accessibility, ios-ettrace-performance, ios-localization, ios-memgraph-analysis, ios-networking, swift-security, swiftlint, ios-simulator, metrickit
ios-hardware-skillsaccessorysetupkit, core-bluetooth, core-motion, core-nfc, dockkit, pencilkit, realitykit, sensorkit
ios-platform-skillsappmigrationkit, audioaccessorykit, browserenginekit, callkit, cryptotokenkit, energykit, homekit, permissionkit, relevancekit, shareplay-activities
ios-gaming-skillsgamekit, scenekit, spritekit, tabletopkit

Skills

SwiftUI

SkillWhat it covers
focus-engine@FocusState, defaultFocus, focusSection, focused scene values, focus restoration, UIFocusGuide
swiftui-animationSpring animations, PhaseAnimator, KeyframeAnimator, matchedGeometryEffect, SF Symbols
swiftui-gesturesTap, drag, magnify, rotate, long press, simultaneous and sequential gestures
swiftui-layout-componentsGrid, LazyVGrid, Layout protocol, ViewThatFits, custom layouts
swiftui-liquid-glassiOS 26 Liquid Glass, glassEffect, GlassEffectContainer, morphing transitions
swiftui-navigationNavigationStack, NavigationSplitView, programmatic navigation, deep linking
swiftui-patterns@Observable, state ownership, environment wiring, view composition, async loading, MV-pattern architecture
swiftui-performanceRendering performance, view update optimization, layout thrash, Instruments profiling
swiftui-uikit-interopUIViewRepresentable, UIHostingController, Coordinator, incremental UIKit-to-SwiftUI migration
swiftui-webkitWebView, WebPage, navigation policies, JavaScript calls, local content, custom URL schemes

Core Swift

SkillWhat it covers
swift-api-design-guidelinesSwift API Design Guidelines -- argument labels, mutating/nonmutating pairs, documentation comments, naming conventions
swift-architectureArchitecture patterns: MV (@Observable), MVVM, MVI, TCA, Clean Architecture, Coordinator, decision framework
swift-codableSwift Codable, JSONDecoder, JSONEncoder, CodingKeys, custom decoding, nested JSON
swift-chartsBar, line, area, pie, donut, and 3D charts, scrolling, selection, annotations
swift-concurrencySwift 6.2 concurrency, Sendable, actors, structured concurrency, data-race safety
swift-formatstyleFormatStyle protocol, number/currency/date/duration/measurement formatting, custom styles
swift-languageSwift 6.3 language idioms, result builders, property wrappers, typed throws
swift-testingSwift Testing framework, @Test, @Suite, #expect, parameterized tests, mocking
core-dataCore Data persistence, NSPersistentContainer, NSFetchedResultsController, batch operations, staged migration
swiftdata@Model, @Query, #Predicate, ModelContainer, migrations, CloudKit sync, @ModelActor

App Experience Frameworks

SkillWhat it covers
activitykitActivityKit, Dynamic Island, Lock Screen Live Activities, push-to-update
adattributionkitPrivacy-preserving ad attribution, postbacks, conversion values, re-engagement
alarmkitAlarmKit system alarms and countdown timers, Lock Screen, Dynamic Island, Live Activities
app-clipsApp Clips, invocation URLs, NFC, QR, App Clip Codes, App Group handoff
app-intentsApp Intents for Siri, Shortcuts, Spotlight, widgets, and Apple Intelligence
avkitAVPlayerViewController, VideoPlayer, Picture-in-Picture, AirPlay, subtitles
carplayCarPlay templates, navigation, audio, communication, EV charging apps
mapkitMapKit, CoreLocation, annotations, geocoding, directions, geofencing
paperkitPaperMarkupViewController, markup editing, drawing, shapes (iOS 26)
pdfkitPDFView, PDFDocument, annotations, text search, form filling, thumbnails
photokitPhotosPicker, AVCaptureSession, photo library, video recording, media permissions
push-notificationsUNUserNotificationCenter, APNs, rich notifications, silent push, service extensions
storekitStoreKit 2 purchases, subscriptions, SubscriptionStoreView, transaction verification
tipkitFeature discovery tooltips, contextual tips, tip rules, tip events
widgetkitHome Screen, Lock Screen, and StandBy widgets, Control Center controls, timeline providers

Data & Service Frameworks

SkillWhat it covers
cloudkitCKContainer, CKRecord, subscriptions, sharing, CKSyncEngine, SwiftData sync
contacts-frameworkCNContactStore, fetch requests, key descriptors, CNContactPickerViewController, save requests
eventkitEKEventStore, EKEvent, EKReminder, recurrence rules, EventKitUI editors and choosers
financekitApple Card, Apple Cash, Wallet orders, transaction queries, account balances
healthkitHKHealthStore, queries, statistics, workout sessions, background delivery
musickitMusicKit authorization, catalog search, ApplicationMusicPlayer, MPRemoteCommandCenter
passkitApple Pay, PKPaymentRequest, PKPaymentAuthorizationController, Wallet passes
weatherkitWeatherService, current/hourly/daily forecasts, alerts, attribution requirements

AI & Machine Learning

SkillWhat it covers
apple-on-device-aiFoundation Models framework, Core ML, MLX Swift, on-device LLM inference
coremlCore ML model loading, prediction, MLTensor, compute unit configuration, VNCoreMLRequest, MLComputePlan
natural-languageNLTokenizer, NLTagger, sentiment analysis, language identification, embeddings, Translation
speech-recognitionSpeechAnalyzer, SpeechTranscriber, SFSpeechRecognizer, on-device recognition, audio buffer processing
vision-frameworkVision text recognition, face/barcode detection, image segmentation, VisionKit DataScannerViewController

iOS Engineering

SkillWhat it covers
app-store-optimizationASO keyword strategy, description writing, screenshot optimization, Custom Product Pages, A/B testing
app-store-reviewApp Review guidelines, rejection prevention, privacy manifests, ATT, HIG compliance
authenticationSign in with Apple, ASAuthorizationController, passkeys, biometric auth (LAContext), credential management
background-processingBGTaskScheduler, background refresh, URLSession background transfers
cryptokitSHA-2/SHA-3, HMAC, AES-GCM, ChaChaPoly, HPKE, ML-KEM/ML-DSA, P256/Curve25519 signing, ECDH, Secure Enclave
debugging-instrumentsXcode debugger, Instruments, os_signpost, MetricKit, crash symbolication
device-integrityDeviceCheck (DCDevice per-device bits), App Attest (DCAppAttestService attestation and assertion flows)
ios-accessibilityVoiceOver, Dynamic Type, custom rotors, accessibility focus, assistive-technology support
ios-ettrace-performanceETTrace launch/runtime capture, exact-build dSYM matching, processed flamegraph JSON, comparable verification
ios-localizationString Catalogs, pluralization, FormatStyle, right-to-left layout
ios-memgraph-analysisSimulator memgraph capture, leak ownership paths, reachable heap growth, raw evidence preservation
ios-networkingURLSession async/await, REST APIs, downloads/uploads, WebSockets, pagination, retry, caching
swift-securityKeychain Services, CryptoKit symmetric/asymmetric, biometric authentication, Secure Enclave, certificate trust, credential storage, OWASP compliance · Based on ivan-magda/swift-security-skill
ios-simulatorxcrun simctl commands, device lifecycle, push/location/privacy simulation, log streaming, simulator limitations
metrickitMetricManager async reports, hang/crash diagnostics, production performance telemetry
swiftlintSwiftLint setup, .swiftlint.yml, build tool plugin, rule selection, baselines, suppressions, CI integration

Hardware & Device Integration

SkillWhat it covers
accessorysetupkitPrivacy-preserving BLE/Wi-Fi accessory discovery, ASAccessorySession, picker UI
core-bluetoothCBCentralManager, CBPeripheral, BLE scanning/connecting, services, characteristics, background modes
core-motionCMMotionManager, CMPedometer, accelerometer, gyroscope, activity recognition, altitude
core-nfcNFCNDEFReaderSession, NFCTagReaderSession, NDEF reading/writing, background tag reading
dockkitDockAccessoryManager, camera subject tracking, motor control, framing
pencilkitPKCanvasView, PKDrawing, PKToolPicker, Apple Pencil drawing and annotation
realitykitRealityView, entities, anchors, ARKit world tracking, raycasting, scene understanding
sensorkitResearch-grade sensor data, ambient light, keyboard metrics, device usage (approved studies)

Platform Integration

SkillWhat it covers
appmigrationkitCross-platform data transfer, AppMigrationExtension export/import (iOS 26)
audioaccessorykitAudio accessory features, automatic switching, device placement (iOS 26.4)
browserenginekitAlternative browser engines (EU), process management, web content extensions
callkitCXProvider, CXCallController, PushKit VoIP registration, call directory extensions
cryptotokenkitTKTokenDriver, TKSmartCard, iOS 26 NFC smart cards, certificate-based auth
energykitElectricityGuidance, EnergyVenue, grid forecasts, load event submission, electricity insights
homekitHMHomeManager, accessories, rooms, actions, triggers, MatterSupport commissioning
permissionkitAskCenter, PermissionQuestion, child communication safety, CommunicationLimits
relevancekitWidget relevance signals, time/location-based relevance providers (watchOS 26)
shareplay-activitiesGroupActivity, GroupSession, GroupSessionMessenger, coordinated media playback

Gaming

SkillWhat it covers
gamekitGame Center, GKLocalPlayer, leaderboards, achievements, real-time and turn-based multiplayer
scenekitSCNView, SCNScene, 3D geometry, materials, lighting, physics, SceneView
spritekitSKScene, SKSpriteNode, SKAction, physics simulation, particle effects, SpriteView
tabletopkitMultiplayer spatial board games, pieces, cards, dice, Group Activities (visionOS)

Structure

Each skill follows the open Agent Skills standard:

skills/
  skill-name/
    SKILL.md              # Required — instructions and metadata
    references/           # Optional — detailed reference material
      some-topic.md

SKILL.md contains YAML frontmatter (name, description) and markdown instructions. The references/ folder holds longer examples, advanced patterns, and lookup tables that the main file points to.

This repository contains original instructional content and examples for Apple platform development. Where Apple frameworks, APIs, documentation, WWDC sessions, or trademarks are referenced, those materials remain the property of Apple Inc. The license for this repository applies to this project's original content only and does not claim ownership of or relicense Apple's documentation, trademarks, sample code, or other third-party materials.

Compatibility

These skills work with any agent that supports the Agent Skills standard, including:

Upgrading from v2.x

v3.0 is a major release. If you previously installed v2.x skills, note the following changes:

  • Skill count: 57 skills in v2.2.0, 76 skills in v3.0.0.

  • Skill renames: 12 existing skills renamed to use Apple Kit framework names. Old skill paths no longer resolve. Uninstall all skills and reinstall to upgrade.

    v2.x namev3.0 name
    live-activitiesactivitykit
    mapkit-locationmapkit
    photos-camera-mediaphotokit
    homekit-matterhomekit
    callkit-voipcallkit
    metrickit-diagnosticsmetrickit
    pencilkit-drawingpencilkit
    passkit-walletpasskit
    musickit-audiomusickit
    cloudkit-synccloudkit
    eventkit-calendareventkit
    realitykit-arrealitykit
  • 19 new Kit framework skills: avkit, gamekit, cryptokit, pdfkit, paperkit, spritekit, scenekit, financekit, accessorysetupkit, adattributionkit, carplay, appmigrationkit, browserenginekit, dockkit, sensorkit, tabletopkit, relevancekit, audioaccessorykit, cryptotokenkit.

  • New bundles: apple-kit-skills (all 39 Apple Kit framework skills) and ios-gaming-skills (GameKit, SpriteKit, SceneKit, TabletopKit).

  • PaperKit standalone: PaperKit content removed from pencilkit and is now its own paperkit skill.

  • Beta frameworks: permissionkit, energykit, paperkit, relevancekit, appmigrationkit, and audioaccessorykit require iOS/watchOS 26 beta and are subject to API changes before GM.

  • All skills remain self-contained: No skill references or depends on another.

To upgrade via the skills CLI:

npx skills add dpearson2699/swift-ios-skills

To upgrade Claude Code bundles, reinstall the bundles you use (old skill paths will no longer resolve).

Support

If these skills save you time or improve your workflow, you can support ongoing maintenance through GitHub Sponsors.

Support helps keep the collection current with new Apple releases, evolving framework APIs, updated examples, and compatibility work across Claude Code, Codex, Cursor, Copilot, and other agents.

Sponsors

Thanks to the following people for supporting this project:

Anthony Jr.

License

PolyForm Perimeter 1.0.0 -- see LICENSE

What this means in practice:

  • Using these skills to build your iOS app -- allowed
  • Using these skills inside a closed-source commercial workflow -- allowed
  • Forking the repo and contributing back -- allowed
  • Sharing the skills with a teammate -- allowed
  • Taking the skills, rebranding them as "Premium iOS Agent Skills," and selling them -- not allowed (that's a competing product)

This project is not affiliated with, endorsed by, or sponsored by Apple Inc.

其他

中风险

  • 来源需自行核对维护者身份。
  • 未检测到明显脚本安装指令。
  • 可能需要外部 token、网络权限或第三方服务。
  • 未检测到高风险命令。
  • 扫描发现:1 条。

Codex — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/dpearson2699/swift-ios-skills.git
  3. 将 "skills/device-integrity" 文件夹复制到 Codex 的 skills 目录中。
  4. 重启 Codex 让新的 skill 生效。

Codex — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Codex 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Codex 让新的 skill 生效。

Claude Code — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/dpearson2699/swift-ios-skills.git
  3. 将 "skills/device-integrity" 文件夹复制到 Claude Code 的 skills 目录中。
  4. 重启 Claude Code 让新的 skill 生效。

Claude Code — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Claude Code 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Claude Code 让新的 skill 生效。

Cursor — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/dpearson2699/swift-ios-skills.git
  3. 将 "skills/device-integrity" 文件夹复制到 Cursor 的 skills 目录中。
  4. 重启 Cursor 让新的 skill 生效。

Cursor — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Cursor 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Cursor 让新的 skill 生效。

GitHub Copilot — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/dpearson2699/swift-ios-skills.git
  3. 将 "skills/device-integrity" 文件夹复制到 GitHub Copilot 的 skills 目录中。
  4. 重启 GitHub Copilot 让新的 skill 生效。

GitHub Copilot — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 GitHub Copilot 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 GitHub Copilot 让新的 skill 生效。

Windsurf — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/dpearson2699/swift-ios-skills.git
  3. 将 "skills/device-integrity" 文件夹复制到 Windsurf 的 skills 目录中。
  4. 重启 Windsurf 让新的 skill 生效。

Windsurf — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Windsurf 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Windsurf 让新的 skill 生效。
查看 SKILL.md 原文
name: device-integrity
description: "Verify device legitimacy and app integrity using DeviceCheck (DCDevice per-device bits) and App Attest (DCAppAttestService key generation, attestation, and assertion flows). Use when implementing fraud prevention, detecting compromised devices, validating app authenticity with Apple's servers, protecting sensitive API endpoints with attested requests, or adding device verification to a backend architecture."

Device Integrity

Verify that requests to your server come from a genuine Apple device running a legitimate instance of your app. DeviceCheck provides per-device bits for simple flags (e.g., "claimed promo offer"). App Attest uses Secure Enclave keys and Apple attestation to cryptographically prove app legitimacy on sensitive requests.

Contents

DCDevice (DeviceCheck Tokens)

DCDevice generates a unique, ephemeral token that identifies a device. Treat each token as single-use: generate a new token for each server operation instead of caching or reusing one. The token is sent to your server, which then communicates with Apple's servers to read or set two per-device bits. Available on iOS 11+.

Token Generation

import DeviceCheck

func generateDeviceToken() async throws -> Data {
    guard DCDevice.current.isSupported else {
        throw DeviceIntegrityError.deviceCheckUnsupported
    }

    return try await DCDevice.current.generateToken()
}

Sending the Token to Your Server

func sendTokenToServer(_ token: Data) async throws {
    let tokenString = token.base64EncodedString()

    var request = URLRequest(url: serverURL.appending(path: "verify-device"))
    request.httpMethod = "POST"
    request.setValue("application/json", forHTTPHeaderField: "Content-Type")
    request.httpBody = try JSONEncoder().encode(["device_token": tokenString])

    let (_, response) = try await URLSession.shared.data(for: request)
    guard let httpResponse = response as? HTTPURLResponse,
          httpResponse.statusCode == 200 else {
        throw DeviceIntegrityError.serverVerificationFailed
    }
}

Server-Side Overview

The server exchanges each fresh token with Apple's authenticated DeviceCheck API. Load DeviceCheck Server Endpoints for endpoint and environment details.

What the Two Bits Are For

Apple stores two Boolean values per device per developer team. You decide what they mean. Common uses:

  • Bit 0: Device has claimed a promotional offer.
  • Bit 1: Device has been flagged for fraud.

Bits persist across app reinstall. You control when to reset them via the server API.

DCAppAttestService (App Attest)

DCAppAttestService validates that a specific instance of your app on a specific device is legitimate. It uses a hardware-backed key in the Secure Enclave to create cryptographic attestations and assertions. Available on iOS 14+.

The flow has three phases:

  1. Key generation -- create a key pair in the Secure Enclave.
  2. Attestation -- Apple certifies the key belongs to a genuine Apple device running your app.
  3. Assertion -- sign server requests with the attested key to prove ongoing legitimacy.

Checking Support

import DeviceCheck

let attestService = DCAppAttestService.shared

guard attestService.isSupported else {
    // Fall back to DCDevice token or other risk assessment.
    // App Attest is not available on simulators or all device models.
    return
}

For app extensions, App Attest is supported only in Action, extensible SSO, and watchOS extensions. Treat other extension types as unsupported even if isSupported returns true.

App Attest Key Generation

Generate one cryptographic key pair per user account on each device. The private key stays in the Secure Enclave. The returned keyId is the only identifier your app can later use to access the key, so record and reuse the account/device-scoped keyId; do not share one key across users. Avoid unnecessary regeneration because each new key affects App Attest key-count risk metrics. Only treat the keyId as usable after your server verifies attestation. If server verification fails, discard the keyId and generate a new key before retrying.

import DeviceCheck

actor AppAttestManager {
    private let service = DCAppAttestService.shared
    private var keyId: String?

    /// Generate and record a key pair for App Attest.
    func generateKeyIfNeeded() async throws -> String {
        if let existingKeyId = loadKeyIdFromKeychain() {
            self.keyId = existingKeyId
            return existingKeyId
        }

        let newKeyId = try await service.generateKey()
        saveKeyIdToKeychain(newKeyId)
        self.keyId = newKeyId
        return newKeyId
    }

    // MARK: - Keychain helpers (simplified)

    private func saveKeyIdToKeychain(_ keyId: String) {
        let data = Data(keyId.utf8)
        let query: [String: Any] = [
            kSecClass as String: kSecClassGenericPassword,
            kSecAttrAccount as String: "app-attest-key-id-\(currentAccountID)",
            kSecAttrService as String: Bundle.main.bundleIdentifier ?? "",
            kSecValueData as String: data,
            kSecAttrAccessible as String: kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly
        ]
        SecItemDelete(query as CFDictionary) // Remove old if exists
        SecItemAdd(query as CFDictionary, nil)
    }

    private func loadKeyIdFromKeychain() -> String? {
        let query: [String: Any] = [
            kSecClass as String: kSecClassGenericPassword,
            kSecAttrAccount as String: "app-attest-key-id-\(currentAccountID)",
            kSecAttrService as String: Bundle.main.bundleIdentifier ?? "",
            kSecReturnData as String: true,
            kSecMatchLimit as String: kSecMatchLimitOne
        ]
        var result: AnyObject?
        let status = SecItemCopyMatching(query as CFDictionary, &result)
        guard status == errSecSuccess, let data = result as? Data else { return nil }
        return String(data: data, encoding: .utf8)
    }
}

App Attest Attestation Flow

Attestation proves that the key was generated on a genuine Apple device running a legitimate instance of your app. You perform attestation once per key, then store the verified public key and receipt on your server. The app stores the keyId for future assertions after the server accepts the attestation.

Client-Side Attestation

import DeviceCheck
import CryptoKit

extension AppAttestManager {
    /// Attest the key with Apple. Send the attestation object to your server.
    func attestKey() async throws -> Data {
        guard let keyId else {
            throw DeviceIntegrityError.keyNotGenerated
        }

        // 1. Request a one-time challenge from your server
        let challenge = try await fetchServerChallenge()

        // 2. Hash the challenge (Apple requires a SHA-256 hash)
        let challengeHash = Data(SHA256.hash(data: challenge))

        // 3. Ask Apple to attest the key
        let attestation = try await service.attestKey(keyId, clientDataHash: challengeHash)

        // 4. Send the attestation object to your server for verification
        try await sendAttestationToServer(
            keyId: keyId,
            attestation: attestation,
            challenge: challenge
        )

        return attestation
    }

    private func fetchServerChallenge() async throws -> Data {
        let url = serverURL.appending(path: "attest/challenge")
        let (data, _) = try await URLSession.shared.data(from: url)
        return data
    }

    private func sendAttestationToServer(
        keyId: String,
        attestation: Data,
        challenge: Data
    ) async throws {
        var request = URLRequest(url: serverURL.appending(path: "attest/verify"))
        request.httpMethod = "POST"
        request.setValue("application/json", forHTTPHeaderField: "Content-Type")

        let payload: [String: String] = [
            "key_id": keyId,
            "attestation": attestation.base64EncodedString(),
            "challenge": challenge.base64EncodedString()
        ]
        request.httpBody = try JSONEncoder().encode(payload)

        let (_, response) = try await URLSession.shared.data(for: request)
        guard let httpResponse = response as? HTTPURLResponse,
              httpResponse.statusCode == 200 else {
            throw DeviceIntegrityError.attestationVerificationFailed
        }
    }
}

Server-Side Attestation Verification

The server must verify the attestation before the client treats keyId as usable, then store the verified public key and receipt. Load Server-Side Attestation Verification for the certificate, App ID, environment, counter, credential, and nonce checks.

App Attest Assertion Flow

After attestation, use assertions to sign sensitive requests. Each assertion proves the request came from the attested app instance and includes a server-issued, one-time challenge to prevent replay.

Client-Side Assertion

import DeviceCheck
import CryptoKit

extension AppAttestManager {
    /// Generate an assertion for encoded client data.
    /// Client data should include a one-time server challenge and request context.
    func generateAssertion(for clientData: Data) async throws -> Data {
        guard let keyId else {
            throw DeviceIntegrityError.keyNotGenerated
        }

        let clientDataHash = Data(SHA256.hash(data: clientData))

        return try await service.generateAssertion(keyId, clientDataHash: clientDataHash)
    }
}

Using Assertions in Network Requests

struct AppAttestClientData: Encodable {
    let challenge: String
    let method: String
    let path: String
    let bodySHA256: String
}

extension AppAttestManager {
    /// Perform an attested API request.
    func makeAttestedRequest(
        to url: URL,
        method: String = "POST",
        body: Data
    ) async throws -> (Data, URLResponse) {
        let challenge = try await fetchAssertionChallenge()
        let bodyHash = Data(SHA256.hash(data: body)).base64EncodedString()
        let clientData = try JSONEncoder().encode(
            AppAttestClientData(
                challenge: challenge,
                method: method,
                path: url.path,
                bodySHA256: bodyHash
            )
        )
        let assertion = try await generateAssertion(for: clientData)

        var request = URLRequest(url: url)
        request.httpMethod = method
        request.setValue("application/json", forHTTPHeaderField: "Content-Type")
        request.setValue(assertion.base64EncodedString(), forHTTPHeaderField: "X-App-Attest-Assertion")
        request.setValue(clientData.base64EncodedString(), forHTTPHeaderField: "X-App-Attest-Client-Data")
        request.httpBody = body

        return try await URLSession.shared.data(for: request)
    }

    private func fetchAssertionChallenge() async throws -> String {
        let url = serverURL.appending(path: "assert/challenge")
        let (data, _) = try await URLSession.shared.data(from: url)
        return String(decoding: data, as: UTF8.self)
    }
}

Server-Side Assertion Verification

The server must verify each assertion's signature, RP ID, counter, one-time challenge, and request binding before authorizing the request. Load Server-Side Assertion Verification for the complete algorithm.

Server Verification Guidance

See references/device-integrity-patterns.md for full server architecture guidance including attestation vs. assertion comparison, recommended endpoint design, and risk assessment.

Security Boundaries

App Attest proves app-instance integrity for selected requests. It does not replace user authentication, OAuth/JWT/session handling, API token design, entitlement or subscription authorization, TLS, certificate pinning, or general networking security. Treat those as handoffs to authentication, networking, or broader security guidance, and still enforce normal authentication and authorization after App Attest passes.

Error Handling

Handle DCError codes from DeviceCheck operations. Key cases:

  • .serverUnavailable — retry with exponential backoff
  • .invalidKey — the key was already attested, assertion used an unattested key, or the service rejected the key
  • .featureUnsupported — fall back to DCDevice tokens
  • .invalidInput — malformed clientDataHash or keyId

For attestKey, retry .serverUnavailable later with the same keyId and the same clientDataHash. For other attestation errors, discard the key identifier and create a new key before retrying. See references/device-integrity-patterns.md for full error handling code, retry strategy, and rejected-key recovery.

Common Patterns

Environment Entitlement

Set the App Attest environment in your entitlements file. Use development during testing and production for App Store builds. Load Environment Entitlement for the XML, default sandbox behavior, distribution behavior, and extension limits.

See references/device-integrity-patterns.md for the full integration manager pattern, gradual rollout guidance, and error type definition.

Common Mistakes

  1. Generating a new key on every launch. Generate once per user account on a device, persist the keyId, and keep key counts low.
  2. Reusing DCDevice tokens. Treat generated tokens as single-use. Generate a new token for each server operation.
  3. Skipping the fallback for unsupported devices or extensions. Not all devices and extension types support App Attest. Use DCDevice tokens or other risk assessment as fallback.
  4. Trusting attestation client-side. All verification must happen on your server.
  5. Signing only the raw request body. Assertion client data must include a one-time server challenge and enough request context for the server to bind the assertion to the request.
  6. Verifying the wrong attestation nonce. Compare the certificate extension with SHA256(authData || SHA256(challenge)), not SHA256(challenge) alone.
  7. Not implementing replay protection. The server must validate one-time challenges and track the assertion counter.
  8. Mixing development and production environments. Sandbox keys and receipts do not work in production, and production keys and receipts do not work in sandbox.
  9. Not handling DCError.invalidKey. Check for repeated attestation, unattested assertion keys, or service rejection; regenerate only after the state is known bad.

Review Checklist

  • DCDevice tokens generated per server operation and never cached for reuse
  • DCAppAttestService.isSupported checked before use; unsupported devices and extension types have a fallback
  • Key generated once per user account on each device and keyId persisted only for that app account/device
  • Attestation performed once per key; server stores verified public key and receipt
  • Server validates attestation certificate chain, App ID hash, environment aaguid, credential ID, and nonce SHA256(authData || SHA256(challenge))
  • Assertions include one-time challenge plus request context; server verifies signature, RP ID, counter, challenge, and request binding
  • Protected endpoints still enforce normal user authentication and entitlement authorization after App Attest passes
  • DCError cases handled: .serverUnavailable retries attestation with the same key/hash; bad keys are discarded and regenerated
  • App Attest environment entitlement and sandbox/production server routing are consistent
  • Gradual rollout considered; feature flag in place for enabling/disabling

References

发现问题?提交给管理员复核

评分:

评论 (0)

暂无评论,成为第一个评论者吧!